Live data from Hacker News

Pokemon Go, Security, and Obsolescence

community.rapid7.com

11–20 of 109 posts

Re: Pokemon Go, Security, and Obsolescence

#11
For all I want a good tracker, and the sympathy I have for friends I have with rooted devices who can no longer play...

Niantic is not beholden to anyone to release anything, add any features, or do anything.

Its their game.

If you don't like it, either a) don't play, or b) make something better.

It's a testament to the compellingness of the AR game genre, and the brand recognition that Pokemon has they so many people are willing to put so much time and effort into the game despite how primitive it is.

People calling for an open API are fooling themselves. Why on earth would they give away the keys to the kingdom?

Hacking the protocol and the cheaters created this situation.

They have only themselves to blame for it. Cry. Me. A. River.

You might say that serious cheaters can bypass the restrictions / measures, but clearly from the fuss (and that fastpokemap is still down), its doing the intended job pretty much spot on.

Realistically, nothing is going to change, unless someone starts offering a compelling alternative to drive innovation.

Re: Pokemon Go, Security, and Obsolescence

#12
post #2

Now Niantic's decision to disallow root devices, imo, is pretty regretful, as serious botters will likely be able to get around that restriction regardless. This only serves to punish users who are stuck between having a root-enabled custom ROM or a stock ROM where critical root exploits may exist. One thing that I observed is that no one seems to be interested in producing a ROM that is both stable, has a variety of…

> I personally got around this problem by compiling a build of CyanogenMod without root enabled, but with things like FDroid (with PrivilegeExtension) and adblock built-in to the ROM itself...

I just bought a Nexus 5x and loaded CopperheadOS on it, and to my dismay I see Ad-Away from F-Droid requires root to function (plus a couple other apps I really like). How much of a hassle is it really, because I absolutely want system wide ad blocking and I worry that I will be defeating the purpose of using a hardened OS in the first place?

Do you rebuild and flash each OS update as a new ROM? Is all your data on the phone persistent or backed up & restored each time?

Re: Pokemon Go, Security, and Obsolescence

#13
post #4
post #2

Now Niantic's decision to disallow root devices, imo, is pretty regretful, as serious botters will likely be able to get around that restriction regardless. This only serves to punish users who are stuck between having a root-enabled custom ROM or a stock ROM where critical root exploits may exist. One thing that I observed is that no one seems to be interested in producing a ROM that is both stable, has a variety of…

I wrote this about Android a while back: http://penguindreams.org/blog/android-fragmentation/ The TLDR is that it'd be nice if Android was more like Windows/Intel: install the OS (i.e. AOSP), drivers (or binary driver package format and an SDK to auto-build it) and boom you're done. Clean, stock, standard. Same with many Linux distros on x86/64. I need to write an update to the article though. Lately I've been strugg…

Some related posts:

https://cascardo.eti.br/blog/GNU_on_Smartphones_part_II/ http://bonedaddy.net/pabs3/log/2012/12/03/debian-mobile/ https://wiki.debian.org/Mobile

Re: Pokemon Go, Security, and Obsolescence

#14

Surprised people are still playing Pokemon Go. Niantic made all the wrong moves.

Me too. Kids still do. They seem to jump on/off the latest craze a lot slower. It gives them something to do while walking with their parent, which is inherently boring to them.

Re: Pokemon Go, Security, and Obsolescence

#15
post #8

Earlier quoted context omitted.

They've gotta stop the GPS spoofers somehow. It's not like this was the first solution they jumped to to stop cheaters. Maybe this was the 80/20 solution over more advanced location anomaly detection methods against their database.

The problem is that you don't need root for GPS spoofing. Botters also don't care about SafetyNet (used to detect root before the game starts), since they reverse engineer the API and make REST calls directly. Furthermore, there are ways around the root check - mostly involving hiding the su binary and some additional tweaks.

Furthermore, you can buy GPS spoofing devices anwyay which you can just carry around with you in your pocket.

Re: Pokemon Go, Security, and Obsolescence

#18
post #2

Now Niantic's decision to disallow root devices, imo, is pretty regretful, as serious botters will likely be able to get around that restriction regardless. This only serves to punish users who are stuck between having a root-enabled custom ROM or a stock ROM where critical root exploits may exist. One thing that I observed is that no one seems to be interested in producing a ROM that is both stable, has a variety of…

A few botters don't hurt Pokémon go. But when it's easy to bot, lots of people will bot. It's easy to circumvent anti root, but it's impossible to use the same way for lots of devices without niantic being able to block it again.

So it really makes sense for them to go this way IMO.

Re: Pokemon Go, Security, and Obsolescence

#19
post #8

Earlier quoted context omitted.

The problem is that you don't need root for GPS spoofing. Botters also don't care about SafetyNet (used to detect root before the game starts), since they reverse engineer the API and make REST calls directly. Furthermore, there are ways around the root check - mostly involving hiding the su binary and some additional tweaks.

Furthermore, you can buy GPS spoofing devices anwyay which you can just carry around with you in your pocket.

To be fair, that's probably highly illegal if caught by the fcc.

Re: Pokemon Go, Security, and Obsolescence

#20

For all I want a good tracker, and the sympathy I have for friends I have with rooted devices who can no longer play... Niantic is not beholden to anyone to release anything, add any features, or do anything. Its their game. If you don't like it, either a) don't play, or b) make something better. It's a testament to the compellingness of the AR game genre, and the brand recognition that Pokemon has they so many peopl…

> Hacking the protocol and the cheaters created this situation.

> They have only themselves to blame for it. Cry. Me. A. River.

What does this have to do with the article, written by someone who didn’t cheat?

> If you don't like it, either a) don't play, or b) make something better.

Yes, everyone affected by this is rather forced to pick (a). Occasionally, they may write articles. If you don’t like them, a) don’t read them.

Post reply on HN