Depends on your phone, but for some qualcomm devices there was a vulnerability some time ago, iirc the OnePlus 15 has a dedicated thread on XDA. I also found this on XDA while trying to find the other exploit:
Side note, it's quite ironic, google being so heavily anti-root is forcing people to opt for root access via more hidden ways, making it easier to avoid root being detected.
A good security track record must be the most valuable company asset in history.
Apple makes $200B per year from selling the iPhone alone. Plus the services they sell on it, plus deals like the one with Google, plus app store ads, plus cross-selling of other hardware ...
I have one too.
Not because I like the hardware too much. Pixel phones are much nicer, they don't wobble when you put them on a table. Not because I like the software too much. Android is much more to my liking with more freedom to customize it.
But because I have the feeling Apple takes security more seriously.
I wish there was some kind of security arena like there is LLM arena for AI. That gives hard facts about the security track record of phone manufacturers.
I didn't find about OEMpocalypse from Google talking about their security issues, I found from calif.io. Security researchers don't wait for companies to "talk about their security".
> but the reality may be different because Android is more scrutinised.
This is famously why Linux appears to be less secure than Windows, right? Because Microsoft doesn't talk about their security while Linux is more scrutinized?
It's a bit ironic to think Apple takes security seriously when they infamously delivered ridiculous bugs like 2017 High Sierra root login, which they fixed and then accidentally unfixed again.
What we're seeing is marketing/branding and a genuine for-show effort, all the while they do not audit their code outside some for-show technologies (Siri AI in the cloud).
So the point I am making is that it's all observational bias. You want actual objective security, use GrapheneOS.
Funny since the GrapheneOS devs praise the iPhone for it's security.
I personally prefer seeing real advancement that integrate both hardware and software like their EMTE[1] which no other vendor has had the balls to implement.
And I say that as a GOS user! My next phone will definitely be an iPhone, mostly because I cannot deal with the terrible Tensor SOC. My G4 overheats for nothing! Shameful
Slightly unrelated: is it relatively safe to root android phones nowadays or should I stick to the unrooted standard android?
The reason I'm asking is that I'm stuck with authy as a MFA code app, and would like to move to something that has both desktop and phone support, and my conclusion is I'd need to root my phone to get access to the actual MFA seeds (they don't allow exports to keep you stuck in their app).
It was never particularly safe to root the phone - both because it drills a hole into the security model and because you don't have any good ways of verifying what apps asking for root actually do.
Moreover, most of root tools and ROMs are rather poorly written and glued together with other forum scripts which you have no way of checking if they're not malware. (There are exceptions.)
So no, "safe" it's not and never has been. The tradeoff might be worth it for you as a user though.
> The reason I'm asking is that I'm stuck with authy as a MFA code app, and would like to move to something that has both desktop and phone support, and my conclusion is I'd need to root my phone to get access to the actual MFA seeds (they don't allow exports to keep you stuck in their app).
The way to do that is to take the hit and recreate your 2FA codes in an opensource app like Aegis or Stratum.
Not sure why this is downvoted. It's accurate. A major problem is that when you root you loose assurance of the integrity of your /system partition. That means malware can now persist undetected.
The answer really depends. Root by what means? And to what end? Permanent or only temporarily?
Personally I reject with extreme prejudice the android security model (it's my &#^@ device not the vendor's). But I don't generally want to grant any apps root. Lineage strikes a nice balance by providing root adb.
I want the ability to grant specific apps root through Magisk. Tasker for example for tasks that change system level settings and adaway for system level adblocking, material files for accessing to root filesystem for pulling config files from apps, Swift Backups for backing up all my apps and their data.
AFAIK rooting an Android phone necessitates a factory reset of the phone beforehand, so I don't think you'd be able to dump the MFA seeds before Authy is uninstalled (unless that's a hardware thing)
That was never the case back when I was rooting phones. Sometimes the phone would reboot immediately after getting root so that you could do something useful like installing recovery, but maybe something has changed.
I wonder if there is a vulnerability that allows for toggling wireless adb. I have an LG with android 12 which technically should support wireless ADB but LG stripped the option from settings. Some say they stripped out the feature entirely. On top of that the USB port is damaged and doesnt accept data but still accepts power. So no wired adb either.
Only if you find a way to create revenue beyond the time-of-purchase, to offset the cost of development and maintenance, aka service revenue.
So far only Apple achieved this by ensuring a walled garden around their ecosystem, securing additional revenue-share for every single 3rd party app and every transaction of the user.
All other vendors are structurally prevented to properly compete in services, and have to rely on Google paying some minor revenue-share on Services, while having only limited control over the user-experience to distinguish themselves...
This would be a bit convincing if there weren't other hardware and services providers like Fairphone, GrapheneOS and Google themselves, who do support and maintenance for longer.
The fact that you put "Google themselves" in this list makes the conversation moot, because Google is de-facto the service-revenue recipient of the entire Android device-ecosystem and the culprit of the problem.
1. Fairphone actually demonstrates that it's not a matter of "want" for sustainable/repairable/longevity, the market still doesn't reward sufficiently for it.
--> If the total potential is an increase in sales of 100k units at ~450 USD/device, there is no fiscal justification for a stock-trading company to actually build such a product. That's why e.g. the EU keeps mandating more and more of this, they "artificially" create the need for it because the market doesn't do it itself.
2. They don't have a comparable service revenue-ecosystem to Google, not even remotely.
Even in sum across their entire mobile ecosystem, the majority of service-revenue their products generate is actually Google's service revenue of the Android ecosystem, of which they get a miniscule revenue-share via Google's RSA program.
The only substantial revenue is still generated at the hardware time-of-sale only, which needs to finance the lifecycle maintenance of the product. So the objective becomes to sell a critical-mass of hardware to sustain the maintenance of the device.
And then, the next level: The market-pressure for in-time software-maintenance can only be fulfilled by not deviating too much from Google's baseline (minimizing the effort of upgrading to newer Android versions). Not deviating from Google's baseline means either contributing back any disruptive changes to Google for integration in the baseline or (more likely) to not disrupt the smartphone landscape on platform-level at all.
Disrupting with hardware innovation only works either on very-large scale or on small-scale, because either you can contract a component supplier for a huge volume of a component exclusive for you, or you pick a innovative component which cannot be supplied in huge quantity yet (and is therefore out of reach for larger brands)
As result, the established players on the smartphone market don't make any more innovative leaps, because the risk/benefit ratio for the ROI is just not there.
--> Vendors ship devices based on common hardware available at that time, combined with software available at that time.
Chinese vendors changed the game a bit by announcing devices with innovative hardware which then never reached the global market, because the components were not available at-scale yet (under-display camera, wrap-around displays, new battery composition, 5G,...) --> This was a game-changer because e.g. Samsung, Apple, Motorola, LG would not announce a device they knew they can't launch at-scale. Oppo, Xiaomi et al could do a limited run for a device-launch in China, with chinese component-suppliers shipping to assembly-factories in China with low ramp-up costs.
I think old Android phones not supported by their makers are so problematic in the LLM era. I would think that even before LLMs the 3 letter agencies had exploits for those, but now one should assume common criminals will...
I am happy that the pixel phone I got has 7 year of support, but it is clear that Apple is in general is much better in this than all the Android providers (including google)
Probably wishful thinking but does this get us any closer to porting postmarketOS to these devices? (Or even LineageOS, though I think LineageOS may have decent support on many of these devices already?)
Don't really see why. The issue with PostmarketOS is that there isn't enough people working on it.
Not that the phones are locked down. Otherwise phones with open bootloader would have good support.
45 comments
[ 1.3 ms ] story [ 46.9 ms ] thread(but would love to verify and use)
https://xdaforums.com/t/the-holy-grail-universal-no-bl-root-...
Side note, it's quite ironic, google being so heavily anti-root is forcing people to opt for root access via more hidden ways, making it easier to avoid root being detected.
Apple makes $200B per year from selling the iPhone alone. Plus the services they sell on it, plus deals like the one with Google, plus app store ads, plus cross-selling of other hardware ...
I have one too.
Not because I like the hardware too much. Pixel phones are much nicer, they don't wobble when you put them on a table. Not because I like the software too much. Android is much more to my liking with more freedom to customize it.
But because I have the feeling Apple takes security more seriously.
I wish there was some kind of security arena like there is LLM arena for AI. That gives hard facts about the security track record of phone manufacturers.
Realistically intelligence agencies aren’t too interested in my grandma, but malware/scams/bloatware absolutely are.
This might make Apple to look like the more secure option but the reality may be different because Android is more scrutinised.
I didn't find about OEMpocalypse from Google talking about their security issues, I found from calif.io. Security researchers don't wait for companies to "talk about their security".
> but the reality may be different because Android is more scrutinised.
This is famously why Linux appears to be less secure than Windows, right? Because Microsoft doesn't talk about their security while Linux is more scrutinized?
What we're seeing is marketing/branding and a genuine for-show effort, all the while they do not audit their code outside some for-show technologies (Siri AI in the cloud).
So the point I am making is that it's all observational bias. You want actual objective security, use GrapheneOS.
And I'm saying this as an iPhone user.
I personally prefer seeing real advancement that integrate both hardware and software like their EMTE[1] which no other vendor has had the balls to implement.
And I say that as a GOS user! My next phone will definitely be an iPhone, mostly because I cannot deal with the terrible Tensor SOC. My G4 overheats for nothing! Shameful
[1] https://security.apple.com/blog/memory-integrity-enforcement...
Moreover, most of root tools and ROMs are rather poorly written and glued together with other forum scripts which you have no way of checking if they're not malware. (There are exceptions.)
So no, "safe" it's not and never has been. The tradeoff might be worth it for you as a user though.
> The reason I'm asking is that I'm stuck with authy as a MFA code app, and would like to move to something that has both desktop and phone support, and my conclusion is I'd need to root my phone to get access to the actual MFA seeds (they don't allow exports to keep you stuck in their app).
The way to do that is to take the hit and recreate your 2FA codes in an opensource app like Aegis or Stratum.
Personally I reject with extreme prejudice the android security model (it's my &#^@ device not the vendor's). But I don't generally want to grant any apps root. Lineage strikes a nice balance by providing root adb.
(probably the broken USB port)
Data is broken on both sides of the port? (if you rotate the plug 180° it should use the other pins on the USB-C)
So far only Apple achieved this by ensuring a walled garden around their ecosystem, securing additional revenue-share for every single 3rd party app and every transaction of the user.
All other vendors are structurally prevented to properly compete in services, and have to rely on Google paying some minor revenue-share on Services, while having only limited control over the user-experience to distinguish themselves...
--> If the total potential is an increase in sales of 100k units at ~450 USD/device, there is no fiscal justification for a stock-trading company to actually build such a product. That's why e.g. the EU keeps mandating more and more of this, they "artificially" create the need for it because the market doesn't do it itself.
2. They don't have a comparable service revenue-ecosystem to Google, not even remotely.
Even in sum across their entire mobile ecosystem, the majority of service-revenue their products generate is actually Google's service revenue of the Android ecosystem, of which they get a miniscule revenue-share via Google's RSA program.
The only substantial revenue is still generated at the hardware time-of-sale only, which needs to finance the lifecycle maintenance of the product. So the objective becomes to sell a critical-mass of hardware to sustain the maintenance of the device.
And then, the next level: The market-pressure for in-time software-maintenance can only be fulfilled by not deviating too much from Google's baseline (minimizing the effort of upgrading to newer Android versions). Not deviating from Google's baseline means either contributing back any disruptive changes to Google for integration in the baseline or (more likely) to not disrupt the smartphone landscape on platform-level at all.
Disrupting with hardware innovation only works either on very-large scale or on small-scale, because either you can contract a component supplier for a huge volume of a component exclusive for you, or you pick a innovative component which cannot be supplied in huge quantity yet (and is therefore out of reach for larger brands)
As result, the established players on the smartphone market don't make any more innovative leaps, because the risk/benefit ratio for the ROI is just not there.
--> Vendors ship devices based on common hardware available at that time, combined with software available at that time.
Chinese vendors changed the game a bit by announcing devices with innovative hardware which then never reached the global market, because the components were not available at-scale yet (under-display camera, wrap-around displays, new battery composition, 5G,...) --> This was a game-changer because e.g. Samsung, Apple, Motorola, LG would not announce a device they knew they can't launch at-scale. Oppo, Xiaomi et al could do a limited run for a device-launch in China, with chinese component-suppliers shipping to assembly-factories in China with low ramp-up costs.
Nope nope nope. LLMs helped you do something cool, great. You can still speak for yourself. Stop outsourcing your humanity to a chatbot.
> In practice the coverage of each chain is exactly the set of devices the OEM chose to ship the vulnerable component on.
Wonderful insight, Claude. "The vulnerability covers exactly the devices that are vulnerable".