5 ms·
I'm waiting for a public exploit for the pixel 7 so that I can do some modifications to my phone (enable call recording outside countries that google supports c
by compsciphd 4y ago
I'm waiting for a public exploit for the pixel 7 so that I can do some modifications to my phone (enable call recording outside countries that google supports call recording in). I could unlock the bootloader and root the phone via "normal" methods, however, that means having something that will then fail google safetynet and the like. A root exploit enables me to make the changes to on flash DBs, and then update the device and the DB changes will persist and my phone will be secure.
Of course, such an exploit could be used for more nefarious things, but as google wants to limit functionality that the phone has (that is legal where I am), I'll be patient.
- phh 4y agoI perfectly understand not wanting to spend time on working around Safetynet, but in case you're not aware, I just want to point out that safetynet is pretty reliably broken (Google clearly doesn't use it for security. I'm pretty confident that it's 99% for passing audits, and 1% for shows). Current stats of the Safetynet workarounds is maybe 7 days of down time per year. Also, my personal point of view of the matter is that apps that require Safetynet, 1. doesn't care about their users, 2. Do just-for-the-show security, and thus users would be better off not using them. I personally don't use any app that require it.
- eptcyka 4y agoSure, but banking, ride hailing, car/scooter rental apps all use it.
- gradeless 4y agoSome apps suggest they use it when they dont. Some (most) apps use a weaker form which an android/AOSP operating system can comply with, without being registered with Google (licencing Play Services) see eg. https://grapheneos.org/usage#banking-apps https://grapheneos.org/usage#banking-apps Very few apps use the full strict version of safetynet that requires hardware attestation
- dvngnt_ 4y agobanking can be done on web with the same experience
- NavinF 4y agoMany banks don't allow check deposits using the website. You're forced to use the app and phone camera.
- eptcyka 4y agoIt depends, some banks offer services through the app that can't be accessed on the web. But I am aware that some apps work just fine, 4/7 banking apps I've used just work on aosp. Still haven't ridden a scooter via aosp though.
- Semaphor 4y agoSometimes. Several banking websites only allow login through their apps. There was even a bank here who did a minor update in which they decided to block rooted phones, locking many people suddenly and without warning out of their banking account, I was evaluating them (luckily, it was worse for people who had DKB as actual bank) and had to contact support to close my account.
- turblety 4y agoCan you not use CalyxOS [1]. It relocks the bootloader, although it doesn't come with any of the Google proprietary stuff. 1. https://calyxos.org/ https://calyxos.org/
- gradeless 4y agoOr you couod look at using an android operating system which also supports bootloader relocking, but that doesnt have a history of repeated significant delays rolling out security patches https://privsec.dev/posts/android/choosing-your-android-based-operating-system/ https://privsec.dev/posts/android/choosing-your-android-base...
- sylware 4y agoDon't fool yourself: locking devices from user control should be plain illegal. This is not even a matter of argument or discussion as this is a red line. The real issue is why this is still not the case in "free" countries.