Live data from Hacker News

Pokemon Go, Security, and Obsolescence

community.rapid7.com

91–100 of 109 posts

Re: Pokemon Go, Security, and Obsolescence

#91
post #2

Now Niantic's decision to disallow root devices, imo, is pretty regretful, as serious botters will likely be able to get around that restriction regardless. This only serves to punish users who are stuck between having a root-enabled custom ROM or a stock ROM where critical root exploits may exist. One thing that I observed is that no one seems to be interested in producing a ROM that is both stable, has a variety of…

Root by itself does not break security entirely. Selinux policies and capabilities assigned to binaries can be used to drastically mitigate privileged processes from doing much harm.

Re: Pokemon Go, Security, and Obsolescence

#92
post #89

Earlier quoted context omitted.

You literally didn't need to do any of this (and I'm astonished someone would wait through a CM build rather than do ten minutes of research). Also, I'd like to remind you that SEAndroid (i.e., SELinux) doesn't give a fig about "root" so your statements about that are quite wrong. You can simply rename your su binaries through the recovery environment to disable them, which neatly disables "root access" and makes the…

> You literally didn't need to do any of this. For me personally, this is not the reason for me to build CyanogenMod. I will occasionally modify certain things inside android to suit my needs and there are enough of these things that are not merged upstream that it's more convenient for me to just build my own version every month/week/whenever. > Also, I'd like to remind you that SEAndroid (i.e., SELinux) doesn't giv…

How do you non-root using people backup your phones, without running the backup software as root?

Re: Pokemon Go, Security, and Obsolescence

#93
post #41

When I have a choice between Pokemon Go or root, I choose root every single time. I loathe Niantic for this stupid decision. The equivalent would be if Riot decided that League of Legends can only be played on PCs with a guest account and not an admin account. Completely pointless and dumb. I can't believe I bought some stuff in the Pokemon Go store, I want a refund. They robbed me, a legitimate and paying customer,…

There is it's called Magisk (it's not as simple as installing but it does exist!)

I know about Magisk and it's a hassle. Not worth doing for pokemon go.

Re: Pokemon Go, Security, and Obsolescence

#94
post #21

After all, the root blocking in Pokémon Go is pretty weak. All I had to do was to rename/move the 'su' binary and then it worked again.

This did not work for every user - for example my buddy bought an Asus Zenfone 2 (ZE551ML) specifically to play this game. I warned him not to buy from a China seller but he proceeded because he was finding guides that told him it was a great phone for the game - he literally bought this phone to play this game. I attempted to remove root however this has now forced the phone to be stuck on Edge network (he can play…

isn't zenfone a non-ARM device too?

Re: Pokemon Go, Security, and Obsolescence

#95
post #54

Earlier quoted context omitted.

> + Disabled footpad tracking made it less fun. That made me quit too. It's basically a slot machine now. You can't hunt anymore, you just have to accidentally stumble across something. > + Gameplay is highly repetitive past lvl 20 I would say gameplay is highly repetitive in general. You're basically just throwing Pokeballs around hoping something sticks. Sometimes a gym battle once you get to that point but most gy…

I started just after footpad tracking was disabled, but now "Sightings" lets me track down 'mons just fine. Maybe it's more work than footpad? I wouldn't know.

That only exists in San Francisco. Anywhere else, we are pretty much blind without cheating tools. Besides, the Sightings system is only helpful in areas with high pokestop density: Without it, the system wouldn't help: There are ZERO pokestops in a one mile radius around me. The nearest area with pokestops has 5 clustered together in a park... that has no pokemon spawns barring luring pokestops.

Third party tracking systems let me go with my son pokehunting in my subdivision: we could see a pokemon we want, and leave the house to look for it. Without that, the game is no fun, as a typical trip will only yield pidgeys and weedles.

Re: Pokemon Go, Security, and Obsolescence

#96
post #73

Earlier quoted context omitted.

Furthermore, you can buy GPS spoofing devices anwyay which you can just carry around with you in your pocket.

Furthermore, you don't need a device at all if you want to bot. The unofficial API (and client-side signing) was figured out a while back.

Got a link for that? I'd like to go read about it. Primarily as what NOT to do ... :)

Re: Pokemon Go, Security, and Obsolescence

#97
This story hits close to home - I have the exact same problem as the blogger. I own a Nexus 4, run the latest CyanogenMod 13, played Pokémon GO for a while, and was blocked in the September update. I never used the root features of my phone, and tried some attempts to remove the root without success. Shame on Niantic for being so heavy-handed on its users.

Re: Pokemon Go, Security, and Obsolescence

#98

Surprised people are still playing Pokemon Go. Niantic made all the wrong moves.

> Niantic made all the wrong moves.

The problem is that Niantic recreated Ingress instead of creating Pokemon. So, the Pokemon players are leaving after the initial hype. The worst part is that Niantic has scads of data as to what game the players want to play and has failed to implement it.

The other piece to this is that it really seems like Niantic don't have a stake in whether Pokemon Go continues to succeed. I suspect Niantic was desperate, Nintendo beat them up in negotiations, gave them a fixed payment, and then flogged them mercilessly. The terribly slow pace of reaction reeks of:

" We don't automatically get a percentage of success, so we're not going to implement that without more money."

" Well, let me discuss that with my manager. But we expect you to be honorable and fix this anyway."

" Uh, yeah. Sure. We'll work real hard on the promise that we might get paid when we're already having to do WAY more than we expected in terms of support given what you paid us. Yeah. We'll get right on that." Rolls eyes, and goes back to team "Do the MINIMUM you need to keep it from burning down and NOTHING else".

Re: Pokemon Go, Security, and Obsolescence

#99
post #92
post #89

Earlier quoted context omitted.

> You literally didn't need to do any of this. For me personally, this is not the reason for me to build CyanogenMod. I will occasionally modify certain things inside android to suit my needs and there are enough of these things that are not merged upstream that it's more convenient for me to just build my own version every month/week/whenever. > Also, I'd like to remind you that SEAndroid (i.e., SELinux) doesn't giv…

How do you non-root using people backup your phones, without running the backup software as root?

If you never change any files outside of the ones you own (i.e. the ones owned by "root"), you don't need to back them up, right? For example, if I never touch any of the files under C:\Windows, I have no need to back up that folder (especially the files owned by SYSTEM that you can't access).

Re: Pokemon Go, Security, and Obsolescence

#100
post #60

Earlier quoted context omitted.

Maybe my comment was unnecessarily rude, but demanding a refund and calling a company a piece of shit because you got banned for cheating is absolutely entitlement. Just because you spend money on a service does not entitle you to have unlimited access against TOS.

What makes you think that person was cheating?

They were banned. Niantic ban for what they consider cheating. I figured if the OP was mistakenly banned for some reason they probably would have mentioned that in their original comment.
Post reply on HN