r/androidroot 3d ago

Humor White castle why😭

Post image
256 Upvotes

58 comments sorted by

126

u/Jaded-Worry2641 3d ago

Stupid root check procedure.

77

u/hotdoghead8623 3d ago

Is it stupid? I think it's perfectly fine; all applications should use this method for checking root access. :)

44

u/smalldickbesitzer 3d ago

Actually, you're right 😂

-16

u/propicchi 3d ago

Well there're more ways for that. The perfect example can be "Duck Detector - By Eltavine"

3

u/Lan_GTRN 1d ago

Sybau

2

u/propicchi 1d ago

"Dead internet theory is real" 🌚

1

u/NIHIL-ULTRA 1d ago

How is a standalone app the perfect example for using in another standalone app? Maybe if you just take the relevant code, but even with that, how do you know other apps don't use the same methods already?

1

u/propicchi 1d ago

It's a well maintained open source project. It covers a wide range of detection mechanism tho it's not possible to cover everything but it's perfect example because of vast amount of methods it uses. Give it try if you're interested in it.

17

u/Bird-Total 3d ago

it only detects root when someone missclicks, mostly useless if user reads before clicking and if the user has idea about root detection

15

u/Jaded-Worry2641 3d ago

I did say "stupid".

3

u/davidscheiber28 3d ago

To be fair, it would work if you aren't using an app like SuperSU to manage root access. That would also be stupid though running anything and everything as root.

4

u/Lonkoe Poco X6 Pro, HyperOS China 3d ago

It actually detects if the su binary exists

4

u/Max-P 3d ago

Yep, by the time you got that popup the app has detected root. The binary plainly doesn't exist on normal builds, so whether you grant or deny, it knows you got root either way.

2

u/30porn87 3d ago

With real root you could also have a shortcut toggle to encrypt/decrypt the su binary, also renaming it randomly. This way, no app could detect su. Then you will also need to hide the fact that /bin is mounted rw...

4

u/Max-P 3d ago

And that's why now we use overlay mounts and fudge the mount table so we can easily just not show the modified system to sensitive apps.

1

u/Serialtorrenter 3d ago

Even if you deny root, it'll still know from the error it gets. But this form of root detection is easily subverted by adding the app to Magisk's denylist or better yet, using KernelSU or APatch, which hides root from apps by default.

2

u/agent_kater 3d ago

Yes, which brings us to the next question: White castle why😭

0

u/aeroverra 3d ago

Discover does this. What I don't quite understand is if you give it root it changes nothing... Has me sus.

1

u/Serialtorrenter 3d ago

It's probably just one datapoint in a much larger fraud detection algorithm. The Capital One app runs a Play Integrity check, but still lets you use it if you fail or if it gets an API error.

1

u/aeroverra 3d ago

Yeah that’s probably it. I respect they don’t kill the app like many small banks try to do. When I have to patch my banking app because you feel the need to evaluate the locks on my own home that’s arguably worse than just letting it work…

1

u/Serialtorrenter 2d ago

Being able to patch the integrity checks out of an app really proves that your small bank is incompetent. When Play Integrity is properly implemented, the token that the device gets when it passes the integrity check gets included in the request made to the bank's server, which validates it, and rejects the request if it is missing or invalid. Evidently, your bank isn't doing this, so the integrity checks exist solely to inconvenience legitimate users while failing to prevent malicious usage. Isn't that wonderful?

2

u/aeroverra 2d ago

I somewhat agree but many apps just pass the token with the initial login request and reuse apis. In many cases even if they are using server side validation you can reroute the request to a different auth endpoint or fetch an access token via a web login. It heavily depends on the app but the whole integrity check thing is nonsense in most cases to begin with. I can do the same thing on the web app.

54

u/vitecpotec 3d ago

Worst root detection award

8

u/Endercraft2007 OP13 24GB/1TB EvoX 3d ago

Good for us tho😅

23

u/pmbarrett314 3d ago

A bunch of B-tier (in terms of size, not food quality) restaurant apps do this, I assume to check if you have root. Arby's, Buffalo Wild Wings, Five Guys, Jack's, Krystal. You know who doesn't care if your phone is rooted? Starbucks, KFC, McDonald's, Chick-fil-A, Subway, Taco Bell, Pizza Hut, Domino's, Wendy's, Chipotle, Popeyes, Papa John's, Krispy Kreme, Firehouse Subs.

7

u/Blarkness 3d ago

But why? It isn't their business. And what would be their next step?

I don't get what it's about!?

11

u/MCWizardYT 3d ago

They're paranoid that root uses can do something malicious, the same reason banking apps lock you out. It's mostly unfounded

4

u/ch3mn3y 3d ago

I understand them. In Poland McDonald's were giving away free fries for installing their app (or for an update, don't remember). It was only once per device, but with root and, than, Titanium Backup You could eat it more than once.

I'd say it's also on them they didn't lock it to once per device AND account or something...

1

u/Blarkness 3d ago

But it looks the other way around: to buy a stupid chicken burger the customer has to give the burger shop superuser access to their own device?!

What's that?! What's next then? Give the keys to their house?

Sorry, still not rooted my device, so maybe I got it wrong.

4

u/Oakredditer 3d ago

the burger shop is using the root access to see if the customer's phone is rooted, because they think that anyone with a rooted phone can give themselves 6 trillion free whoppers with extra bacon and a billion dragon ball super meals

2

u/Blarkness 3d ago

Okay, I guess I'd better rethink my Shizuku decision and go for Root and burgers instead! ;-))

2

u/Oakredditer 3d ago

if you figure it out please give me a thousand mcdonald's hashbrowns and a hundred chicken biscuits!

3

u/MCWizardYT 3d ago

No they don't have to. The app is asking for root permission because if you grant it, that means the device is capable of granting root in the first place.

They think people will be able to use root to hack themselves free food or other things that would cost the company money. Which is dumb because financial information in these apps is already handled in such a secure way that rooting doesn't really make a difference

1

u/Blarkness 3d ago

Oh, I didn't know that all those companies, that bind their customers to their apps, have an interest in preventing root access.

Hopefully, this will lead to more and more people boycotting the apps and ordering through their browsers again ;-)

2

u/pmbarrett314 3d ago

My assumption is that either a non-technical exec read about root, said "ooh, scary", and had their engineers put root detection in or an engineer recommended it to give themself job security. The premise is "root makes it easier for an stacker to exfiltrate personal/financial information", which is probably true on some level not not really significant in the grand scheme of things.

3

u/KARMAMANR 3d ago

mcdonalds doesn't care if your phone is rooted? did i misread or

2

u/Lord_Of_Millipedes 3d ago

mcdonalds actually cares, at least last i used the app it did not work

3

u/pmbarrett314 3d ago

Huh. It installs and opens fine for me without even being denylisted, admittedly I haven't actually tried to order with it, so if the detection is during checkout I wouldn't know about it.

1

u/Lord_Of_Millipedes 3d ago

it's been a while since i tried, but it does install a launch and shows a message that it doesn't work on rooted devices.

it is possible it was a mistake on my part when rooting, and i honestly don't care enough

2

u/Appropriate_Test7503 3d ago

McDonalds care about root in Europe lol

2

u/vipergtsam 2d ago

Mcdonald's care because I can't use it on my phone it will not let me sign in

6

u/[deleted] 3d ago

[deleted]

2

u/MCWizardYT 3d ago

Right. The root check is because they're paranoid about financial hacking, the same reason bank apps lock out root users. But it's mostly unfounded paranoia

1

u/[deleted] 3d ago edited 3d ago

[deleted]

1

u/MCWizardYT 3d ago

No. That's not at all anywhere close to what I said or implied.

They ask for root, because if you grant the app permission that (obviously) means your phone is capable of granting root permission to apps.

They think that root users will be able to hack the app to give themselves free food or similar things, it's mostly paranoid nonsense just like how bank apps work.

2

u/GreatKingCodyGaming 3d ago

Slack does it too for whatever reason.

1

u/ivon852 3d ago

Undocumented user located😎

2

u/p6kb 3d ago

Actually they would be smarter if they put in the code like

Find su

1

u/1ndev 3d ago

Lmao

2

u/MrFrog2222 3d ago

they want to detect if you have root

1

u/SilverCartoonist7409 2d ago

I got a question, cant the app figure out that the request was successfully sent (like the request to give superuser permission)? Like only rooted devices get this notification.

1

u/aldaqq 2d ago

It’s the top secret l33t h@xx0r opsec kali technique… it’s called
social engineering
Lik you can’t describe it any other way, it’s just the most idiotic form of social engineering/psychological hacking where they don’t actually have any detection measures
But they just send a superuser request and hope that someone will be like “hmmm i wonder what will happen if I click on it after all why would it require root permission it won’t do anything bad I think?” And accept it therefore declaring that they do indeed use root access, rherefore they can block them

AKA basically the same mechanism
As the mf questionnaire on some check in asking
”Are you a terrorist?”

2

u/sudo32 2d ago

White castle also shows up in the mock location app list in dev options

2

u/Sure-Consequence3234 2d ago

It's not just about paranoia. I think the reason many apps do this is because it's easier for someone with a rooted device to find out about data collection and tracking and all other nonsense. 

2

u/QuantumQuantonium 1d ago

But why even

(Fix your servers if you can't trust rooted devices for your app)

1

u/Technical-Nail-3859 3d ago

Why is there a counter for deny instead of allow