Remix.run Logo
encom 3 hours ago

How does a rooted phone enable bank fraud? This smells like pointless policy checkboxing.

biosboiii 2 hours ago | parent | next [-]

If you run a rooted phone and download malware, that malware can gain root and do payments on your behalf. Then PayPal has to deal with you revoking payments etc., they don't want to so they forbid you from using PayPal on a rooted phone.

ruszki 2 hours ago | parent | next [-]

Malwares can possibly do that even on non rooted phones if a privilege escalation attack is possible. And just yesterday, there was an article here about exactly one of those.

Also I highly doubt that there is any real statistics anywhere about whether this is a real threat or not. I guarantee that nobody did such statistics properly. The only known data is from companies which sell root prevention tools, so totally unreliable. And internally I guarantee, that no banks collect such info.

So no, banks lie about this only because they can sell this to judges as safety feature, when they fuck up, which happens continuously.

fylo 2 hours ago | parent | prev | next [-]

Graphene isn't rooted.

Grombobulous 2 hours ago | parent [-]

Not only is it not rooted, it runs real Google Play services. It’s not microG.

master-lincoln 2 hours ago | parent | prev | next [-]

If this happens it's the device owners fault and they should be responsible for it.

Grombobulous 2 hours ago | parent | next [-]

Which they would be anyway since PayPal isn’t a bank and isn’t FDIC insured.

They allow you to open PayPal.com on any web browser. Running Windows/macOS/Linux is basically identical to a rooted Android phone (you have local admin rights, you can modify and automate the browser, and can run unsigned code).

bayindirh 2 hours ago | parent | prev [-]

No, no... In 2026, all footguns are banned. Even in programming, so if something allows a footgun, it's banned now.

Apparently the world can't adult and be responsible for their actions, or people believe in that.

2 hours ago | parent | prev | next [-]
[deleted]
encom an hour ago | parent | prev [-]

For that argument to hold, they'd also have to blacklist any phone not running the newest, most up to date Android version, because all older versions presumably have known exploits. So that basically leaves Pixel phones.

goonersallofyou an hour ago | parent | prev | next [-]

One thing that I'm actually excited about regarding AI is that the pointless policy checkboxes that have never been effective in adding any actual security are even less so effective now that everyone can wield their very own security researcher.

iamnothere 2 hours ago | parent | prev [-]

Graphene OS does not support root. This is a false positive based on some check they are doing.

fluidcruft 2 hours ago | parent [-]

It's probably just a generic error message for failing that Google Play Protect thingamajigger that attests provenance of the vendor OS from boot. Will be interesting to see whether the Motorola phones have this endorsement when they ship. Most devices would probably fail because they are rooted rather than because they are GrapheneOS. I wouldn't put it past a scammer talking grandma into rooting their phone.