Earlier quoted context omitted.
Google provides attestation and it's a constant cat-and-mouse game that the rooters are usually losing. Websites can't tell, but lots of companies don't provide equivalent functionality via website. I know I can't upload check images for remote deposit unless I use the native banking app.
It's called SafetyNet [1] What irked me is sometime app developers are abusing it without asking themself "Does this app really need to check for rooted phones at all?" I'm okay if banks apps are using that. But why does fast foods apps need to use that? Most people that I know are paying with cash when they order foods online (and you can't hack paper money with rooted android phones). [1] https://developer.android.…
like having to rotate your password every 3 weeks and requiring 4 special characters/...