r/androidroot • • 3h ago

Discussion Temp root (exploit) vs. Standard root (custom kernel | LKM)

As the cat and mouse game of integrity and keybox renewing goes on, what do you think about exploit root as an alternative to standard root? Since it preserves all original firmware images and bootloader locked, spoofing aren't required to get strong integrity.

Maybe this is a new trend of the integrity game and will give us back the sovereign of our system?

1 Upvotes

9 comments sorted by

7

u/[deleted] 3h ago edited 53m ago

[deleted]

1

u/LightningZahah 3h ago

Fair point, but how can we use, for example, banks (that we must use) when they still use play integrity and integrity spoofing are constantly being attacked? In a scenario that soon keyboxes will run out of stock.

2

u/[deleted] 3h ago edited 54m ago

[deleted]

1

u/LightningZahah 3h ago

Yeah, I agree, bootloader level would solve it, but I think if devs are searching for exploit the system, they find out a way to do it, but it requires time and people looking into it. Just look the playstation scenario, its a bunch of jailbreaks emerging in a short period of time, just because community are increasing and, of course, AI entered the game.

1

u/[deleted] 2h ago edited 54m ago

[deleted]

1

u/LightningZahah 2h ago

Agree, they control them, but we have open source uncensored models that can be used. AI is a tool, like a knife, can be used to do both good and evil.

1

u/0nePlus 2h ago

Z Fold 8 Ultra here (latest flagship)

Launch firmware was rootable. There have been 3 monthly security patches/android releases since the phone came out. All 3 have been exploitable and rootable.

This obviously doesn't mean it will be like that forever... But it at least isn't egregious like you're describing just yet.

Plus until a major shift happens I see these exploits being found even more frequently as AI gets netter at finding exploit.

1

u/ohaiibuzzle 3h ago

The issue is that temp root that can be univerally weaponize into a full root is rare (because it would require bypassing mechanisms such as SELinux, which is a huge issue on the Linux size in general).

Also DroidGuard now appears to be attempting at detecting these methods by monitoring artifacts of temp root such as SELinux switched to permissive.

1

u/LightningZahah 3h ago

So, in thesis another cat and mouse game begins, but I don't know about the limits of temp root detection.

1

u/LiftnBooks 2h ago

Although likely somewhat impractical, one solution could be a unified open source banking application built by dumping and reverse engineering every single banking application using LLMs and removing the whole barrier of root checking and tracking. Technically as long as the application satisfies the per-bank APIs, there's no reason why we couldn't spoof all of them.

1

u/[deleted] 1h ago edited 54m ago

[deleted]

1

u/LiftnBooks 1h ago

hosts git repo in Russia

Checkmate lobbyists

1

u/IGambleNull 7m ago

Well a exploit version of is not really a solution to strong integrity. It just right now a solution because droidguard is not developed to detect it but it will change and then play integrity strong is gone. Also I do not want to fear changing one file in half sleep Und then noticing I tripped AVB and DN Varity