Hacker Newsnew | past | comments | ask | show | jobs | submit | xdxfw's commentslogin

Rooting becomes a no brainer - message sent from rooted lineageos poco x3 pro


Help, I can't access my banking app!

- sent from every device with SafetyNet invalidated.

I'm not trying to be sarcastic, just pointing out the reality of the situation and the reason why I didn't root or mod my own phone.


You can install 3rd party roms but skip the rooting part to not mess with SafetyNet.


That still breaks SafetyNet, because it checks if the bootloader is unlocked, which it has to be to install a custom ROM.


My stack:

- omen 15, 32g ram: Windows11 for gaming + wsl2 + vbox hackingtosh + bluestacks.

- fully rooted poco x3 pro running lineage


wsl2 is a must


They should force apple and android manufacturers to add 1 button to jailbreak and root. Rooting is much more useful than that warranty


In the U.S., rooting does not void the warranty unless the manufacturer can prove the rooting itself caused physical damage. Just having a blanket policy of rooting = voided warranty is illegal because of the Magnuson-Moss Warranty Act.


Frankly I think the current root/jailbreak situation on android is fine, I feel like there should atleast be a some technical barrier to that power.


I'll be happy after they get rid of Samsung Knox and put more restrictions on who can use the SafetyNet API.


Oh yeah Samsung Devices are weird.. I think they even have a different fastboot implementation. But I do not think that represents "stock" android?


This creates a dependency on the email. If your email gets compromised/locked, your account gets too. OTP passwords are better


Sometimes, that’s exactly what you want though: you don’t care (and the user has bigger issues if their email is compromised) if the email is compromised. In the terms you might say “access is granted based on access to email that you register with” and if someone loses access to their email, you don’t need to do any id verification or “proof” to recover the account. You can just say “tough.”


> OTP passwords are better

For accounts which hold something of value (monetary and/or personal data) then sure.

But every once in a while when I need to login to GitHub it blocks my logon and demand what I give it a code sent to my e-mail. In essence this doean't seems that different from the scheme in the article.


Is there any evidence that email accounts have done anything besides become stickier?


Credential stuffers will have a feast on this one.



Thanks for mentioning. Nice logo! I have seen that and borrowed verbose sql logging. Nice gem, I see the differences.

My gem:

1. has more checks 2. has more migration helpers (renaming tables/columns, changing columns types, backfilling etc) 3. more flexible in terms of configuration 4. has background data migrations 5. does not disables wrapping migrations in a transaction, which can be inconvenient and dangerous


If you like ruby, please give https://matestack.io/ a try


Location: US, England, UK, UAE, Europe, SEA

Remote: Only remote

Technologies: Ruby, Ruby on Rails, Javascript, React, Postgres, Linux, Redis, Nginx, Crypto, Web3, Decentralized Web, p2p

Willing to relocate: No

Résumé/CV: https://www.linkedin.com/in/sebastian-buza-280407219/

email: sebyx07@protonmail.com

Only looking for interesting projects, >= $180k



different use-case: i2p/tor anonymity -- slow ygg : fast

Though I must admit I don't yet know how Yggdrasil does routing.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: