7 ms·
> Imagine tax software (comercial or gov provided) refusing to work unless you use an OS with TPM support for "security reasons". > I don't think this will hap
by IvanAchlaqullah 5y ago
> Imagine tax software (comercial or gov provided) refusing to work unless you use an OS with TPM support for "security reasons".
> I don't think this will happen any time soon (hopefully) but I can see how even making your own hardware might no be enough.
This already happened in Android, at least where I lives (Indonesia). Most of Banks, Government Services, and freaking McDonald's apps will refuse to run if your phone are rooted "for security reason".
- TedDoesntTalk 5y agoHonest question: how do those apps know your phone is rooted, and can you still use their websites for equivalent functionality?
- pxeboot 5y agoThe most popular root solutions have a "hide" feature so apps you specify can't tell you are rooted. It is slightly more complicated with custom roms. I have Google Pay and several banking apps on my rooted phone without issue.
- SXX 5y agoDoes your phone pass hardware attestation? Google can make it mandatory at any moment and then you won't be able to "hide" anything.
- dane-pgp 5y agoPresumably a website could support WebAuthn and require you log in using a "Platform Authenticator" like Windows Hello.[0] One way or another, websites will end up requiring that only "secure" devices access them (preferably disclosing a unique serial number registered to them). [0] https://www.hypr.com/platform-authenticator/ https://www.hypr.com/platform-authenticator/
- zbrozek 5y agoGoogle provides attestation and it's a constant cat-and-mouse game that the rooters are usually losing. Websites can't tell, but lots of companies don't provide equivalent functionality via website. I know I can't upload check images for remote deposit unless I use the native banking app.
- IvanAchlaqullah 5y agoIt's called SafetyNet [1] What irked me is sometime app developers are abusing it without asking themself "Does this app really need to check for rooted phones at all?" I'm okay if banks apps are using that. But why does fast foods apps need to use that? Most people that I know are paying with cash when they order foods online (and you can't hack paper money with rooted android phones). [1] https://developer.android.com/training/safetynet/attestation https://developer.android.com/training/safetynet/attestation
- rossy 5y ago> I'm okay if banks apps are using that. I'm not okay with it, to be honest. It's my money, and I trust a rooted LineageOS with it much more than I trust the default firmware of most phones. Besides, my bank lets you do the same operations from their website that you can do with the app, so in my case it's pure inconvenience, not security.
- blibble 5y agoprobably becomes a tick on an auditor's checklist like having to rotate your password every 3 weeks and requiring 4 special characters/...
- ryanlol 5y agoPlatforms like deliveroo have lost tens of millions to fraud, I don’t blame them for enforcing safetynet. Perhaps “food delivery” means pizza to you, but there are many places where it also includes thousand dollar bottles of wine.
- zbrozek 5y ago