305
you are viewing a single comment's thread
view the rest of the comments
[-] RobotToaster@mander.xyz 77 points 7 months ago

We really need to move away from the idea that a user having control over his/her device is insecure.

I can use online banking and paypal with windows logged in as administrator or GNU/Linux logged in as root[0], why shouldn't I be able to use google ~~wallet~~ ~~pay~~ wallet with root?

[0] yes I know you shouldn't log in as root, but that doesn't change that you can do it.

[-] yurgenst@lemmy.world 25 points 7 months ago

"why shouldn't I be able to use google wallet pay wallet with root?" Because little innocent Google won't be able to build their advertising profile of you. Can't have that!

[-] Wes_Dev@lemmy.ml 21 points 7 months ago

No my friend, our overloads have decided that you shouldn't have control over your desktop either.

[-] programmer_belch@lemmy.dbzer0.com 10 points 7 months ago

Does rooting your device make you the root user or just gives you access to superuser utilities?

In linux systems the root user shouldn't be used for daily use, you just make an user account with permission to use sudo, doas or su.

[-] user224@lemmy.sdf.org 16 points 7 months ago

If you root your phone, at least with most tools, you don't become the root user. Apps that use root access have to request it, and you'll have to allow it in the root tool you flashed.

Example pop-up from SuperSU:

[-] programmer_belch@lemmy.dbzer0.com 7 points 7 months ago

So google is lying about rooted devices, they seem as secure as an OEM letting an user sideload apps or google themselves letting malware apps inside their store

[-] evo@sh.itjust.works 3 points 7 months ago

Lol. So if you use an exploit to gain SU what makes you think a malicious app can't do the same? Or better yet, find a new exploit in the SU management software you installed. As soon as you root, you can no longer guarantee root activities are not taking place unbeknownst to you...

[-] michaelmrose@lemmy.world 16 points 7 months ago

if you use an exploit to gain SU what makes you think a malicious app can’t do the same

They can. 99% of computer security is still not installing malware or being tricked into taking actions that enable your own harm. That said often rooting methods involve physically pressing keys while booting to access the boot loader, ADB, running things with with expansive permissions. Malicious apps install via play store with reasonable permissions will generally have a much harder time breaking out of the sandbox.

Or better yet, find a new exploit in the SU management software you installed

Historically "sudo" tools haven't been the source of many issues whereas a multitude of problems flowed from complex memory unsafe code.

As soon as you root, you can no longer guarantee root activities are not taking place unbeknownst to you

You can never guarantee this however if you are careful what you install you will remain safe same as it was before.

[-] notfromhere@lemmy.ml 3 points 7 months ago

That goes for unrooted phones as well. The danger with rooting a phone comes from the automated software that is doing the initial rooting. It could install anything in there and the user would be none the wiser. Once it’s rooted and permissions are requested via the superuser app, it’s not any more dangerous than a non-rooted phone, assuming nothing malicious was installed during the rooting process, that is.

[-] evo@sh.itjust.works 3 points 7 months ago

Once it’s rooted and permissions are requested via the superuser app

And you expect this piece of community software (that is often closed source to avoid detection by safetynet) is perfect? Never had any bugs or exploits?

it’s not any more dangerous than a non-rooted phone

The SU software itself is an attack vector. One with the ultimate payoff (root access). When you root the device you install a window in what was otherwise a solid wall. It is inherently less secure and I can't understand how a knowledgeable person would argue otherwise.

[-] michaelmrose@lemmy.world 2 points 7 months ago

SU software has been a thing for about as long as android about 20 years or about. Has otherwise legitimate su been a source of unattended exploiting?

The obvious risk factors are that users shall be tricked into granting inappropriate permissions to otherwise malicious or compromised software that they have deliberately installed. Outside of mobile platforms this is considered an acceptable risk that competent users can consistently successfully manage on their own hardware.

In fact if you look at actual users even those with very limited technical know how the primary thing that

The secondary risk is that users with no legit source of tools to root

[-] notfromhere@lemmy.ml 2 points 7 months ago* (last edited 7 months ago)

I agree with what you’re saying, but all software is insecure and it should be up to the user what their risk tolerance is. Instead, users’ control of their equipment is whittled down and before long the only choice will be deal with it or don’t play. Pinephone comes to mind as a phone with root access that is somewhat secure, but it also has latent vulnerabilities that could be exploited as its version of sudo is also an attack vector. Everything is a trade off especially in software/tech.

[-] evo@sh.itjust.works 2 points 7 months ago

but all software is insecure and it should be up to the user what their risk tolerance is

Yes. And app developers/companies should in turn do the same. A banking app and a lemmy app probably don't have the same security requirements. Each needs to apply the appropriate security constraints, and if that means not allowing rooted decices that's fair imo.

[-] knobbysideup@sh.itjust.works 10 points 7 months ago

I'm not even rooted and gpay keeps breaking on crdroid for me, despite passing safetynet. I've given up and just got another credit card that I can use with my garmin watch that works every time without the hassle.

[-] evo@sh.itjust.works 7 points 7 months ago

Yeah, I'm going to get downvoted into oblivion for this...

I'm sick and tired of reading this same uneducated argument. Your desktop browser and an app on your phone are entirely different paradigms security/development wise.

Your desktop browser is expected to be insecure. Nobody stores data there besides cookies. Most processing happens somewhere else on a server.

Apple and Google have changed this stance entirely because they knew apps could be a lot more powerful if they did. The API's that exist to build apps on your phone are designed around the concept of having a secure, sandboxed environment per app. Apps can run offline and manipulate data quickly because data can be synced down and stored locally. I know it sucks for rooted users, but I don't blame developers for refusing to support those devices one bit.

[-] Norodix@lemmy.world 8 points 7 months ago

We all get that the design paradigm is "a secure, sandboxed environment per app". We just know its a retarded design.

[-] umbrella@lemmy.ml 4 points 7 months ago* (last edited 7 months ago)

how would an unrooted but old, deprecated version of android be any better than an updated custom rom?

those things baffle me, they just want to take away control dont they?

this post was submitted on 01 Mar 2024
305 points (100.0% liked)

Android

27761 readers
162 users here now

DROID DOES

Welcome to the droidymcdroidface-iest, Lemmyest (Lemmiest), test, bestest, phoniest, pluckiest, snarkiest, and spiciest Android community on Lemmy (Do not respond)! Here you can participate in amazing discussions and events relating to all things Android.

The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:

Rules


1. All posts must be relevant to Android devices/operating system.


2. Posts cannot be illegal or NSFW material.


3. No spam, self promotion, or upvote farming. Sources engaging in these behavior will be added to the Blacklist.


4. Non-whitelisted bots will be banned.


5. Engage respectfully: Harassment, flamebaiting, bad faith engagement, or agenda posting will result in your posts being removed. Excessive violations will result in temporary or permanent ban, depending on severity.


6. Memes are not allowed to be posts, but are allowed in the comments.


7. Posts from clickbait sources are heavily discouraged. Please de-clickbait titles if it needs to be submitted.


8. Submission statements of any length composed of your own thoughts inside the post text field are mandatory for any microblog posts, and are optional but recommended for article/image/video posts.


Community Resources:


We are Android girls*,

In our Lemmy.world.

The back is plastic,

It's fantastic.

*Well, not just girls: people of all gender identities are welcomed here.


Our Partner Communities:

!android@lemmy.ml


founded 1 year ago
MODERATORS