I’m lucky my banking app works (GrapheneOS), as it’s now requiring 2FA with the app anytime I login on the browser. Can’t use an actually secure form like TOTP. At least they now allow passwords over 8 characters (yes, serious).

(Meme in comments)

  • viking@infosec.pub
    link
    fedilink
    English
    arrow-up
    1
    ·
    9 months ago

    Magisk plus DenyList luckily works for my banks. Couldn’t imagine not having a rooted phone.

      • Azzu@lemm.ee
        link
        fedilink
        English
        arrow-up
        1
        ·
        9 months ago

        What are the security issues? Rooted just means the potential to give trusted apps root access. Of course, if you give an app root access that you trust but is then abusing that trust and being malicious, yes it’s a security issue. But if you don’t do that, the simple fact of having a rooted phone should have no security change in any way. (Ok, except for potential bugs in Magisk/su or whatever)

        • lseif@sopuli.xyzOP
          link
          fedilink
          English
          arrow-up
          0
          ·
          9 months ago

          thats fair. device support is a major downside of GOS. but, remember: its not really the fault of the OS, as it requires a lockable/unlockable bootloader, which only pixel phones provide (at least in terms of mainstream phones). blame the OEMs like samsung

          • viking@infosec.pub
            link
            fedilink
            English
            arrow-up
            1
            ·
            9 months ago

            There are a ton of unlockable bootloaders. On my OnePlus that’s a matter of flipping a switch in the settings.