4 ms·
OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others
- rvz 12d agoWhat a disaster for Android.
- LoganDark 12d agoEnd users love these for rooting! (I sure would have.)
- la_oveja 12d agobetter see these in the open than in an israeli lab
- hzwanip 12d agothe israeli labs exist anyway
- 9865322689965 12d ago[dead]
- ReptileMan 12d agoIt is a feature. Every device should give root by mandate to the owner, the same way they have USB-C for phones.
- deleted 12d ago[deleted]
- _ZeD_ 12d agowill the "exploit" app be available? asking for a friend :D
- yehoshuapw 12d agowould you install such a app (without compiling from source)? I would not trust it to not come with "friends" (but would love to verify and use)
- sureglymop 12d agoOn an isolated test device for this purpose, yes. But otherwise, I would decompile it to look at it.
- user_7832 12d agoDepends on your phone, but for some qualcomm devices there was a vulnerability some time ago, iirc the OnePlus 15 has a dedicated thread on XDA. I also found this on XDA while trying to find the other exploit: https://xdaforums.com/t/the-holy-grail-universal-no-bl-root-for-qualcomm-devices-bypass-locked-bootloaders.4782827/ https://xdaforums.com/t/the-holy-grail-universal-no-bl-root-... Side note, it's quite ironic, google being so heavily anti-root is forcing people to opt for root access via more hidden ways, making it easier to avoid root being detected.
- ArtTimeInvestor 12d agoA good security track record must be the most valuable company asset in history. Apple makes $200B per year from selling the iPhone alone. Plus the services they sell on it, plus deals like the one with Google, plus app store ads, plus cross-selling of other hardware ... I have one too. Not because I like the hardware too much. Pixel phones are much nicer, they don't wobble when you put them on a table. Not because I like the software too much. Android is much more to my liking with more freedom to customize it. But because I have the feeling Apple takes security more seriously. I wish there was some kind of security arena like there is LLM arena for AI. That gives hard facts about the security track record of phone manufacturers.
- CGamesPlay 12d agohttps://mashable.com/article/high-sierra-password-fix-apple-update https://mashable.com/article/high-sierra-password-fix-apple-... > In the simplest of terms, with the bug, if you created a new APFS (Apple File System) encrypted volume on High Sierra, and set anything at all as the password hint, then your password was stored as the hint. In plain text.
- ArtTimeInvestor 12d agoI know Apple phones had bugs. Even worse bugs than the one you linked to. But Google phones had those too. That's why I said I "feel" like Apple takes security more seriously. And that I wish there were hard facts. Statistics of number of bugs by severity. Independently verified.
- izacus 12d agoYour post is essentially admitting that you're ignoring the bugs from the company you love and taking seriously form the company you don't. So the difference isn't about taking things "more seriously", but in the fact that you take marketing from Apple more seriously. That's not the same. (Note: There's plenty of proof that Apple does take security more seriously than Samsung, Xiaomi & Co. in the article, but your feelings aren't it.)
- gorgmah 12d agoSlightly unrelated: is it relatively safe to root android phones nowadays or should I stick to the unrooted standard android? The reason I'm asking is that I'm stuck with authy as a MFA code app, and would like to move to something that has both desktop and phone support, and my conclusion is I'd need to root my phone to get access to the actual MFA seeds (they don't allow exports to keep you stuck in their app).
- torben-friis 12d agoThe main issue is that many apps will block rooted phones (banks, state apps and the like). Usually more trouble than it's worth.
- KetoManx64 12d ago* some apps. Both of my banking apps work fine with a rooted GrapheneOS phone. If you want to have full control over your phone like you would a Linux laptop, to customize it to your own preferences and maximize privacy, there is nothing else gives you the same amount of control over the device that you bought and paid for. The fact that people pay $1000 for a device and then not be able to fully uninstall pre-installed crapware nor fully block it from the internet is depressing.
- gunapologist99 11d agoGOS is not rooted by default - in fact, rooting breaks the GrapheneOS security model and is unsupported.
- KetoManx64 11d agoI don't care. It's my phone and I care more about my privacy and the ability to sandbox apps (useful every day) than I do about a border patrol agents trying to clone my phone. (Will statistically never happen to me)
- throwa356262 12d ago
- deleted 12d ago[deleted]
- FrequentLurker 12d agoI wonder if there is a vulnerability that allows for toggling wireless adb. I have an LG with android 12 which technically should support wireless ADB but LG stripped the option from settings. Some say they stripped out the feature entirely. On top of that the USB port is damaged and doesnt accept data but still accepts power. So no wired adb either.
- Gander5739 12d agoWhat's stopping you from rooting it and then sshing in? You can then run the adb commands using root access.
- rickdeckard 12d ago> What's stopping you from rooting it (probably the broken USB port)
- Gander5739 12d agoIsn't the article about obtaining root from an unprivileged app? The recent GhostLock exploit is potentially usable for this purpose, for instance.
- rickdeckard 12d ago> On top of that the USB port is damaged and doesnt accept data but still accepts power. Data is broken on both sides of the port? (if you rotate the plug 180° it should use the other pins on the USB-C)
- FrequentLurker 12d agoTried both sides but no luck.
- veeti 12d agoIf you can get root and a terminal emulator on the device, you could try something like "adb shell settings put global adb_wifi_enabled 1".
- ece 12d agoYou'd almost think supporting a phone for a longer amount of time might actually be better than trying to sell a new phone every year or two.
- rickdeckard 12d agoOnly if you find a way to create revenue beyond the time-of-purchase, to offset the cost of development and maintenance, aka service revenue. So far only Apple achieved this by ensuring a walled garden around their ecosystem, securing additional revenue-share for every single 3rd party app and every transaction of the user. All other vendors are structurally prevented to properly compete in services, and have to rely on Google paying some minor revenue-share on Services, while having only limited control over the user-experience to distinguish themselves...
- ece 11d agoThis would be a bit convincing if there weren't other hardware and services providers like Fairphone, GrapheneOS and Google themselves, who do support and maintenance for longer.
- rickdeckard 11d agoThe fact that you put "Google themselves" in this list makes the conversation moot, because Google is de-facto the service-revenue recipient of the entire Android device-ecosystem and the culprit of the problem.
- ece 11d agoSamsung and Xiaomi have bigger ecosystems than Google in some ways. If they want to fix their development and support for issues like this, they can.
- rickdeckard 11d ago1. Fairphone actually demonstrates that it's not a matter of "want" for sustainable/repairable/longevity, the market still doesn't reward sufficiently for it. --> If the total potential is an increase in sales of 100k units at ~450 USD/device, there is no fiscal justification for a stock-trading company to actually build such a product. That's why e.g. the EU keeps mandating more and more of this, they "artificially" create the need for it because the market doesn't do it itself. 2. They don't have a comparable service revenue-ecosystem to Google, not even remotely. Even in sum across their entire mobile ecosystem, the majority of service-revenue their products generate is actually Google's service revenue of the Android ecosystem, of which they get a miniscule revenue-share via Google's RSA program. The only substantial revenue is still generated at the hardware time-of-sale only, which needs to finance the lifecycle maintenance of the product. So the objective becomes to sell a critical-mass of hardware to sustain the maintenance of the device. And then, the next level: The market-pressure for in-time software-maintenance can only be fulfilled by not deviating too much from Google's baseline (minimizing the effort of upgrading to newer Android versions). Not deviating from Google's baseline means either contributing back any disruptive changes to Google for integration in the baseline or (more likely) to not disrupt the smartphone landscape on platform-level at all. Disrupting with hardware innovation only works either on very-large scale or on small-scale, because either you can contract a component supplier for a huge volume of a component exclusive for you, or you pick a innovative component which cannot be supplied in huge quantity yet (and is therefore out of reach for larger brands) As result, the established players on the smartphone market don't make any more innovative leaps, because the risk/benefit ratio for the ROI is just not there. --> Vendors ship devices based on common hardware available at that time, combined with software available at that time. Chinese vendors changed the game a bit by announcing devices with innovative hardware which then never reached the global market, because the components were not available at-scale yet (under-display camera, wrap-around displays, new battery composition, 5G,...) --> This was a game-changer because e.g. Samsung, Apple, Motorola, LG would not announce a device they knew they can't launch at-scale. Oppo, Xiaomi et al could do a limited run for a device-launch in China, with chinese component-suppliers shipping to assembly-factories in China with low ramp-up costs.
- applfanboysbgon 12d ago> Here, I describe the one I took and why, measured against three properties I use as a yardstick throughout Nope nope nope. LLMs helped you do something cool, great. You can still speak for yourself. Stop outsourcing your humanity to a chatbot. > In practice the coverage of each chain is exactly the set of devices the OEM chose to ship the vulnerable component on. Wonderful insight, Claude. "The vulnerability covers exactly the devices that are vulnerable".
- sega_sai 12d agoI think old Android phones not supported by their makers are so problematic in the LLM era. I would think that even before LLMs the 3 letter agencies had exploits for those, but now one should assume common criminals will... I am happy that the pixel phone I got has 7 year of support, but it is clear that Apple is in general is much better in this than all the Android providers (including google)
- bayindirh 12d agoI keep my old iPhone X powered on as a handheld gaming device. It still gets software patches now and then. Funnily, even though the device is in its forsaken era, most of the applications I used to use daily still gets updates too. Not being able to update an app on it is a rarity.
- NoboruWataya 12d agoProbably wishful thinking but does this get us any closer to porting postmarketOS to these devices? (Or even LineageOS, though I think LineageOS may have decent support on many of these devices already?)
- tym0 12d agoDon't really see why. The issue with PostmarketOS is that there isn't enough people working on it. Not that the phones are locked down. Otherwise phones with open bootloader would have good support.
- p32929 11d ago[flagged]