safetyNet: unlock -> flash AOSP based/Xiaomi.eu -> flash Xiaomi global -> lock = ok? - Xiaomi Poco X3 NFC Questions & Answers

safetyNet: unlock -> flash AOSP based/Xiaomi.eu -> flash Xiaomi global -> lock = ok?
I come from a long line of "clean" devices (Galaxy Nexus, Nexus 4, Nexus 5, One Plus 3) and after using the Poco for a day I already feel the hardware is awesome, but the software is not up to par, or bloated/useless and cannot be disabled (I'm looking at you, Security).
So I want to tinker with it, but I realize nowadays "our" phones are not that "ours" to begin with, and playing with them as we like may mean losing access to some apps, maybe forever.
Right now I don't use or need prime video (SD for now even with L1 anyway)/netflix/google pay/banking apps/mcdonalds (lol), so I don't care about losing SafetyNet evalType hardware or Widevine L1, BUT, I don't know if I may need it in the future (especially for banking apps).
So, if I unlock and flash a custom rom, then some time in the future decide I want SafetyNet evalType hardware... can I recover it by flashing the global rom again and relocking? Or do I lose it forever (like Samsung Knox and its e-fuse)? Because I'm worried when I see things like these (for other devices):
https://forum.xda-developers.com/galaxy-s8/help/safetynet-trip-stock-rom-install-t3876768
https://forum.xda-developers.com/g4/help/safetynet-failed-stock-rom-relocked-t3808699

Related

How can I secure my S7 as much as possible, short of a custom ROM

Ok, so I'm a little new to this. I am pretty much unfamiliar with root (I've only done it once, a few years ago, on a completely different kind of device, via KingoRoot without even having to plug in to a PC), but I am very good at following directions/making sense of tutorials . But recently I have have become very aware of privacy concerns, and I realize that the form my phone is in now is very insecure.
But I'm a little confused by "rootable" vs "unlocked bootloader"
So, I though I understood these terms, but apparently I don't. I thought that *root access* was an admin level (the highest), and that it required an unlocked bootloader to achieve it. However, my device, Galaxy S7 US version, is supposedly rootable(https://forum.xda-developers.com/tm...eres-how-rooted-nougat-s7-edge-g935t-t3567502), but does not have an unlocked boot-loader, like the international/Exynos version, that would allow you to install a custom ROM. How is this possible?
Either way, I cannot use a custom ROM, since none of the even remotely trustworthy ones (Copperhead, Lineage, Replicant) work on the US version.
So, if I am stuck with Samsung version android, what else can I do (If any of these are possible, a little direction or at least a link to a good guide would be very helpful)?
- Without an unlocked boot loader, can I still remove all GAPPS and bloatware?
- Can I remove Googe Play Services and replace it with MicroG, and still use the apps with the Play dependency?
- Is Xposed/Xprivacy an option? (Are these still considered safe?).
- If not, how can I get the most specific control over device processes: being able to see and control permissions for each app, moniter all incoming/outgoing data stream (everything apps send to other parties/devices and what they receive),
- Any possibility for a firewall?
I realize that this is asking a lot, but Reddit was thoroughly unhelpful, so I throw myself at your charity.

What do I lose by rooting and/or custom ROM

Hi, newbie here.
I'd love to root my Galaxy S7 (SM-G930FD) and maybe even install a new ROM. However, I'm concerned about losing some nice features of the phone.
At first thought, three key features that I like are: Samsung Pay, device encryption, and Samsung's encrypted folder. (For my line of work, I have to be very very security conscious, so device encryption is important.)
Also, along the lines of security, any recommendations for the most secure OS for the S7 phone, and possibly a firewall to manage net traffic?
Thanks!
Adding small reply to my own post.
Looks like rooting will permanently disable Samsung pay. But, looks like Google Pay should still work. (If your bank supports it.)
Looks like TW bootloader can't handle whole-phone encryption, so that's a loss of a major security tool.
But still nothing like loosing some camera features as with some Sonys?
I've rooted my s7 from the start and since I am enjoying full camera support, can even use snapchat (though under Parrallel space, so it's not obvious)
Don't use and will never use Samsung Pay (It's not working here in The Netherlands anyhow) and all other banking apps I use do work.

Advantages of unlocking bootloader

Hi,
I am curious what you guys think about it ?
What is the advantages? Why you unlocking ? Which kernel are you using etc..thx
I haven't unlocked mine yet but probably will. Main reason is to root and ability to run custom roms and kernels. Once you have custom kernel and magdisk the possibilities are almost endless as far as tweaking and optimization goes!
Basically what @oneandroidnut said. I have mine rooted and get about 7hrs of SOT over 40hr periods when using certain kernels. Its well worth it IMO.
I'm unlocked, and appreciate the level of access (read "root" ) that this affords me to run custom ROMs and kernels, get better sound, etc.
What you should know is a pretty significant drawback of bootloader unlocking according to some reports here on XDA. Namely, your Widevine level will go to L1 to L3.
What is Widevine?
"Widevine
marko94 said:
Hi,
I am curious what you guys think about it ?
What is the advantages? Why you unlocking ? Which kernel are you using etc..thx
Click to expand...
Click to collapse
Many reasons. To me, the best advantage is having customizable black/dark themes for hundreds of appes like Instagram, Snapchat, Outlook, all google apps, for the system*, etc. This requires root/magisk, which in turn requires an unlocked bootloader.
You can have many gestures and remap keys to do a myriad of functions as well. I used Xposed Edge Pro- I can have over 30+ gestures and remap keys.. You can also get expanded volume slider back, which pie removed for some dumb reason. You have to be aware that some apps try to check for root/unlocked bootloader. Magisk Hide is able to hide root detection for the most part. You might need developer options to be disabled for additional checking too (dev settings only useful if using -Always on Data -Disable Absolute Volume -USB debugging)
reaper000 said:
I'm unlocked, and appreciate the level of access (read "root" ) that this affords me to run custom ROMs and kernels, get better sound, etc.
What you should know is a pretty significant drawback of bootloader unlocking according to some reports here on XDA. Namely, your Widevine level will go to L1 to L3.
What is Widevine?
"Widevine
Click to expand...
Click to collapse
Yeah,I heard about that. But screen on this phone is so beautiful , so watching Netflix for example in non hd mode is awesome. Hehe
Maybe there will be some fix soon for that ,who knows
Netflix looks just fine on my rooted phone. I would rather have themes and all the other tweaks other than Netflix. Can watch that crap in my huge tv.
marko94 said:
Hi,
I am curious what you guys think about it ?
What is the advantages? Why you unlocking ? Which kernel are you using etc..thx
Click to expand...
Click to collapse
What everyone said about getting custom roms, root, etc is correct. Magisk modules are also amazing.
With magisk, you will pass saftynet and can use google pay too.
But sadly after unlocking bootloader, widevine goes from L1 to L3 so you can't stream HD HDR content on netflix and amazon prime. Another drawback to unlocking bootloader and custom roms is that usually stock camera takes a hit (you can use Gcam), and the FP unlock speed is usually also effected. This is all my prior experience from Oneplus 3T and 5T, both of which I unlocked and rooted within a few days of getting them.
But the 7pro has this amazing HDR compliant screen, so I'm probably going to enjoy it as long as I can, I'll eventually get fed up with OOS and then go to custom roms.
Overall, there are more advantages than disadvantages to unlocking boot loader IMO.
---------- Post added at 04:35 PM ---------- Previous post was at 04:33 PM ----------
reaper000 said:
I'm unlocked, and appreciate the level of access (read "root" ) that this affords me to run custom ROMs and kernels, get better sound, etc.
What you should know is a pretty significant drawback of bootloader unlocking according to some reports here on XDA. Namely, your Widevine level will go to L1 to L3.
What is Widevine?
"Widevine
Click to expand...
Click to collapse
On my oneplus 5T, I have L1 even after unlocking bootloader but Netflix won't play higher than 960x540.
Is there no possibility that we can somehow bypass that like saftynet?

Pie Root

Hi,
i have read here in Forum about android pie and i cant find my answer for myself.
Is it possible to Flash rooted pie on xzp with restore the drm keys?
i know the camera is workin on pie's root, but what is with the other Issues?
Is there any Solution out there?
Best Regards
Sc0rp1on said:
Is it possible to Flash rooted pie on xzp with restore the drm keys?
Click to expand...
Click to collapse
No, you can't do anything to resotre lost keys, not unless you made a backup of them first. You can fool the phone that the DRM is in place, but that's different to restoring them.
You can unlock you phone and put a custom rom on there, there are some Pie threads here on XDA, eXistenZ Pie, or LineageOS. But getting these to work isn't a simple download the rom and install it. You need to follow the instructions on the Sony unlock, then install TWRP, which will give you the ability to flash roms and recoverys.
It might be worth sticking to a stock rom and using janjan's kernel, wich will fix any DRM problems and give you compatability with Magisk
Yes, the camera does work on Pie, even with bootloader uinlocked, but there are some other features that remain disabled, but nothing important.
Thx for Reply. My Old XZP has unlocked Bootloader, Oreo Rooted within DRM Patch from XperiFix. But now, the Display is broken and the Phone is dead.
I have buy the Same Model (Locked & Fresh) and want to remove System Apps , have Root and eventually Pie. But i want to have all functions like unrooted and hoped that the time brings out new Methods for that.
I have read here, that the camera Quality gets down on pie root.
Now my Hope / Question:
Pie + Root within DRM Features (Fooled DRM is ok also) or should i Flash Oreo and use Xperi Fix again, like my old one?
Sc0rp1on said:
Thx for Reply. My Old XZP has unlocked Bootloader, Oreo Rooted within DRM Patch from XperiFix. But now, the Display is broken and the Phone is dead.
I have buy the Same Model (Locked & Fresh) and want to remove System Apps , have Root and eventually Pie. But i want to have all functions like unrooted and hoped that the time brings out new Methods for that.
I have read here, that the camera Quality gets down on pie root.
Now my Hope / Question:
Pie + Root within DRM Features (Fooled DRM is ok also) or should i Flash Oreo and use Xperi Fix again, like my old one?
Click to expand...
Click to collapse
Pie or Oreo is a personal choice and you'll get people batting for both sides on the forum here.
You can stick with what you know, or go with stock Pie and use janjan's kernel, that will get you Pie build with DRM fix.
Didgesteve said:
Pie or Oreo is a personal choice and you'll get people batting for both sides on the forum here.
You can stick with what you know, or go with stock Pie and use janjan's kernel, that will get you Pie build with DRM fix.
Click to expand...
Click to collapse
Thx for Answer.
I have read the thread about the kernel and pie and i cant find Information for camera Quality (i have read pie root make camera Quality bad) and about the Screen-Modus (Superlebendig / Professional/ Standard). My old Oreo Rooted One was running perfect, but i would try pie, only if i can get sure, that cam and Display works like stock Rom.
I hope you understand my english and my wishes
Sc0rp1on said:
Thx for Answer.
I have read the thread about the kernel and pie and i cant find Information for camera Quality (i have read pie root make camera Quality bad) and about the Screen-Modus (Superlebendig / Professional/ Standard). My old Oreo Rooted One was running perfect, but i would try pie, only if i can get sure, that cam and Display works like stock Rom.
I hope you understand my english and my wishes
Click to expand...
Click to collapse
The camera on the Sony works perfect or it doesn't (takes green pictures), it's a myth that there is some sort of half way 'poor' quality.
There is no degradation of camera quality with rooted Pie no DRM, if you think that might be a problem then use a 'fixed' rom or kernel.
Try Pie and if you think that the camera is broken, then go back to Oreo
Didgesteve said:
The camera on the Sony works perfect or it doesn't (takes green pictures), it's a myth that there is some sort of half way 'poor' quality.
There is no degradation of camera quality with rooted Pie no DRM, if you think that might be a problem then use a 'fixed' rom or kernel.
Try Pie and if you think that the camera is broken, then go back to Oreo
Click to expand...
Click to collapse
@Sc0rp1on, @Didgesteve, in my opinion, it is totally worth to backup and restore locked TA to preserve drm keys, if just only in order to be on the safe side.
The unlock procedure erases all userdata anyway, similarly as when you do downgrade to exploitable oreo...
Anyway, I am not sure about the camera quality - is it really a myth? Please see here for few pictures comparisons where differences are visible. You may visit the linked posts too for more opinions / previous discussions.
j4nn said:
@Sc0rp1on, @Didgesteve, in my opinion, it is totally worth to backup and restore locked TA to preserve drm keys, if just only in order to be on the safe side.
The unlock procedure erases all userdata anyway, similarly as when you do downgrade to exploitable oreo...
Anyway, I am not sure about the camera quality - is it really a myth? Please see here for few pictures comparisons where differences are visible. You may visit the linked posts too for more opinions / previous discussions.
Click to expand...
Click to collapse
I wouldn't advocate anyone unlock thier phone without backing up the TA partition. but I was replying to a question.
I can't see any difference in the pictures myself and I think if there were a difference more would have been said about it.
Myself I was an early jumper and unlocked my phone before backup and restore of the DRM keys was possible, so that rather shaped which version of firmware I use. I didn't step to Pie, I stuck with Oreo and a 'fix' that keeps everything sweet.
@Didgesteve, it's not easy to do a good comparison - only those who have two phones or at least have a locked _and_ unlocked TA backup of one phone could try. Although many complain about camera quality in general.
But as you could see in the linked "xz1c locked oreo vs unlocked pie comparison" post I tried to compare having two xz1 compact phones side by side, one still locked and one with lost drm keys.
And comparing the not downsized original photo images you can clearly see some differences - which are cut to attached pictures so you can find them easier in the original files available for download.
It could have been a coincidence, but it's have been done two times in a row switching the order of the phones getting very similar results of quality difference in each trial.
So in my opinion, it might be a myth or may not.
j4nn said:
[MENTION=4354390]So in my opinion, it might be a myth or may not.
Click to expand...
Click to collapse
It may or may not, but no one else seems to have noticed.
If you think it makes a difference then use Janjan's kernel with built in 'fix'
@Didgesteve, that "no one else seems to have noticed" - a rather big assumption of yours. There are many users complaining about xzp/xz1/xz1c camera quality in general.
But just with regard to oreo vs pie, read the xzp thread from here: post#27, particularly post#30 contains very interesting internal stuff.
I would like to believe sony stopped conditioning camera with keeping bootloader locked with pie but somehow I am not sure about that at all considering all the circumstances and my linked camera quality comparison test.
Thanks for your advice, luckily I do not need janjan's kernels as I've implemented the TA backup exploit, so both my phones can have drm keys restored (in fact one of them is still locked on purpose).
I (and anybody who saved TA-unlocked.img together with TA-locked.img) can switch easily between "drm keys restored" and "drm keys lost" states for testing/comparisons.
j4nn said:
@Didgesteve, that "no one else seems to have noticed" - a rather big assumption of yours. There are many users complaining about xzp/xz1/xz1c camera quality in general......
Click to expand...
Click to collapse
I have 3 xz premiums running pie in my household. My wifes - never unlocked. Mine - unlocked with no ta backup. And a third one which I acquired cheaply recently - unlocked with restored original ta backup running a kernel with @j4nn's commits which hides bootloader unlock status.
The photo quality appears similar on all three devices. Maybe closer scrutiny on a pc will reveal differences.
However restoring original ta with blu hide kernel will always be the optimal solution regardless of camera quality due to the fact that it also restores widevine L1 functions (eg: screen mirroring etc.)
@shoey63, that's right, on phone's display, differences are probably not visible.
But if not zoomed out images are compared on PC, you may see some differences as my test showed.
Most people just take a quick shot to post it on a social network, there you cannot see a difference at all, as the image gets downscaled automatically - so majority may not complain.
Anyway that "restoring original ta with blu hide kernel will always be the optimal solution" is right - should behave as much as in still locked state as we can get.
Mentioning screen mirroring - does it depend on drm too in case of pie?
I tested it with oreo and it needed TA-locked restored with bootloader unlock hidden to get it working - running just kernel hiding BL unlock with lost drm keys is not enough with oreo.
I cannot test it anymore and I wonder if it still depends on drm keys with pie too or if sony dropped that dependency similarly as making camera somehow working instead of green pictures with pie.
@j4nn
Screen mirroring still is reliant on drm keys on Pie.
It won't connect with unlocked bootloader and stock kernel.
However with restored TA backup and blu hide kernel it connects without issue.
The problem with screen mirroring is just the use of HDCP.
You can disable it with persist.debug.wfd.enable=1 or persist.debug.wfd.appmonitoring=1

Question What is the benefits of Rooting these days?

I used to do it to flash firmwares but that does not seem to be prevalent any more, so why do I need to root?
I know this is a developer/modding site but I have to agree with the OP.
I come here for the general forum information that is "usually" more technical for obvious reasons. But to risk a very expensive tool for unlocking and modding....the risks far outweigh the benefits...IMO...YMMV
App & system theming (with Substratum + Swift Black, Repainter for pure system AMOLED black & Project Themer for different notification styles, lockscreen clock etc.). System-wide equaliser (currently with JamesDSP but will await VIper4Android working on A13 hopefully), system-wide ad-blocking. Revanced Youtube for background play etc.
Plus with AOSP Mods via Magisk it adds tons on features like customisable quick toggle column/row quantities + label text size, clock position, removing carrier label from status bar, long press power button screen off for torch and so much more! Plus not to mention custom rom support which whilst sometimes buggy, come with a wealth of benefits. I like to stick to stock these days with AOSP Mods & Magisk, as that module has many features and saves having any custom rom bugs (e.g. on Pixel 6 Pro, a custom rom would lose Magic Eraser whereas having a modded stock, retained it)/
I get the risks, but we do plenty of research and tread carefully and all is generally ok!
Got my Pixel 7 Pro just today and bootloader unlocked after the first OTA came through. It's now rooted and without passing safetynet currently, all cards successfully added to my Google Wallet.
Running like a dream
I used to root every one of my previous phones, but I've not done so on my Noted 10 Plus as I find Samsung Pay too useful. And rooting destroys it forever. Not sure if Google Pay still works when rooted, that may nudge me to do it.
I have no plans to root my 7 Pro when it arrives. But that may change.
Naughty boy client for Pokemon GO and system-wide AdBlock
For me the main thing is working app backup, since the Google solution is absolutely unreasonable (I have several non-play-store apps that I have had on every smartphone I've owned, and data generally isn't saved with Google anyway) But also tons of little things like being able to set a limit on battery charge level, full (to the extent still possible) filesystem access, a floating CPU monitor I like, Greenify, Island, Tasker stuff, etc.
System wide as blocking since 2012. No other phone does it better and easier.
How about Banking? I ditched rooting since all Banking apps denied to work. Workaround didn't work anymore.
Custom kernels that save on battery
Better Internet Tiles
ACC (Advanced Charging Controller) and AccA (Advanced Charging Controller App)
@siavash79's thread [MOD][Xposed+Magisk][Pre-Release] AOSP Mods - System modifications for AOSP-based Android 12+. This is a big one for me, personally.
Classic Power Menu
Swift Backup
hey_malik said:
How about Banking? I ditched rooting since all Banking apps denied to work. Workaround didn't work anymore.
Click to expand...
Click to collapse
Just use their website? Or switch banks? I have my primary bank with a local outfit that doesn't care about rooting (although that's not why I got them, it certainly helps keep me there) if I need to deposit a check and everything else can be done on their mobile website.
My main reason would be for the custom Kernels and for Viper4Android. I didn't have a bunch of $ to fork out for 2 new phones so I went with Verizon so I won't be getting either unless I hit the lottery and then buy a Google Version of the P7P.
Anyone remember what made us able to root/ unlock the bootloader On the OG Verizon pixel?
Any chance of that happening on this device or should I just go ahead and do the system update that's waiting? For instance, I know the Samsung Galaxy Note Ultra 20 5G on Verizon(The Device I'm switching from) was locked down but apparently some guy on XDA started an Unlock service and would unlock it for ~$100.
I root since it's my XDA addiction!
Also add Titanium to the attached list!
bryan1854 said:
Any chance of that happening on this device or should I just go ahead and do the system update that's waiting? For instance, I know the Samsung Galaxy Note Ultra 20 5G on Verizon(The Device I'm switching from) was locked down but apparently some guy on XDA started an Unlock service and would unlock it for ~$100.
Click to expand...
Click to collapse
From memory on the Verizon Pixel 1, there was a bug on Android 7.10, I believe it was, that fully just allowed us to toggle OEM unlocking on. From there it was a done deal. They patched it in 7.11. Again, from memory but it was either that or 7.11 before and 7.12 after.
And no, not likely to happen again. It would be very, very rare and like hitting the lottery. Didn't happen on the Pixel 6 Pro.
roirraW edor ehT said:
From memory on the Verizon Pixel 1, there was a bug on Android 7.10, I believe it was, that fully just allowed us to toggle OEM unlocking on. From there it was a done deal. They patched it in 7.11. Again, from memory but it was either that or 7.11 before and 7.12 after.
And no, not likely to happen again. It would be very, very rare and like hitting the lottery. Didn't happen on the Pixel 6 Pro.
Click to expand...
Click to collapse
Maybe I will contact the guy doing it for the note 20 ultra and see if he thinks whatever he's doing to those phones is possible here.
Thanks for the reply.
galaxys said:
I root since it's my XDA addiction!
Also add Titanium to the attached list!
Click to expand...
Click to collapse
holy crap, when you mention "Titanium", do you mean the backup?! or even the "tweaker"? either way, aren't those EOL for years???
EtherealRemnant said:
Just use their website? Or switch banks? I have my primary bank with a local outfit that doesn't care about rooting (although that's not why I got them, it certainly helps keep me there) if I need to deposit a check and everything else can be done on their mobile website.
Click to expand...
Click to collapse
I don't see how that again helps with tan apps. But sure just don't use it is always an option.
hey_malik said:
I don't see how that again helps with tan apps. But sure just don't use it is always an option.
Click to expand...
Click to collapse
The reality is that forced hardware attestation and the Play Integrity API will soon put an end to the tricks used to get around detection so people will have to figure out what root is worth to them. I decided awhile ago that I can live without it. Adb pull /sdcard does a nice enough backup job for me and Google's cloud backup pulls partial app data and will restore it where applicable.
Of course it does seem that there isn't a way to disable 5G SA on Pixels without disabling 5G altogether so I may have a use for root in the end anyway, time will tell, as I get sick of being stuck on T-Mobile's slow as molasses SA when midband is available.
Well i have rooted every other phone and rooting, installing kernel or roms solve some problem where oem is lazy or will not solve. Previously i was using OnePlus 7 pro with unlocked bootloader initially with Android 9. During Android 10 i prefer to lock bootloader again as during that time i was damm busy and getting time for root and transfer data was not possible. During Android 11 Oneplus had really ****ed up, device was getting hot like frying pan in summer. I really had no choice but to unlock bootloader and installed a stable custom rom(CR Droid) . Everything was perfect. After 9-10 months i thought i willl go to stock again and lock bootloader. But to my surprise cts profile was not getting matched. My phone was constantly recognized as Google pixel 6 pro (no NFC payment and play store dont recognize netfix) . Only safety net fix with Magisk was able to fix it. What really surprise is when i again installed Oxygen OS 10 cts profile was showing match with locked bootloader and with Oxygen OS 11,12 will show CTS profile mismatch. I really don't know what i had done wrong and there is no solution for locked bootloader.
So my suggestion is if anybody really want to unlock bootloader and have magisk prefer with your secondary device.
Is it possible to unlock 5G in another countries with root while having functional google wallet?
I only do it for AdAway. Would be wonderful if I could avoid rooting for blocking ads since it makes a few apps unusable (specificly Norwegian with no rooting community support). But I'll probably root my P7P when I get it on monday.

Categories

Resources