6 ms·
Such a shame. So right now Google is the only phone manufacturer that allows unlocking the bootloader without losing any functionality or enrolling into some de
by shrvtv 5y ago
Such a shame. So right now Google is the only phone manufacturer that allows unlocking the bootloader without losing any functionality or enrolling into some developer program
- JackGreyhat 5y agoOnePlus does so too...
- SXX 5y ago> that allows unlocking the bootloader without losing any functionality Does Google Pay work with unlocked bootloader? Any bank apps that require SafetyNet attestation?
- rchaud 5y agoI don't understand why mobile apps need special security verification. I can use my bank website on any computer's web browser without issue. Why can't I use the mobile website to do the same? Why does it have to be an app?
- fomine3 5y agoSome bank apps skip annoying authentication like webapp because they are in "trusted" environment. I wish those app have "untrusted" mode but unlikely happen.
- jeroenhd 5y agoThe only decent defence I know is DRM. Streaming companies are afraid of people ripping their 4K streams through hacked devices. They'd rather deprive their customer base of features than risk letting go of their strict requirements. I still see high res WEBDL torrents appearing online every time streaming services release new episodes, so whatever they're doing is clearly not working anyway. For banking apps there may be a certain level of liability ascribed to the bank. depending on local jurisdiction, but I don't think banks need top of the line security to comply with those regulations; even if there is legislation, security only needs to be good enough so that basic rooted malware can't steal money. I think the wording in the errors and warnings for broken apps say all. When an app doesn't work because the device is rooted, the messaging is usually "your device does not support X" or "your system does not meet the requirements" or "your device is not secured". It's never "you may have malware" or any other potentially helpful message; the wording always seems to punish the user for daring to modify the software on their phone.
- hulitu 5y ago> Streaming companies are afraid of people ripping their 4K streams through hacked devices. Or maybe they are afraid that people will see that instead of 4k they get 720i scaled to 4k. If they are so afraid of people ripping they could always insert a break in the stream and downgrade the quality, blaming internet connection.
- jeroenhd 5y agoGPay is not available in my country, but the two bank apps that I use have no problem with contactless payments or normal bank transfers. I did get a popup once that the device was not in the original state, but that only seems to happen once per install. Your experience will depend on the laws of your country and the terms of your bank, but unlocking a bootloader with Magisk and using the right masking tools is all you need to work around most SafetyNet validation. The trick seems to be to fake the type of attestation available to make the system think hardware attestation (which can't be faked reliably by software) isn't available, falling back to basic software attestation which can be spoofed. Software developers could theoretically detect this bypass by keeping their own mapping of device type to device properties (available hardware etc. to validate the model number and prevent quick spoofing, available attestation to prevent SafetyNet bypasses, and so on) but they'd have to disable some obscure devices or accept the spoofing.
- sudosysgen 5y agoAdd Xiaomi too.
- SahAssar 5y agoI thought multiple companies did that? Like Sony, Fairphone, Oneplus etc?
- fsflover 5y agoHow about GNU/Linux phones, Librem 5 and Pinephone, which run desktop OS with root access?
- yjftsjthsd-h 5y agoI'm pretty sure Motorola does?
- Hackbraten 5y agoIIRC, Purism and Pine64 also sell their phones with the bootloader unlocked.