4 ms·
The problem with rooting the phone is that it actually compromises features like verified boot and selinux namespacing. I still want those security features for
by asimops 4y ago
The problem with rooting the phone is that it actually compromises features like verified boot and selinux namespacing. I still want those security features for daily use. I still need a way around this, but it at least has to be technically secure. It will obviously still be open to social engineering attacks.
For your suggestion, sadly you somehow need to get steam's otp secret first, which is held in the apps data directory. Therefore you would need root/priv-esc to get to it.
- feanaro 4y ago> compromises features like verified boot and selinux namespacing It only compromises those features because vendors refuse to build in the functionality to have full control over your purchased hardware out of the box. Make it protected behinds loads of warnings and even hidden behind a trick like what you have to do to enable developer mode, but leave it baked into the OS.
- asimops 4y agoWell, I don't deny that there should be an option. Look at the parent post. But having root in the running OS seems to be a bad idea. I got this position after an extensive talk on this with some of the graphene os developers. They explained pretty good how rooting the device would impact the security measures taken in graphene. This is why I suggested putting the access behind a special boot mode.
- yoavm 4y agoCan you be more specific about your concerns? It's not like "having root" means "everything runs as root". You can enable/disable it per app, you always grant it explicitly when you want to - it's not very different from sudo on Linux.
- feanaro 4y agoI'd also like to hear these arguments, as I can't think of a technical reason why it would be unconditionally a bad idea.
- yjftsjthsd-h 4y ago> The problem with rooting the phone is that it actually compromises features like verified boot and selinux namespacing I'll grant that on most phones you can't use ex. magisk with verified boot (although on ex. the Pixels I think you could? just more work), but AFAIK there's no problem with having root and selinux enforcing at the same time? Obviously it gives you the ability to bypass those protections, but overruling the usual protections is kind of the point of giving an app root, and you shouldn't give that level of access to apps you don't trust completely (like running `sudo someprogram` on a desktop).
- heavyset_go 4y agoYou can still have security features if you also have the ability to grant root privileges.
- hparadiz 4y agoIt's like they don't realize that we have the a gui version of sudo where we have to confirm that we allow a certain app to run something as root.
- hparadiz 4y agoWhat exactly do you think will happen to your device without those features?