Question Mix Fold 2 Security after Root - Xiaomi Mix Fold 2

Is it possible to re-lock the phone "Xiaomi Mix Fold 2" after rooting it and installing Magisk, and make the device secure enough to use for work with a clear conscience?
I would like to root the phone because I want the apps to be displayed in German. Actually, the English software wouldn't even bother me if it didn't also automatically set all the apps to English.

You can't have the bootloader lock and root.

NOSS8 said:
You can't have the bootloader lock and root.
Click to expand...
Click to collapse
Thanks for the answer. What would you do to secure your personal data after you rooted your device?

Bonzen81 said:
Thanks for the answer. What would you do to secure your personal data after you rooted your device?
Click to expand...
Click to collapse
Have a Xiaomi account with location enabled.
Have a pin code, or others on the lock screen.
install apps from trusted sites.
Grant apps only the necessary permissions.

Okay, is Face unlock safe on rooted androids? Or would you recommend to only use fingerprint or passcode?

In order of security:
Fingerprint,passcode,Face unlock .

Is it possible to encrypt the personal data of the rooted mix fold 2 with fingerprint?

As soon as there is security on the lock screen, the data is encrypted.

Thanks!

Related

how to completely secure android device ?

hi first of all i'm not a dev and i don't know much about deep functions, so i write this question as a regular user and to find answers that can be advanced in nature but should be easy to understand.
there are flashable zips available to break the lock screen security and to gain access to android device and access all apps with accounts logged in and everything else!
first of all i want to secure my device from any weak points like this, i don't want anyone to bypass my lock screen, but as i talked to a person about it, it looks like i can't survive this "Lock Screen Security Bypass" hack which removes some keys to break the lockscreen security.
then there was a suggestion to not root / unlock bootloader, not to flash custom recovery and not to turn on usb debugging. well even if i do that, there is still a possibility to unlock bootloader from odin mode and or may be flash something from there to break lock screen security, and gain root access and then flash this security bypass zip.
so what i can think is the only way to survive is to encrypt whole device? am i right?
and if i have to encrypt my whole device including ext-sdcard then will all the tweaks work? like xposed framework and it's apps etc? will my phone eat more battery? if i encrypt my device will i survive this lock screen bypass hack ?
please give your opinions by looking at all the possibilites. thanks in advance.
or may be if there is a way to put a password on custom recovery as well as all other modes from where someone can flash things into my phone?
i never heard of anything like that, but why no one is thinking about it?
no one?
Sent from my GT-N7100

Samsung galaxy j3 prime sm-j327t1

Does anyone have any development on this device? It's newer and running a droid 7.0 nougat. Any root info or bootloader unlock info would be greatly appreciated
I too am looking, upgraded from the smj320a, gotta day love the phone just needs root do I can retire my older one.
Side note, I noticed oem unlock is missing. Haven't been able to find a reason or answer.
Yeah I seen that too. I was thinking about trying the custom recovery twrp for the galaxy emerge which has the same board and specs as the j3 prime except it's running marshmallow. If I flash it that might work but then it will trip the frp lock and the phone will be soft bricked. It's hopeless with a locked bootloader
Well, frp bypass is kind of my new found hobby. Have locked 10 devices and bypassed them all, one was a new found bypass on the lg tribute 5 running that 5.1.1. So if you frp I can help. Can we tag people in these like that crap spy social network site? Aka FB. Because I do know someone who could possibly help.
I too would also like to root this phone. T-Mobile variant.
How do we go about getting the sm-j327t1 it's own set of development threads?
bobbyp1086 said:
Well, frp bypass is kind of my new found hobby. Have locked 10 devices and bypassed them all, one was a new found bypass on the lg tribute 5 running that 5.1.1. So if you frp I can help. Can we tag people in these like that crap spy social network site? Aka FB. Because I do know someone who could possibly help.
Click to expand...
Click to collapse
Frp is not locked as I have not tried to flash a recovery but I know if will lock if I flash my device with the bootloader locked
mrmack44240 said:
Frp is not locked as I have not tried to flash a recovery but I know if will lock if I flash my device with the bootloader locked
Click to expand...
Click to collapse
I did some digging and
https://forum.xda-developers.com/honor-5x/help/unlock-bootloader-issues-kiw-t3411032
Idk if that's what we're looking at so far only lead to it tho
Also did some digging with shortcut master found some interesting things
Adb shell getprop shows 1 for oem unlock ability
bobbyp1086 said:
Adb shell getprop shows 1 for oem unlock ability
Click to expand...
Click to collapse
At the same time it says it's not allowed check pictures
Also found this,
https://www.google.com/url?sa=t&sou...RE0Emhghh1sYy7IZw&sig2=DRKv6ALTtyfnCCjjE-CzgQ
Verified boot. Maybe a root that takes affect after boot. Like a temp boot, an on and off switch type root.
bobbyp1086 said:
At the same time it says it's not allowed check pictures
Click to expand...
Click to collapse
I don't own this device, but according to what I can gather, it seems that FRP can be OEM unlocked, but the property is not set hence the property set to 0 for sys.oem_unlock_allowed.
For why it doesn't appear in dev settings I think is another issue. Can anyone confirm that this device does NOT have a manufactuerer locked bootloader.
Just to clarify:
OEM unlock = disable Googles FRP lock not unlock the bootloader.
If this device has a manufacturer locked bootloader then the likelyhood of root for this device is minimal.
ashyx said:
I don't own this device, but according to what I can gather, it seems that FRP can be OEM unlocked, but the property is not set hence the property set to 0 for sys.oem_unlock_allowed.
For why it doesn't appear in dev settings I think is another issue. Can anyone confirm that this device does NOT have a manufactuerer locked bootloader.
Just to clarify:
OEM unlock = disable Googles FRP lock not unlock the bootloader.
If this device has a manufacturer locked bootloader then the likelyhood of root for this device is minimal.
Click to expand...
Click to collapse
How can I check it?
Also while roaming through a shortcut creator I noticed frp is an option in many of the secret menu settings, what ever happened to temp root?
bobbyp1086 said:
How can I check it?
Also while roaming through a shortcut creator I noticed frp is an option in many of the secret menu settings, what ever happened to temp root?
Click to expand...
Click to collapse
Do you have the stock firmware?
ashyx said:
Do you have the stock firmware?
Click to expand...
Click to collapse
Yes Sir only a week old
bobbyp1086 said:
Yes Sir only a week old
Click to expand...
Click to collapse
The easiest way would be to simply remove the signature from the stock recovery image and then see if it flashes with odin. If it does the bootloader isn't locked. If it fails then it's highly likely to be locked.
ashyx said:
The easiest way would be to simply remove the signature from the stock recovery image and then see if it flashes with odin. If it does the bootloader isn't locked. If it fails then it's highly likely to be locked.
Click to expand...
Click to collapse
English? I have Odin, then what
I found an article saying for oem unlock to factory reset and don't set up Google, no frp to stop oem unlock. I'm backing up apps now will update in a few hours
bobbyp1086 said:
I found an article saying for oem unlock to factory reset and don't set up Google, no frp to stop oem unlock. I'm backing up apps now will update in a few hours
Click to expand...
Click to collapse
That sounds promising
Yes I didn't set a screen lock as from what I've learned that's what activates frp, unfortunately my laptop has crashed (anyone good at bios pm me) but still no oem unlock and adb isn't working now, pc at work I've got android studios downloaded but I'll refrain from the lock until I can check, still don't know how to pull a signature from a stock image tho... But also in that article it States that oem unlock was enabled even tho there was no setting but they had unlocked boot loaders

Theft protection

Does android/S7 have anything equivalent to apples find my phone which effectively turns it into a brick when stolen? If so, how?
In the Google app settings there is a phone finding service you can activate, and some CSCs have "Find my mobile" which allows you to remote wipe / brick etc
but does this stop the device from being wiped if stolen and activating like apples activation lock does?
lofty5 said:
but does this stop the device from being wiped if stolen and activating like apples activation lock does?
Click to expand...
Click to collapse
Yes, provided you keep the bootloader locked.
EDIT: Technical term is FRP(Factory reset protection), and it's tied to the Google account used to set up the device
This is what i was thinking, that the boot loader has to be locked in order to do this. would keeping the phone rooted be an option or make it insecure?
Could i do this on a region that isn't my csc without bricking the phone? I'm pretty sure that as long as the source files are stock samsung any region should work. Can download mode be protected?
I'm currently backing up my device after which i am enabling all the security options and am going to try to hack into the phone to see if its worth doing or not. If it can be broken easily id rather keep it unprotected for convenience, but if i can protect the phone I'd rather do this as i lost my phone a couple of years ago and there was no protection on it at all nor on the sd card, which sucked.
bump
Root almost always requires a modified boot image which will immediately be blocked by a relocked bootloader. So root and FRP cannot coexist as they counteract each other. FRP itself is not CSC locked, only the remote control features. There are ways around it but they are mostly only present in older firmware, which is blocked by bootloader downgrade fuses. So yeah, pretty unbreakable if the device remains full Knox stock.
Hint: anything confidential should never be stored on the external card, or should be encrypted if it is (eg. Turn on encryption in titanium backup). Internal memory is always encrypted on stock firmware.
Edit: Download would work as usual. So basically what would happen is if a malicious firmware was flashed the bootloader will block it at boot and trip the Knox fuse, essentially burning all data on the device. If the crooks are smart they can still make use of the device, but most aren't so you should be safe
I'm using Cerberus, it can disable the shutdown/reboot menu on the lockscreen.
CurtisMJ said:
Root almost always requires a modified boot image which will immediately be blocked by a relocked bootloader. So root and FRP cannot coexist as they counteract each other. FRP itself is not CSC locked, only the remote control features. There are ways around it but they are mostly only present in older firmware, which is blocked by bootloader downgrade fuses. So yeah, pretty unbreakable if the device remains full Knox stock.
Hint: anything confidential should never be stored on the external card, or should be encrypted if it is (eg. Turn on encryption in titanium backup). Internal memory is always encrypted on stock firmware.
Edit: Download would work as usual. So basically what would happen is if a malicious firmware was flashed the bootloader will block it at boot and trip the Knox fuse, essentially burning all data on the device. If the crooks are smart they can still make use of the device, but most aren't so you should be safe
Click to expand...
Click to collapse
I had it rooted last night with magisk and boot loader locked, however it did refuse to boot due to modification and frp locked after a factory reset, but worked fine prior to this.
is it not worth doing if not fully knox stock?
I only really use root these days for titanium backup and perhaps ad blocking.
How difficult is it for a hacker to get back into the phone, I mean iPhones are practically impossible to get back into if on the latest firmware.
Blacky25 said:
I'm using Cerberus, it can disable the shutdown/reboot menu on the lockscreen.
Click to expand...
Click to collapse
is your boot loader locked and rooted?
lofty5 said:
is your boot loader locked and rooted?
Click to expand...
Click to collapse
Yes it is, I know it is also possible to delete everything but when I really loose my phone I will hope that people without the knowledge find my phone.
lofty5 said:
I had it rooted last night with magisk and boot loader locked, however it did refuse to boot due to modification and frp locked after a factory reset, but worked fine prior to this.
is it not worth doing if not fully knox stock?
I only really use root these days for titanium backup and perhaps ad blocking.
How difficult is it for a hacker to get back into the phone, I mean iPhones are practically impossible to get back into if on the latest firmware.
Click to expand...
Click to collapse
About as difficult as an iPhone to crack provided it's on latest firmware with a locked bootloader, even preventing reuse. FRP remains fully operational irregardless of Knox warranty status. It's possible to keep encryption while rooting (though this depends on strictly "close to stock" firmware, specifically by using a stock kernel binary. Ramdisk mods like Magisk or SuperSU are fine) to retain the data protection so thieves wont be able to deduce anything about you, but as long as the bootloader is unlocked a thief could always just wipe and reuse the device.
CurtisMJ said:
About as difficult as an iPhone to crack provided it's on latest firmware with a locked bootloader, even preventing reuse. FRP remains fully operational irregardless of Knox warranty status. It's possible to keep encryption while rooting (though this depends on strictly "close to stock" firmware, specifically by using a stock kernel binary. Ramdisk mods like Magisk or SuperSU are fine) to retain the data protection so thieves wont be able to deduce anything about you, but as long as the bootloader is unlocked a thief could always just wipe and reuse the device.
Click to expand...
Click to collapse
I am now back to full stock with no root. It’s not the same now as when i first started rooting back on the arc s, back then you could literally do nothing without it, things so basic such as a firewall. I only at this minute have one issue.
How in god’s name do you do a full backup of apps WITH data. I have helium but it refuses to backup most of them, it’s not a big deal now as i have re-setup the programs it wasn't compatible with. However, it would be handy to know for future reference, is there anything that can do a full backup with app data that doesn’t require root? If not, never mind I guess.
lofty5 said:
How in god’s name do you do a full backup of apps WITH data. I have helium but it refuses to backup most of them, it’s not a big deal now as i have re-setup the programs it wasn't compatible with. However, it would be handy to know for future reference, is there anything that can do a full backup with app data that doesn’t require root? If not, never mind I guess.
Click to expand...
Click to collapse
Not quite sure as I've always been rooted. Kies or Google Cloud Sync might be sufficient?
CurtisMJ said:
Not quite sure as I've always been rooted. Kies or Google Cloud Sync might be sufficient?
Click to expand...
Click to collapse
is the latest s7 fw protected against this attack?
https://forum.xda-developers.com/sa...galaxy-on5-metropcs-sm-g550t1-t3439557/page13
and root junkies hack?
lofty5 said:
is the latest s7 fw protected against this attack?
https://forum.xda-developers.com/sa...galaxy-on5-metropcs-sm-g550t1-t3439557/page13
and root junkies hack?
Click to expand...
Click to collapse
Only one way to find out An easy way to test would be to see if the phone responds to the USB command to dial the number, so no need to reset to check.

Is there Any way to bypass OEM unlock?

Hello There
Honorables
i have a Samsung phone G930F and i forgot its pattern and want to bypass its pattern lock without losing DATA...
can't install TWRP or ROOT my phone like android 4.4 because of OEM Lock...
please Help me if you can
haadimobiles said:
Hello There
Honorables
i have a Samsung phone G930F and i forgot its pattern and want to bypass its pattern lock without losing DATA...
can't install TWRP or ROOT my phone like android 4.4 because of OEM Lock...
please Help me if you can
Click to expand...
Click to collapse
Only way I know is factory reset. You can try and go to the snapdragon thread and use the root.bat we have, it removes lock screen use 2.82. It won't root without your confirmation (so no worries about messing it up) just let it do the first part (remove lockscreen)
Craz Basics said:
Only way I know is factory reset. You can try and go to the snapdragon thread and use the root.bat we have, it removes lock screen use 2.82. It won't root without your confirmation (so no worries about messing it up) just let it do the first part (remove lockscreen)
Click to expand...
Click to collapse
bruh how to remove lock screen for Samsung M20 with out losing data ?

Question Google pay indicates device isn't fulfilling security requirements

Hello,
On my OnePlus 9, I would like to activate Google Pay, but this service indicate me that my device isn't fulfilling security requirements.
I had root my phone when it was new, but now it's not the case anymore. Also, the play protect indicates that my phone is ok.
I have also tried several time to completely wipe cache and restore the phone without success.
Is there any way to improve current situation ?
DaMqXwEE said:
Hello,
On my OnePlus 9, I would like to activate Google Pay, but this service indicate me that my device isn't fulfilling security requirements.
I had root my phone when it was new, but now it's not the case anymore. Also, the play protect indicates that my phone is ok.
I have also tried several time to completely wipe cache and restore the phone without success.
Is there any way to improve current situation ?
Click to expand...
Click to collapse
If you were rooted your bootloader is probably still unlocked. Leaves an L 3 widevine without magisk. Causing cts to fail, Re-lock your bl. Reboot will wipe device this will fix issue.
mattie_49 said:
Leaves an L 3 widevine without magisk.
Click to expand...
Click to collapse
Honestly I didn't catch what you mean with "L 3 widevine".
Otherwise I re-activated the developer options to check, and the "OEM unlock" is gray (so I can change it's states), and looks like on tick position.
So your statement looks correct, but I don't know how I can easily access to this parameter in order to untick it.
DaMqXwEE said:
Honestly I didn't catch what you mean with "L 3 widevine".
Otherwise I re-activated the developer options to check, and the "OEM unlock" is gray (so I can change it's states), and looks like on tick position.
So your statement looks correct, but I don't know how I can easily access to this parameter in order to untick it.
Click to expand...
Click to collapse
OnePlus 9 / 9 Pro Unlock Bootloader Guide and Relock It Later
In this tutorial, we will show you the steps to unlock the bootloader on your OnePlus 9 and 9 Pro as well as relock it later on. Well, After the success
www.getdroidtips.com
. . This is for 9pro but it's exactly the same way read to the end of the Re-lock bl part. Gl

Categories

Resources