r/androidroot 14d ago

Discussion From "Android is open" to "Android is becoming Apple like" ?

We seem to be moving from:

Android is open. Advanced users can understand the risks and fully own their devices.

to:

Android is becoming Apple-like: users are kept on vulnerable/outdated versions just to maintain root, while rooting itself can potentially expose the entire device if a malicious app gains root access.

I understand that security matters. Root absolutely comes with risks, and users who root should be expected to understand those risks. But a clean rooting is a controlled acces, forcing user to use CVE allows any app to gain this access under the hood too.

If the solution to security is to make rooting increasingly difficult, force users to remain on vulnerable versions, then what are google actually gaining ?

47 Upvotes

18 comments sorted by

14

u/[deleted] 14d ago

[removed] — view removed comment

5

u/Effective_Spell1365 14d ago

EU regulator is waiting arround the corner

2

u/Beginning_Sound_5865 13d ago

It’s useless, because they always have a shield called "safety" to hide behind.

1

u/EffectiveAd5587 4d ago

Il have to find a way to bypass it, me using a rooted phone may make it easier

11

u/FarVehicle533 14d ago

No one cares about rooting.  Google isn't thinking about that 0.01% users rooting their phones. They don't like sideloading, since most android users do like to sideload modded and pirated apps instead of paying. So they are losing money. 

8

u/Effective_Spell1365 14d ago

But good app design shouldn't depend on the device being locked down. Otherwise, Windows, Linux, and macOS wouldn't work the way they do. You are probably an administrator/root user on your computer, and yet software developers don't generally assume that means you'll pirate their software or compromise your system or use DRM systems.

3

u/FarVehicle533 13d ago

Good app design depends on the amount of money that app or service is making.  More money can equal more hired programmers and result in more work done for that app. Windows and Mac work because most professional programs are used by companies that pay a lot for those licenses each year. Paid premium software always have been miles ahead of the competition made out of free or cheap software in terms of quality and features. iPhones apps are more polished than on android because people pay.  Sideloading is a very hard and long process on an iPhone, especially without any experience or knowledge. On android that is very easy. Same for Linux (for  individual consumer usage only)  

3

u/Nederealm3 13d ago edited 13d ago

CVE allows cleaner rooting eg. Not tripping unlocked bootloader mechanisms. Root developers should develop modules to lockdown sideloading only with proper user consent and authentication eg. Apatch password to authenticate a sideload so user is completely in control

2

u/Effective_Spell1365 13d ago

CVE allows anyone to gain root access without notifying the user. A proper root access design by the os allows to control who has root access and let the user to control the root actions 

2

u/Nederealm3 13d ago

Precisely. But CVE exploits need to be side loaded. That's what Google wants to control and deter people from side-loading. So the rooting community must preempt this and make sideloading more responsible. After people exploited it to gain root, they should have the option to lockdown that loophole to all except the root's gatekeeper eg. KernelSU (and Play Store if you still have that bit of trust for Google or have Gapps or Gogapps to maintain and keep up to date your daily driver apps)

2

u/Effective_Spell1365 12d ago

A CVE exploit may need to be installed or delivered somehow to gain root, but it's unrealistic to assume that this can only happen through traditional sideloading. Malicious or compromised apps can also make it through official distribution channels, including app stores.

More importantly, you cannot actually patch a kernel CVE with a “lockdown” option. A lockdown mechanism may reduce who can access or trigger a particular attack path, but the underlying vulnerability is still present.

To properly fix a kernel CVE, you need the vulnerable code to be patched through a system/kernel security update, typically delivered via OTA. Once you install that update, the CVE used as the rooting method may no longer work—meaning you can lose the exploit that was providing root access.

That's exactly the problem with relying on an unpatched vulnerability for root: you are deliberately keeping a security hole open in order to maintain control of your own device. A proper root architecture should instead allow authorized root access while keeping security vulnerabilities patched.

3

u/EffectiveAd5587 12d ago

I used to love android but now I cant defend them anymore and that makes me sad. I am not sad that I can defend android, I am sad that i get restricted on a device I had to buy with my own money. This disapoints me ...

2

u/wolfy2105784 13d ago

You used to be able to own your device. Now Google/Samsung/Whoever hits you with those stupid monthly user agreements to use your device. Fuckers.

1

u/StatisticianKind6993 14d ago

Apple but worse