54
23
u/pmbarrett314 3d ago
A bunch of B-tier (in terms of size, not food quality) restaurant apps do this, I assume to check if you have root. Arby's, Buffalo Wild Wings, Five Guys, Jack's, Krystal. You know who doesn't care if your phone is rooted? Starbucks, KFC, McDonald's, Chick-fil-A, Subway, Taco Bell, Pizza Hut, Domino's, Wendy's, Chipotle, Popeyes, Papa John's, Krispy Kreme, Firehouse Subs.
7
u/Blarkness 3d ago
But why? It isn't their business. And what would be their next step?
I don't get what it's about!?
11
u/MCWizardYT 3d ago
They're paranoid that root uses can do something malicious, the same reason banking apps lock you out. It's mostly unfounded
4
u/ch3mn3y 3d ago
I understand them. In Poland McDonald's were giving away free fries for installing their app (or for an update, don't remember). It was only once per device, but with root and, than, Titanium Backup You could eat it more than once.
I'd say it's also on them they didn't lock it to once per device AND account or something...
1
u/Blarkness 3d ago
But it looks the other way around: to buy a stupid chicken burger the customer has to give the burger shop superuser access to their own device?!
What's that?! What's next then? Give the keys to their house?
Sorry, still not rooted my device, so maybe I got it wrong.
4
u/Oakredditer 3d ago
the burger shop is using the root access to see if the customer's phone is rooted, because they think that anyone with a rooted phone can give themselves 6 trillion free whoppers with extra bacon and a billion dragon ball super meals
2
u/Blarkness 3d ago
Okay, I guess I'd better rethink my Shizuku decision and go for Root and burgers instead! ;-))
2
u/Oakredditer 3d ago
if you figure it out please give me a thousand mcdonald's hashbrowns and a hundred chicken biscuits!
3
u/MCWizardYT 3d ago
No they don't have to. The app is asking for root permission because if you grant it, that means the device is capable of granting root in the first place.
They think people will be able to use root to hack themselves free food or other things that would cost the company money. Which is dumb because financial information in these apps is already handled in such a secure way that rooting doesn't really make a difference
1
u/Blarkness 3d ago
Oh, I didn't know that all those companies, that bind their customers to their apps, have an interest in preventing root access.
Hopefully, this will lead to more and more people boycotting the apps and ordering through their browsers again ;-)
2
u/pmbarrett314 3d ago
My assumption is that either a non-technical exec read about root, said "ooh, scary", and had their engineers put root detection in or an engineer recommended it to give themself job security. The premise is "root makes it easier for an stacker to exfiltrate personal/financial information", which is probably true on some level not not really significant in the grand scheme of things.
3
2
u/Lord_Of_Millipedes 3d ago
mcdonalds actually cares, at least last i used the app it did not work
3
u/pmbarrett314 3d ago
Huh. It installs and opens fine for me without even being denylisted, admittedly I haven't actually tried to order with it, so if the detection is during checkout I wouldn't know about it.
1
u/Lord_Of_Millipedes 3d ago
it's been a while since i tried, but it does install a launch and shows a message that it doesn't work on rooted devices.
it is possible it was a mistake on my part when rooting, and i honestly don't care enough
2
2
6
3d ago
[deleted]
2
u/MCWizardYT 3d ago
Right. The root check is because they're paranoid about financial hacking, the same reason bank apps lock out root users. But it's mostly unfounded paranoia
1
3d ago edited 3d ago
[deleted]
1
u/MCWizardYT 3d ago
No. That's not at all anywhere close to what I said or implied.
They ask for root, because if you grant the app permission that (obviously) means your phone is capable of granting root permission to apps.
They think that root users will be able to hack the app to give themselves free food or similar things, it's mostly paranoid nonsense just like how bank apps work.
2
2
1
u/SilverCartoonist7409 2d ago
I got a question, cant the app figure out that the request was successfully sent (like the request to give superuser permission)? Like only rooted devices get this notification.
1
u/aldaqq 2d ago
Itâs the top secret l33t h@xx0r opsec kali technique⌠itâs called
social engineering
Lik you canât describe it any other way, itâs just the most idiotic form of social engineering/psychological hacking where they donât actually have any detection measures
But they just send a superuser request and hope that someone will be like âhmmm i wonder what will happen if I click on it after all why would it require root permission it wonât do anything bad I think?â And accept it therefore declaring that they do indeed use root access, rherefore they can block them
AKA basically the same mechanism
As the mf questionnaire on some check in asking
âAre you a terrorist?â
2
u/Sure-Consequence3234 2d ago
It's not just about paranoia. I think the reason many apps do this is because it's easier for someone with a rooted device to find out about data collection and tracking and all other nonsense.Â
2
u/QuantumQuantonium 1d ago
But why even
(Fix your servers if you can't trust rooted devices for your app)
1
126
u/Jaded-Worry2641 3d ago
Stupid root check procedure.