Hacker Newsnew | past | comments | ask | show | jobs | submit | izacus's commentslogin

It was never particularly safe to root the phone - both because it drills a hole into the security model and because you don't have any good ways of verifying what apps asking for root actually do.

Moreover, most of root tools and ROMs are rather poorly written and glued together with other forum scripts which you have no way of checking if they're not malware. (There are exceptions.)

So no, "safe" it's not and never has been. The tradeoff might be worth it for you as a user though.

> The reason I'm asking is that I'm stuck with authy as a MFA code app, and would like to move to something that has both desktop and phone support, and my conclusion is I'd need to root my phone to get access to the actual MFA seeds (they don't allow exports to keep you stuck in their app).

The way to do that is to take the hit and recreate your 2FA codes in an opensource app like Aegis or Stratum.


Thanks for the summary. I agree with you about 2FA, but it's still annoying, I was hoping I would find a lazier solution.

Not sure why this is downvoted. It's accurate. A major problem is that when you root you loose assurance of the integrity of your /system partition. That means malware can now persist undetected.

Your post is essentially admitting that you're ignoring the bugs from the company you love and taking seriously form the company you don't.

So the difference isn't about taking things "more seriously", but in the fact that you take marketing from Apple more seriously.

That's not the same.

(Note: There's plenty of proof that Apple does take security more seriously than Samsung, Xiaomi & Co. in the article, but your feelings aren't it.)


Good thing they never claimed their feelings were proof of anything.

This is where reading ability comes into play.

Because you'll be hounded by patent pools and sued into oblivion if you dare to use it in your own software and aren't Apple, Microsoft or Samsung.

"We don't want to support another pile of security bug ridden C++ library" absolutely aren't "dubious grounds".

You'd rip a new one to Google if there would be a CVE in a new C++ library in Chrome because of it.

Now that Rust library is available, they will continue adoption, as it should be.


The stated reason for Chrome was not ‘we need a memory-safe implementation’. It was ‘there is not enough interest’ and ‘there is not enough improvement over AVIF’. At the time, there was interest and there was improvement over AVIF (which Google has decided to support regardless of memory safety, interest, or seemingly any deeper consideration).

Memory safety as a condition for adoption was brought up only years later, and by Mozilla rather than Google. The JPEG XL devs, who’d offered to work on it if there was interest, got to work as soon as interest was proclaimed. You might say it’s a good thing for Chrome to have held off adoption until then, but that’s completely incidental, not because they cared. Near-zero efforts to be fair and responsible were made.


> "We don't want to support another pile of security bug ridden C++ library" absolutely aren't "dubious grounds".

It is when that didn't stop them YOLO'ing in webp and then avif support.


If you have two toilets in your house, are you going to sign up to clean mine too, for free, because I demanded it from you?

Thought so.


EU is already 40% better than US, so why exactly are you implying it's worse?

> why exactly

Hyacinth Bucket has entered the chat.


What a bizarre thing to say - is that your attempt to discredit anyone that complains about wrongdoing?

"Everybody's enraged, why don't you like this unethical thing being done to you by a company?"

What's going on here?


Most of those are webapps too (just packaged in APK) since it doesn't make sense for most app developers to build a special bespoke version for Android.

If you check YouTube version string you'll see Cobalt as well on Android.


Those ad breaks only appear if you opt out of personalized tracking.

They're a punishment for you because you won't let them collect data.

FB app does that too.


Well, in my case it seems like a win-win, less of a punishment and more of an extra feature I gained for making the right choice I guess. It's all the eyes of the beholder!

Yeah, same here, but that's the reason why others aren't seeing it :)

Same way it works for everything else. They sell their performance and then they make something else.

You keep making up strwamen and positions that don't exist.

Maybe mock something people have actually said.


Um sorry? I don't see where I mocked anybody. You might be seeing sarcasm where there was none.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: