The discussion I stumbled upon, about this SSH app for Android, is really worrying. Will Google really manage to make it impossible to root your phone?

But there’s more to this, it’s more complicated. In the Big Picture, Google has every incentive to make these changes — they lead to more security, and they’re aligned with Google’s corporate goals as well.

  • When talking to users, Google will emphasize control over hackers.
  • When talking to stockholders, Google will emphasize control over users.

Edit: I disagree with “they lead to more security”. That’s not “security”, let’s not turn words upside-down.

44 points

It already is. Fuck SafteyNet. It’s DRM for phones.

permalink
report
reply
2 points
*

SafetyNet isn’t a shit anymore and it could be ez passed on unlocked BL with magisk. Play integrity check is nightmare nowdays specially on stock roms but it also can be passed on some phones/custom roms using lsposed or other magisk modules.

permalink
report
parent
reply
2 points

SafetyNet isn’t a shit anymore and it could be ez passed on unlocked BL with magisk

The real challenge has yet to come, from what I’ve understood, once basic attestation eventually gets abandoned over hardware-backed attestation.

permalink
report
parent
reply
1 point

Tell me what module will allow me to pass CTS on a stock ROM, I can’t find fuck all - the most I can find is mods to pass basic Attestation, and “disable” CTS - the problem is that SafteyNet, for phones that are known to have a working CTS, will fail if CTS is disabled - to this day I have 2 apps that I can no longer use as they require CTS.

If you can tell me any app, short of a custom ROM that I can use to bypass this behaviour, it will make me incredibly happy.

(google wallet, which Idgaf about, but also this other app that allows me to block companies from checking my credit score)

permalink
report
parent
reply
1 point
*

https://github.com/kdrag0n/safetynet-fix/releases

It should work. Flashed this on more than 10 devices stock/custom and it not working only on shitsung Galaxy a13.

My current setup is lineageos with magisk (magisk delta fork) and microg also installed as module and i pass safetynet without a problem.

edit: fuck g00gle

permalink
report
parent
reply
39 points

That has to my understanding been Google’s project all along (making Android crappy that is). IIRC they bought Android, which due to utilizing the Linux kernel was GPL software. The solution was therefore to seperate Android from all the tools that make Android work, splitting core functionality away from the now AOSP and over to Google services. By abuse of market position we are now in the position where stuff like Google push services, safety net and etc are now basically forcing people into their ecosystem. It will not get better, as witnessed with the company’s attempts at making email and most sites on the internet dependant on their ecosystem as well.

permalink
report
reply
11 points
*
Deleted by creator
permalink
report
parent
reply
15 points
*

To some extent you are of course right in that the underlying technology of Android has improved. What I was referring to was a design strategy aimed at crippling those who might want to present a Google-free Android alternative.

EDIT: I also want to add that MicroG, though a great project, is to my knowledge not Google free and probably never can be.

permalink
report
parent
reply
1 point
*
Deleted by creator
permalink
report
parent
reply
1 point

This is an interesting take. Could you share some resources or links to follow this line of reasoning more in detail? Especially resources that are somewhat “noob-friendly”. Cheers.

permalink
report
parent
reply
1 point
*
Deleted by creator
permalink
report
parent
reply
25 points

Will Google really manage to make it impossible to root your phone?

Google has managed this years ago, but it’s optional. There was a fairly short timeframe when most phone makers enforced it, but now most allow power users to disable the security and root their phones. But usually they will disable some security-sensitive features like Samsung Knox. And many security-sensitive apps like banking apps will not let you run them anymore (if yours does, great for you, but that also means your bank’s security is shit, just FYI).

permalink
report
reply
17 points

A banking app allowing itself to run on rooted devices isn’t a security issue.

permalink
report
parent
reply
9 points

Depends on your level of security consciousness. If you’re relying on security identifiers or apis that need an “intact” system, it certainly can be a security issue if you can’t rely of those.

That being said, it’s not exactly a plausible risk for most people or apps.

permalink
report
parent
reply
9 points

That’s right. And if there is, the issue is the bank, not your phone. Rule number 1 in security is never trust the client.

permalink
report
parent
reply
Deleted by creator
permalink
report
reply
19 points

Thankfully GraphenOS and others are maturing very well and will be a good replacement to googles BS. Hopefully they can keep custom versions alive that will support the apps you want

permalink
report
reply

Technology

!technology@beehaw.org

Create post

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community’s icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

Community stats

  • 2.7K

    Monthly active users

  • 3.4K

    Posts

  • 81K

    Comments