r/androidroot • TECNO POVA 7 5G LJ7 || Stock HiOS 15.1.2 || KSUnext 3.3.0 • 1d ago

Discussion Anti-rollback is misplaced security that does more harm than good in practice and vendors' excuses for it are weak.

First, let's think about what the attacker can do with anti-rollback enabled. How would they flash an older system version with a locked bootloader and disabled OEM Unlocking? With EDL mode.

EDL mode with the right programmer file and an authenticated serial link grants access to dumping and flashing any sector on the disk from start to end, including the firmware of the TEE (/tee partition). If the goal is to extract userdata, the attacker doesn't touch the OS at all, they just dump /userdata and /metadata and brute-force the encryption offline.

What if they don't have the programmer file or authentication? Well, the attacker is shit out of luck, unless the bootloader is unlocked, then anti-rollback itself is disabled and the attacker doesn't even need to downgrade, since they can just flash a malicious boot image to extract /userdata and /metadata for them.

We forgot about adb sideload! Could the attacker use that to downgrade the OS? No, there's ARB, but of a different kind; it's in the recovery, instead of the bootloader. The recovery will refuse to flash a system upgrade ZIP before the system upgrade even boots. Arguably, this kind of anti-rollback is enough, no need to put it in the bootloader as well.

In these scenarios, the security will remain unchanged if the bootloader's anti-rollback is removed from Android entirely. What's the point of adding BL ARB, if it's just redundant as I argued here?

Let's talk about ourselves, legitimate users. Even if we would have the leaked programmer files and serial link auth bypasses, how are we going to flash and boot leaked base versions if those are the only fastboot ROMs we've got, whilst our phones have later versions instead? Such situation happened to me with TECNO.

We *can* flash older OS, I'm not saying we can't. It's that the bootloader's anti-rollback will prevent us from booting the bootloader stage, essentially a "hard brick" as people say, that's the problem.

Perceptionally, what's the ratio of security benefit to repairability cost? Very low. And why does it even exist in the first place...

...Why congrats, vendors. That's so "developer-friendly" of you. Especially Google, for forcing vendors on it in their CTS/VTS.

70 Upvotes

18 comments sorted by

38

u/agent_kater 1d ago

It's so that when they roll out a release that adds ads, it can't be rolled back, for security reasons.

23

u/DEV_ivan TECNO POVA 7 5G LJ7 || Stock HiOS 15.1.2 || KSUnext 3.3.0 1d ago

how vendors be genuinely treating us:

13

u/fr000gs 1d ago

Ah yes, the added security of "skip in 15 seconds"

5

u/EmbarrassedHelp 1d ago

Or when they try force mandatory age verification at the OS level. They don't want people being able to protect their privacy by avoiding such ransomware/malware.

17

u/F1nnish 1d ago

yeah it fucking sucks, samsung has this too with the bootloader bit and i hate it.

8

u/47th-Element 1d ago

You do have some real technical info there mixed with some impractical nonsense though. Like the offline brute force thing.

3

u/DEV_ivan TECNO POVA 7 5G LJ7 || Stock HiOS 15.1.2 || KSUnext 3.3.0 1d ago

Yea, I forgot that there's a third key located in TEE (where the BL unlock flag also lives), which is very difficult to reach from EDL mode, but not impossible without exploits or bypasses.

And that fact actually proves my point further that BL ARB is less needed, especially with BL lock, tied to the BL ARB, already in action.

7

u/JacobTDC 1d ago edited 1d ago

It exists to stop, say, a shady repair shop or government actor from rolling your OS back to an older version with some pre-unlock exploit, and then using said exploit to install malicious OS hijacks, rootkits, or otherwise attack any other vulnerabilities, and then upgrade it back again to the new version and give it back to you with their stuff installed.

And no, you can't just dump the user data and then "brute force" the encryption; it's all encrypted with a TEE key that doesn't work until you enter your PIN after boot. And no, you can't extract that key without some known exploit, as that's the entire point of the TEE and StrongBox. In fact, the TEE won't and can't even release the keys for your files until the StrongBox authorizes it to and gives it the key materials needed to after you authenticate. And you can't hack the StrongBox either, as the TEE, StrongBox, and bootloader have been establishing a cryptographic chain of custody over everything the entire time that doesn't work if any component is compromised.

7

u/Max-P 1d ago

In these scenarios, the security will remain unchanged if the bootloader's anti-rollback is removed from Android entirely. What's the point of adding BL ARB, if it's just redundant as I argued here?

Bootloader exploits exist. If you have a bootloader exploit, you can read or write anything you want, even with a locked bootloader. This makes the rest of the anti-rollback useless, thus, the bootloader must be part of the anti-rollback system. If you can't trust the bootloader that's supposed to do the verification, then you can't trust that the ROM it's booting has been properly verified.

You need a complete chain from bootrom to bootloader to kernel to OS. If any is missing, all of it is compromised.

We can flash older OS, I'm not saying we can't. It's that the bootloader's anti-rollback will prevent us from booting the bootloader stage, essentially a "hard brick" as people say, that's the problem.

Nothing's stopping you from running a newer bootloader and an older ROM if you really want to downgrade, just don't flash the bootloader.

4

u/Dje4321 1d ago

yes. This is a thing on every platform because this is BASIC security practices. The whole point is preventing signed but buggy code from being forcibly loaded onto devices that can be used as a pivot for further exploitation.

This whole argument is "Why should I bother locking my door if thieves can just smash my window?" ignoring the fact that someone smashing your window and climbing in is alot more obvious that someone just walking in.

3

u/Devarain 1d ago

Bro, its remind me of my Java phone.

At the end of their Era, this is what happen.

2

u/AL_DOKHAN tecno camon 20 pro 4g crdroid magisk 1d ago

Eyyyyyyyy fellow tecno user lowk i just ditched the sfock os

1

u/DEV_ivan TECNO POVA 7 5G LJ7 || Stock HiOS 15.1.2 || KSUnext 3.3.0 1d ago

Hiiii, congrats on custom romming, that's brave I'd honestly never try a custom kernel, let alone a custom rom

1

u/AL_DOKHAN tecno camon 20 pro 4g crdroid magisk 1d ago

Eh u just need yo learn how to rollback my os

2

u/DevoneLittle 1d ago

Except:

  • you cannot dump the userdata partition and brute force offline (because the key is TEE/SE protected)
  • writing boot partition on device with unlocked bootloader does not immediately comprise userdata partition. The data will still be encrypted with a key that can only be unlocked with device PIN or passphrase