Live data from Hacker News

OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

calif.io

41–50 of 62 posts

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#41

I wonder if there is a vulnerability that allows for toggling wireless adb. I have an LG with android 12 which technically should support wireless ADB but LG stripped the option from settings. Some say they stripped out the feature entirely. On top of that the USB port is damaged and doesnt accept data but still accepts power. So no wired adb either.

What's stopping you from rooting it and then sshing in? You can then run the adb commands using root access.

> What's stopping you from rooting it

(probably the broken USB port)

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#42

I wonder if there is a vulnerability that allows for toggling wireless adb. I have an LG with android 12 which technically should support wireless ADB but LG stripped the option from settings. Some say they stripped out the feature entirely. On top of that the USB port is damaged and doesnt accept data but still accepts power. So no wired adb either.

> On top of that the USB port is damaged and doesnt accept data but still accepts power.

Data is broken on both sides of the port? (if you rotate the plug 180° it should use the other pins on the USB-C)

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#43
post #26

Earlier quoted context omitted.

Some apps such as Aegis allow exporting the MFA secrets.

I think they allow importing from Authy but only on rooted phones. I missed the train to move away from Authy in 2024 and now the only non-root option is to regenerate the seed from every provider one by one. As other commenters said, rooting my main phone would lock me out of banking apps. I suppose I could find an old phone, sync from authy cloud, root it, and then migrate, but then generating new seeds is probably…

It's not quick, but you can submit a GDPR/Subject Access Request to Twilio and after a month or two they will send you all your Authy TOTP seeds.

Then you can import them into Aegis or some other FLOSS solution: https://github.com/uiltondutra/authy-migrate

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#44

Probably wishful thinking but does this get us any closer to porting postmarketOS to these devices? (Or even LineageOS, though I think LineageOS may have decent support on many of these devices already?)

Don't really see why. The issue with PostmarketOS is that there isn't enough people working on it. Not that the phones are locked down. Otherwise phones with open bootloader would have good support.

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#45
post #29

You'd almost think supporting a phone for a longer amount of time might actually be better than trying to sell a new phone every year or two.

Only if you find a way to create revenue beyond the time-of-purchase, to offset the cost of development and maintenance, aka service revenue.

So far only Apple achieved this by ensuring a walled garden around their ecosystem, securing additional revenue-share for every single 3rd party app and every transaction of the user.

All other vendors are structurally prevented to properly compete in services, and have to rely on Google paying some minor revenue-share on Services, while having only limited control over the user-experience to distinguish themselves...

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#46
post #26

Earlier quoted context omitted.

I think they allow importing from Authy but only on rooted phones. I missed the train to move away from Authy in 2024 and now the only non-root option is to regenerate the seed from every provider one by one. As other commenters said, rooting my main phone would lock me out of banking apps. I suppose I could find an old phone, sync from authy cloud, root it, and then migrate, but then generating new seeds is probably…

It's not quick, but you can submit a GDPR/Subject Access Request to Twilio and after a month or two they will send you all your Authy TOTP seeds. Then you can import them into Aegis or some other FLOSS solution: https://github.com/uiltondutra/authy-migrate

So there is a real solution to that problem! Thanks a lot for sharing it

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#47
post #15

Slightly unrelated: is it relatively safe to root android phones nowadays or should I stick to the unrooted standard android? The reason I'm asking is that I'm stuck with authy as a MFA code app, and would like to move to something that has both desktop and phone support, and my conclusion is I'd need to root my phone to get access to the actual MFA seeds (they don't allow exports to keep you stuck in their app).

The answer really depends. Root by what means? And to what end? Permanent or only temporarily?

Personally I reject with extreme prejudice the android security model (it's my &#^@ device not the vendor's). But I don't generally want to grant any apps root. Lineage strikes a nice balance by providing root adb.

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#48

I wonder if there is a vulnerability that allows for toggling wireless adb. I have an LG with android 12 which technically should support wireless ADB but LG stripped the option from settings. Some say they stripped out the feature entirely. On top of that the USB port is damaged and doesnt accept data but still accepts power. So no wired adb either.

> On top of that the USB port is damaged and doesnt accept data but still accepts power. Data is broken on both sides of the port? (if you rotate the plug 180° it should use the other pins on the USB-C)

Tried both sides but no luck.

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#49
post #26

Earlier quoted context omitted.

I think they allow importing from Authy but only on rooted phones. I missed the train to move away from Authy in 2024 and now the only non-root option is to regenerate the seed from every provider one by one. As other commenters said, rooting my main phone would lock me out of banking apps. I suppose I could find an old phone, sync from authy cloud, root it, and then migrate, but then generating new seeds is probably…

It's not quick, but you can submit a GDPR/Subject Access Request to Twilio and after a month or two they will send you all your Authy TOTP seeds. Then you can import them into Aegis or some other FLOSS solution: https://github.com/uiltondutra/authy-migrate

That is alarming. They have access to the plaintext? And they will hand auth secrets out? That seems extremely wrong to me.

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#50

Earlier quoted context omitted.

It's not quick, but you can submit a GDPR/Subject Access Request to Twilio and after a month or two they will send you all your Authy TOTP seeds. Then you can import them into Aegis or some other FLOSS solution: https://github.com/uiltondutra/authy-migrate

That is alarming. They have access to the plaintext? And they will hand auth secrets out? That seems extremely wrong to me.

They always had access to the plaintext, they could do better to hand them out
Post reply on HN