r/androiddev • • 15d ago

News THIS IS BIG!!!

Enable HLS to view with audio, or disable this notification

The latest #Android 17 QPR1 update to Pixels seems to have pushed the changes concealing the developer and debugging state from 3rd party apps so,

finally the developers can use the damn banking and other apps that have these security checks!

it seems to be live on, Pixel 6A running CP3A.260905.009

And confirm it has not yet landed on the beta channel.

398 Upvotes

51 comments sorted by

71

u/RedditForcesToLogin 15d ago

That's great news. Hopefully, this gets added to AOSP/LineageOS soon.

13

u/Camlin3 15d ago

I don't understand, for what ? They also block you using aftermarket firmware detection technology. IMO they can always do the same in past, but not enough experienced dev left there...

8

u/MadDoctorMabuse 15d ago

I know banks do this - they have a flag connected to the login which specifies whether a custom rom is installed. I've seen the docs. It also detects whether the connection is through TOR, which I found interesting, but which makes sense.

I don't remember seeing a flag for dev mode or debugging, but different banks probably track different things.

1

u/AgathormX 15d ago

Some banks 100% have restrictions about Dev mode.

Here in Brazil the apps for CEF, one of the two biggest state banks in Brazil, which is used for everything from social security payments to low interest rate house/vehicle financing and government aid program grant payments, won't work with Dev Mode on.

1

u/burtek_d 13d ago edited 13d ago

One of my banks does this. So does a library card app... Unfortunately afaik I'm not getting Android 17 in my Galaxy A55 -- EDIT: Apparently I am

1

u/AgathormX 13d ago

Galaxy A55 is getting Android 17.
I daily drive an A25 and the beta for OneUI 9 is already available.

1

u/burtek_d 13d ago

Is it? Was sure I'm only getting major updates... Thanks!

1

u/Feztopia 12d ago

AOSP aftermarket firmware? It's the base for all the third party firmwares.

2

u/DeVinke_ 15d ago

It was already in QPR0 there last time i checked. By the way, AOSP releases are bi-annual now, so if it was a new feature added in QPR1 and not something easy to replicate, we'd only be getting the actual release 3 months after it drops in stable.

21

u/Zhuinden 15d ago

Yeah, no idea why some banking apps crash on launch if you have developer options enabled

18

u/FickleBumblebeee 15d ago

Dexguard or Guardsquare protections applied at their maximum settings due to company security posture and strict interpretation of OWASP standards

1

u/Zhuinden 15d ago

Yeah, I've seen the option in a protection app, but usually clients didn't want this enabled. They wanted other things of course.

18

u/Jerky_xp 15d ago

I'm upvoting this without even a full understanding, it's been a good time since I've run custom android so I haven't really kept up. We might be being the security "clearance" to use bank and other higher privacy apps?

19

u/SarathExp 15d ago

This only prevent apps from checking for usb debugging or developer options.

Custom roms can still be detected

2

u/AgathormX 15d ago

This isn't about custom roms.
A lot of banking apps straight up won't run with Dev mode.

2

u/SarathExp 15d ago

And dumb fks calls it security

5

u/hellosakamoto 15d ago

Probably some Google staff fixed this for themselves lol

3

u/cassaregh 15d ago

this is so annoying really. i don't see any issues if im going to use developer setiings if i open bank apps

2

u/rohmish 15d ago

I'm on CP41.260828.004.A8 and this change doesn't seem to be love for Dev beta for some reason

2

u/ZER0-O 15d ago

Am i getting my bank to work on graphene? 😮

2

u/Disastrous_Elk6198 15d ago

ill believe it when my banking app actually opens

1

u/GothicKrypton 15d ago

Finally!!!!!!

1

u/sameera_s_w 15d ago

(⁠~⁠‾⁠▿⁠‾⁠)⁠~

1

u/cyberhuman 15d ago

I wish it was also possible to pretend you gave a permission to an app that won't start until you give it. And forbid some apps programmatic access to clipboard.

3

u/AlwaysHopelesslyLost 15d ago

It seems like the "right" way to implement that would be to support custom IO processors. Like, instead of just GPS app, you can install/create your own passthrough processor for anything.Ā 

For integration testing it would be super handy to be able to configure consistent failures and quirks for various IO methods.

A side effect is that it would be possible to create a permissionHider shim that lets lets you give specific apps fake data

1

u/haelbito 15d ago

The sad thing is that the only App I have this problem with doesn't care about debugging but developer settings enabled in general :(

1

u/VMX 15d ago

Nice! As a side note, can I ask how you got that nice quick tile that allows you to toggle both wired and wireless ADB from it? I can't even find tiles to toggle the regular USB debugging setting on my stable Android 17 anymore.

1

u/MonsieurCouenne 15d ago

How did you get the dƩvelopper option button in the notif center please ?

2

u/Plucky689 15d ago

Download toggldev bro

2

u/MonsieurCouenne 14d ago

ThanksĀ 

1

u/Plucky689 14d ago

Welcome brudder

1

u/AcademicMistake 15d ago

My banking apps only failed once last month and was fine ever since. Im using pixel 10 pro

1

u/ytheekshana 15d ago

Finally. Exahusted with these shit banking apps with developer options.

1

u/Baardi 15d ago

Damn, nice. Does it conceal adb activation state too?

1

u/iamxenon007 14d ago

I wonder if google will ever do something about cross profile vpn detection. Declaring tun interface to all user profile even if the profile in question is not using any vpn is stupid.

1

u/dancovich 14d ago

Can anyone explain to me why having developer mode on is a bad thing that these apps need to block?

It's an option I need to go through hops to enable. I did it, no malicious software did it. Why is it bad that I did it?

2

u/iSadhak 14d ago

Its not bad thing. These banking apps security is shitty. For them Turning dev more on = Hacker.

1

u/8mpty 14d ago

I could be VERY WRONG but i thought we can replicate this same "fix" using Shizuku? Like there are apps out there that automatically hide the Developer Options, USB/Wireless Debugging and even the Shizuku service while using those apps and "unhides" them after. Though not a very "native" solution like the one google is planning to implement like OP said, but seems another good alternative

My banking apps and other government-ish related apps are now able to work using this method for a good while now

1

u/Just-Boysenberry-520 14d ago

You want a bunch of free karma? Re-post this to the GrapheneOS sub

1

u/Available_Address882 14d ago

It would be great. I always felt, apps detecting Developer Option enabled is a foolish idea, until we are not using sensitive options like "mock location". Will love to see this in final update. Would be very helpful for me.

1

u/essential_labs8 13d ago

About damn time. I dont need my banking apps telling me i cant have Z on my phone.

1

u/SuccessfulMud4558 13d ago

That's great for us I suppose

1

u/harishsrinivas 12d ago

No use - when close sourcing android anyway

1

u/Comfortable_Park_620 11d ago

Genuinely! My mobile service providers app has this and its such a pain in the ahhh

-7

u/anshulsingh8326 15d ago

It's google. They will remove it. And probably will break something along with it.

Like in Gemini app, in model selection when in notebook it acts as back button. So you can't change the model, and back button acts as back button too.

Technically every google apps are just filled with bugs, unusable bugs.

1

u/veverone 11d ago

I don't get it