• viking@infosec.pub
    link
    fedilink
    English
    arrow-up
    19
    arrow-down
    1
    ·
    edit-2
    19 hours ago

    No, I exactly mean rooting, and it is a hard requirement for me when choosing phones.

    If you know what you’re doing, there is no security risk involved, since every app requesting for root access needs to be granted individually, and you can opt to do so for a limited time or permanently. Or not grant it at all, obviously.

    Tools like AppOps (advanced permission management), Storage Isolation (prevent access to certain folders even if “file access” permission is granted to some app), Ice Box (keep certain apps in a permanent state of hibernation unless you explicitly launch them) are absolute core essentials.

    Other apps that enable you to fully remove system apps, system level adblockers, VPN sharing etc. might be optional, and there are no-root workarounds, but they all come with serious limitations.

    • Rolivers@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      2
      ·
      13 hours ago

      Hmm… Do you use a different root method than magisk? I don’t think a root method based on the efforts of a single developer is a safe practice.

      • viking@infosec.pub
        link
        fedilink
        English
        arrow-up
        2
        ·
        11 hours ago

        There are other tools, but their developers aren’t publicly known. So I indeed trust into the one man show that is magisk, at least as a full time Google employee who gets his codebase reviewed in-house, there’s some more trust than to a random nobody. And he does publish the code and allows for user contributed fixes on github.

        • SpongyAneurism@lemmy.frozeninferno.xyz
          link
          fedilink
          English
          arrow-up
          2
          ·
          5 hours ago

          Little nitpick: Graphene OS isn’t artificially restricted to Google phones. Pixel phones just happen to be the only ones that fulfill the safety requiremets that Graphene OS wants.

          Other manufacturers could do the same and Graphene OS devs would welcome it, they just choose not to do that.