3 ms·
There seems to be a lot of confusion and misinformation about what dm-verity actually does in this thread. It's the same verified boot mechanism that's used by
by aray 13y ago
There seems to be a lot of confusion and misinformation about what dm-verity actually does in this thread. It's the same verified boot mechanism that's used by ChromeOS[1].
This just guarantees that on a locked, signed device (i.e. you haven't unlocked it to flash custom ROMs), the filesystem there is the one that's supposed to be there. Things that would be caught by this are (as the original documentation says[2]) rootkits and other persistent exploits.
You should still be able to unlock and flash your device; this is supposed to make it harder for a malicious app to root and own your (locked & signed) device persistently without you knowing.
[1] http://www.chromium.org/chromium-os/chromiumos-design-docs/verified-boot http://www.chromium.org/chromium-os/chromiumos-design-docs/v...
[2] http://source.android.com/devices/tech/security/dm-verity.html http://source.android.com/devices/tech/security/dm-verity.ht...
- saurik 13y agoIf I cannot unlock my device, modify its software, and then relock it and continue to use the modified software, that is serious issue: you should not run your Devi e normally with an unlocked bootloader as there is then no protection against someone picking up your device, booting it into fastboot, and flashing new software (which normally is protected against as the unlock process erases all your data). This does not actually seem to verify things at this level, though (and thereby does not seem similar to the ChromeOS mechanism).