ads

mardi 29 septembre 2015

No Android Pay with root and why it's BS.



Yes, this is a new thread because the existing ones are focused on the technical debates around why it should or shouldn't work.


I've been following this discussion to some degree and I just couldn't help but jump in. IMO the focus on the technical aspects of this issue are misguided. This is a purely, for lack of a better word, "political" decision.
Here's the thing. You can blather on for days about the supposed technical reasons that Android Pay cannot or should not work in a rooted/ROM'd environment, but the truth is, the state of the host device is nearly irrelevant. Consider this. You can take any Windows, Linux, or Mac PC and login with any level of user privilege you wish and use nearly any browser to access your bank's "secure" account website. There you can do MUCH more financial damage than you could ever do from a mobile payment app given the transaction limits placed on the latter. You can even do this from a pirated, hacked copy of Windows or MacOS with no issue. In fact you can login from a PC with known malware or trojan infections! Given this, anyone trying to make a technical security argument for not supporting mobile payment on rooted devices is either ignorant or lying. This was strictly an arbitrary decision on someone's part. Likely on the banking system's side.
The fact is, an Android phone with a rooted, custom ROM, is at best still a more secure environment than most PC's, at worst it's no less secure. Given the mechanism's in place on Android, it's even easier to verify an apps integrity than on a desktop OS.
So let's throw out all the pointless discussions about the technical issues that make mobile payment on rooted devices impossible. We already know that the banks have accepted much less than a perfectly pristine and secure environment for accessing their systems. Raising the bar for mobile devices was simply a bureaucratic decision, not a technical one.
If you want mobile payment on rooted devices, you'll have to lobby for it. Hard, and hope you can force anther bureaucratic decision in your favour. Even then I wouldn't hold my breath.



Aucun commentaire:

Enregistrer un commentaire