There are a lot of tutorials on the Internet (there are even so-called "one-click ROOT" methods). These tutorials will surprise you and find out how easy it is to get ROOT. Ideally, every user should know why they need to ROOT before taking this step, and more importantly, how to save the information on their phone before doing so.
However, this is not an ideal world. Every day I see newbies immediately rooting their phones as soon as they get them, and then ask: What is the use of rooting? We cannot entirely blame the user, because many tutorials do not emphasize the serious consequences that rooting may cause, which will endanger the security of the device in your hand.
What is even more contradictory is that these tutorials assume that readers already have a certain technical level, but often these tutorials are classified as novice tutorials! My point is, many users don't need ROOT access at all!
Before starting the discussion, ask yourself the following two questions:
1. How many times have you read the license agreement for software or games you downloaded from the market?
2. How many times have you read the permission requirements (full internet, gpslocation, readcontacts, etc.) in the software usage agreement and asked, "Well, why does this game need these permissions?"
Did you just install it correctly? The fact is that the vast majority of users don't care about the permissions required by the ANDROID program, and they will just install it.
Although the wet market has notified users of the permissions required by the software, this is far from enough. Because users still don't know what the relationship between these permissions and security is. Once you approve the permissions requested by these software.
You are equivalent to opening the door to your home to these software. For example, the program can arbitrarily send the information of the contacts on your phone to their server.
To give another example, some software may not be malicious, but its design is extremely bad. Because developers are human and make mistakes. Sometimes programmers choose a protocol that they think is safe, but is actually very dangerous. Or they decide to let all users use SINGLESIGNON, but output the user's SSO information to the console in DEBUGGINGCODE. Or there may be some malware that allows others to remotely clear your phone, or send the information in your phone back to a designated server and then clear your phone (perhaps such software already exists).
The examples I mentioned above show that even programs with non-ROOT permissions can be dangerous (for novices), but what about those programs with ROOT permissions?
Okay, now back to the topic we want to discuss.
Of course, many MOD firmwares already include superuser programs, but is this enough? Like the account control message in WINDOWS or similar programs in other operating systems, this program only tells the user when the program requires superuser permissions, but it does not (cannot?) tell us what the program needs to use these permissions for! ! How many times have we chosen "always allow" (me too) without knowing what the program is actually doing. How on earth can we know? Most people have no way of knowing this. We can only rely on other users to tell us. Or do we fully trust the program's developers? But do you dare to trust 100% someone you have never met?
In many but not all cases, these programs are open source, so we can read their code to assess the risk. However, this is a double-edged sword. Others can also add a backdoor to the code, name it a customized version, and openly enter your phone. One such program among a hundred programs is enough for you. But what can a malicious or ROOT-authorized software do? Two words: anything!
I discussed it with my friends and concluded the following points:
@Replace GMAIL with the so-called "customized version"
@Change your input method to one with key recording function
@Delete the programs or data in the phone
@Download and try to install the modified firmware
@Download a specific program, you can dial toll phone numbers in the background at night.
@Invade your wet market account and purchase software "for you".
@More. . .
Fortunately, such a program has not yet appeared. Hopefully there won't be any in the future. Chances are you're now thinking, "Oh my God, this stuff is scary..." and I, the author, will be happy too. If users can be aware of the potential threats of misuse of ROOT permissions and keep this in mind, they can better protect their own devices and information. Before using a piece of software and trusting its developer, do your homework and search online. For security reasons, do not select "ALWAYS ALLOW" in the super user program, although this cannot completely protect the security of your device. In fact, some functions should not require ROOT permissions at all. For example, many users obtain ROOT permissions just to add some of their own themes. If ANDROID could natively support adding themes by yourself, then many users would not need ROOT. Some users ROOT in order to optimize their phones to run faster. So why not integrate these optimization programs directly into the official firmware? For example, because the storage space of G1 is quite limited, we have to use APP2SD to install the program into the SD card. Why can't this program be integrated into the official firmware? Let users always remember the importance of security.
Security risks after Android phones obtain ROOT permissions
Replies (5)
→_→。,
...The crappy phone takes up space
I'm speechless ^ OP, madam ^ After rooting, the phone will be safer ^ For those who don't know how to use it, it could be very dangerous
Passing through Saipan
A scholar passes by
— All replies loaded —