Live data from Hacker News

OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

calif.io

21–30 of 61 posts

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#21

A good security track record must be the most valuable company asset in history. Apple makes $200B per year from selling the iPhone alone. Plus the services they sell on it, plus deals like the one with Google, plus app store ads, plus cross-selling of other hardware ... I have one too. Not because I like the hardware too much. Pixel phones are much nicer, they don't wobble when you put them on a table. Not because I…

Doesn't make a difference if Apple takes security more seriously if they bend like a rubber pole when the government comes asking...

That depends on your threat model.

Realistically intelligence agencies aren’t too interested in my grandma, but malware/scams/bloatware absolutely are.

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#22
post #12

Earlier quoted context omitted.

Your post is essentially admitting that you're ignoring the bugs from the company you love and taking seriously form the company you don't. So the difference isn't about taking things "more seriously", but in the fact that you take marketing from Apple more seriously. That's not the same. (Note: There's plenty of proof that Apple does take security more seriously than Samsung, Xiaomi & Co. in the article, but your fe…

Good thing they never claimed their feelings were proof of anything.

This is where reading ability comes into play.

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#23
post #15

Slightly unrelated: is it relatively safe to root android phones nowadays or should I stick to the unrooted standard android? The reason I'm asking is that I'm stuck with authy as a MFA code app, and would like to move to something that has both desktop and phone support, and my conclusion is I'd need to root my phone to get access to the actual MFA seeds (they don't allow exports to keep you stuck in their app).

It was never particularly safe to root the phone - both because it drills a hole into the security model and because you don't have any good ways of verifying what apps asking for root actually do.

Moreover, most of root tools and ROMs are rather poorly written and glued together with other forum scripts which you have no way of checking if they're not malware. (There are exceptions.)

So no, "safe" it's not and never has been. The tradeoff might be worth it for you as a user though.

> The reason I'm asking is that I'm stuck with authy as a MFA code app, and would like to move to something that has both desktop and phone support, and my conclusion is I'd need to root my phone to get access to the actual MFA seeds (they don't allow exports to keep you stuck in their app).

The way to do that is to take the hit and recreate your 2FA codes in an opensource app like Aegis or Stratum.

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#24

A good security track record must be the most valuable company asset in history. Apple makes $200B per year from selling the iPhone alone. Plus the services they sell on it, plus deals like the one with Google, plus app store ads, plus cross-selling of other hardware ... I have one too. Not because I like the hardware too much. Pixel phones are much nicer, they don't wobble when you put them on a table. Not because I…

It's a bit ironic to think Apple takes security seriously when they infamously delivered ridiculous bugs like 2017 High Sierra root login, which they fixed and then accidentally unfixed again.

What we're seeing is marketing/branding and a genuine for-show effort, all the while they do not audit their code outside some for-show technologies (Siri AI in the cloud).

So the point I am making is that it's all observational bias. You want actual objective security, use GrapheneOS.

And I'm saying this as an iPhone user.

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#25
post #23
post #15

Slightly unrelated: is it relatively safe to root android phones nowadays or should I stick to the unrooted standard android? The reason I'm asking is that I'm stuck with authy as a MFA code app, and would like to move to something that has both desktop and phone support, and my conclusion is I'd need to root my phone to get access to the actual MFA seeds (they don't allow exports to keep you stuck in their app).

It was never particularly safe to root the phone - both because it drills a hole into the security model and because you don't have any good ways of verifying what apps asking for root actually do. Moreover, most of root tools and ROMs are rather poorly written and glued together with other forum scripts which you have no way of checking if they're not malware. (There are exceptions.) So no, "safe" it's not and never…

Thanks for the summary. I agree with you about 2FA, but it's still annoying, I was hoping I would find a lazier solution.

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#26
post #15

Slightly unrelated: is it relatively safe to root android phones nowadays or should I stick to the unrooted standard android? The reason I'm asking is that I'm stuck with authy as a MFA code app, and would like to move to something that has both desktop and phone support, and my conclusion is I'd need to root my phone to get access to the actual MFA seeds (they don't allow exports to keep you stuck in their app).

Some apps such as Aegis allow exporting the MFA secrets.

I think they allow importing from Authy but only on rooted phones. I missed the train to move away from Authy in 2024 and now the only non-root option is to regenerate the seed from every provider one by one. As other commenters said, rooting my main phone would lock me out of banking apps. I suppose I could find an old phone, sync from authy cloud, root it, and then migrate, but then generating new seeds is probably both safer and faster at that point.

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#28
I wonder if there is a vulnerability that allows for toggling wireless adb. I have an LG with android 12 which technically should support wireless ADB but LG stripped the option from settings. Some say they stripped out the feature entirely. On top of that the USB port is damaged and doesnt accept data but still accepts power. So no wired adb either.

Re: OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

#30
post #26

Earlier quoted context omitted.

Some apps such as Aegis allow exporting the MFA secrets.

I think they allow importing from Authy but only on rooted phones. I missed the train to move away from Authy in 2024 and now the only non-root option is to regenerate the seed from every provider one by one. As other commenters said, rooting my main phone would lock me out of banking apps. I suppose I could find an old phone, sync from authy cloud, root it, and then migrate, but then generating new seeds is probably…

Importing is usually not an issue, as you can always enter the secret manually. It is the exporting that is the problem.

The secret looks something like this:

JBSW Y3DPF QQHO ....

(usually fairly short unless its google)

Post reply on HN