←back to thread

436 points kennedn | 1 comments | | HN request time: 0.428s | source
Show context
201984 ◴[] No.45252931[source]
Are techniques like using Frida and mitmproxy on Android apps still going to be possible after the signing requirement goes into effect next year?
replies(3): >>45253290 #>>45254332 #>>45255348 #
bri3d ◴[] No.45253290[source]
Overall: yes, but it will get much harder for apps which need attestation, which is sort of the point, for better or for worse. As far as I know you'll still be able to OEM unlock and root phones where it's always been allowed, like Pixels, but then they'll be marked as unlocked so they'll fail Google attestation. You should also be able to still take an app, unpack it, inject Frida, and sideload it using your _own_ developer account (kind of like you can do on iOS today), but it will also fail attestation and is vulnerable to anti-tampering / anti-debugging code at the application level.
replies(1): >>45254373 #
josteink ◴[] No.45254373[source]
So for people with any practical needs what so ever (like banking): No.

At this point Android isn’t meaningfully an open-source platform any more and it haven’t been for years.

On the somewhat refreshing side, they are no longer being dishonest about it.

replies(4): >>45254712 #>>45254817 #>>45255119 #>>45258788 #
Wowfunhappy ◴[] No.45255119[source]
I'm stuck on iOS for various reasons, but if I was on Android I could do without mobile banking in exchange for having root privileges. I don't entirely understand why this is such a big deal.

If e.g. Slack required attestation that would be a different story. I need that for work.

replies(1): >>45255294 #
1. lights0123 ◴[] No.45255294[source]
they leave that up to your organization: https://slack.com/help/articles/360042097113-Block-jailbroke...