Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's called SafetyNet [1]

What irked me is sometime app developers are abusing it without asking themself "Does this app really need to check for rooted phones at all?"

I'm okay if banks apps are using that. But why does fast foods apps need to use that? Most people that I know are paying with cash when they order foods online (and you can't hack paper money with rooted android phones).

[1] https://developer.android.com/training/safetynet/attestation



Here's a question I'd love for Google to answer: why do you need their special blessing to be able to make a file manager app, but not an app that uses SafetyNet?


> I'm okay if banks apps are using that.

I'm not okay with it, to be honest. It's my money, and I trust a rooted LineageOS with it much more than I trust the default firmware of most phones. Besides, my bank lets you do the same operations from their website that you can do with the app, so in my case it's pure inconvenience, not security.


probably becomes a tick on an auditor's checklist

like having to rotate your password every 3 weeks and requiring 4 special characters/...


Platforms like deliveroo have lost tens of millions to fraud, I don’t blame them for enforcing safetynet.

Perhaps “food delivery” means pizza to you, but there are many places where it also includes thousand dollar bottles of wine.


Could you explain how the locked-down phone is protection against fraud here?


Statistically people who do payment fraud crap use rooted phones more, probably to help with things like location spoofing to get around other fraud detection methods when apps use third party payment libraries, so you reduce your fraud cost with something that is a few lines of code. The cost/benefit ratio is too good which is why you see it everywhere that has a payment fraud risk of some sort.


This way they can permanently ban your device. Fraud detection stuff works better too, but it’s mostly about the first.

Fraud becomes significantly less profitable and more of a pain in the ass if you need to set up a new phone for each account.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: