3 ms·
On Android, the standard root system most people apply to their device prompts you when you launch an application if you want to allow it root access. This make
by problems 10y ago
On Android, the standard root system most people apply to their device prompts you when you launch an application if you want to allow it root access. This makes it trivial to block malicious applications - that new game you downloaded probably doesn't need root for any good reason. Just hit deny. The sandbox is still fully in place, just now you can poke holes in it for certain applications of your choosing.
What you're thinking of are things which use exploits to gain root - this may be done by some users, but most often Android devices are rooted via bootloader unlocking these days, which does _not_ use an exploit.
Exploits however are used by malware - and not having your device rooted won't prevent them. They gain root via exploitation, whether you want them to or not.
Not to mention that the kind of root detection done is by looking for things that only the legitimate sort of root leaves behind, like a su binary which prompts the user if they want to permit root or not.
Often times, rooting your device legitimately may allow you to flash a custom ROM and get updates that your original vendor hasn't released for your device, allowing you to actually _prevent_ exploitation by malware, even after your vendor has long abandoned the device.
- Godel_unicode 10y agoMy experience has been that Android malware authors tend to be kind of sloppy, and frequently leave a modified su binary hanging around. YMMV.
- problems 10y agoIn the same place that you'd install it as a user? That'd be some very stupid malware - anyone who was actually rooted would notice immediately when their root tool told them their support binary needs to be updated.