Hacker News new | ask | show | jobs
by crimsonnoodle58 92 days ago
GrapheneOS user. Disappointing they consider our OS rooted when its actually more secure than stock Android.

So if I'm locked out of my 365 sysadmin user by this, what then?

Hopefully disabling the hardened memory allocator, as suggested by the article, holds them off for a while..

4 comments

Curious how severe their root detection will be. I have a cheap China phone with LineageOS installed, but it's not running rooted. Will be nasty if they flag all 3rd party ROMs as "insecure".

My banks app works fine, but i have had one financial app refuse to install.

"'Microsoft Authenticator is not officially supported on GrapheneOS and Entra accounts may be impacted in the future on devices running GrapheneOS that are detected as rooted,' a Microsoft spokesperson said."

Doesn't that imply it'll run on GrapheneOS unless the phone is also rooted (and by default it's not)? The spokesperson might be using the term "rooted" incorrectly though?

I poked at the app, which surprisingly enough isn't even obfuscated, and as far as I can tell, it's mainly relying on Play Integrity's verdict. I didn't investigate it in detail though, so I don't know absolutely sure if that's really all or whether they're also running some additional custom checks, and I also don't know which integrity level they're requiring.
> So if I'm locked out of my 365 sysadmin user by this, what then?

I'm sure they have TOS that indemnify them, but I'd sure like to see a similarly-sized company sue them for resulting downtime.

Wonder what Motorola thinks of this.