this post was submitted on 20 Aug 2023
700 points (96.8% liked)

Asklemmy

44176 readers
2012 users here now

A loosely moderated place to ask open-ended questions

Search asklemmy ๐Ÿ”

If your post meets the following criteria, it's welcome here!

  1. Open-ended question
  2. Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
  3. Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
  4. Not ad nauseam inducing: please make sure it is a question that would be new to most members
  5. An actual topic of discussion

Looking for support?

Looking for a community?

~Icon~ ~by~ ~@Double_[email protected]~

founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[โ€“] [email protected] 31 points 1 year ago (1 children)

Most security on consumer hardware

Let's take android for example. There are legitimate security implementations like SELinux, full disk encryption but something like samsung's knox is useless outside of enterprise use and kills OS level modifications

[โ€“] [email protected] 8 points 1 year ago (2 children)

The only reason I haven't rooted my phone is because of the Knox circuit. Rooting it trips the circuit, and it can't be reset. Once the circuit is tripped, my bank won't ever recognize my phone again, because it's "insecure".

[โ€“] [email protected] 2 points 1 year ago

My understanding was that knox is only used for samsung pay, secure folder and similar samsung exclusive crap

I haven't owned a recent scamsus tho so idk

[โ€“] [email protected] 2 points 1 year ago (1 children)

Knox is used by Samsung own functions. Your bank app only does a root check. Which can easily be hidden with Magisk. If you trip Knox, you lose the Samsung exclusive security features baked into the OS. That's it. Google Pay and USAA both complained about root access and refused to work with Magisk hiding off. With it on, they function as normal.

Integration into Knox requires enterprise device management and a custom app.

[โ€“] [email protected] 1 points 1 year ago (1 children)

Huh. I'll have to give it a try then. My prior phone, which had been rooted, wouldn't work with my bank, and my bank claimed it was due to the Knox circuit.

[โ€“] [email protected] 2 points 1 year ago

When Knox is tripped it sets off the root check. Your banks misleading statement is due to their own confusion. Knox is no longer active so it can't guarantee there is no root access. The OS basically says it's untrusted/insecure due to lack of Knox and always says it's rooted regardless of that actually being true. You can hide root for all apps that check. Do note that while you can return the functionality of third party apps, Samsung baked in apps can be hit or miss. It's a game of cat and mouse. I speak from experience.

Additionally here are some other conversations about it:

https://forum.xda-developers.com/t/tripping-knox-and-banking-apps.4390167/#post-86279609

https://forum.xda-developers.com/t/knox-efuse-and-banking-apps.4565143/