Print 15 comment(s) - last by lexluthermiest.. on Aug 4 at 2:38 AM

Google's modifications make root less powerful in Android 4.3, and that's good says Steve Kondik

Power users have long rooted their smartphones to gain access to capabilities not available to locked devices.  Apple, Inc. (AAPLactively fights rooting; Microsoft Corp. (MSFT) allows it, but only for developers; and Google Inc. (GOOG) and its OEM partners mostly condone and support rooting.

But the key issue with rooting is that it opens the device up to new attacks (one of the justifications Apple often gives for fighting rooting).

Steve "Cyanogen" Kondik -- a Washington-area Android developer whose CyanogenMod replacement firmware is currently used by over 5 million Android users -- points out that new APIs from Google make keeping root privileges active in aftermarket mods (like CyanogenMod) less essential.  He reveals:

Android 4.3 introduces some new and much needed security features which not only restrict setuid binaries on the system partition (su), but also limit the capabilities of processes. In the current architecture, even if you could get elevated privileges, you can't do anything out of the ordinary. Root in the shell via ADB is all I use, and it still works just fine.

Steve Kondik
Steve "Cyanogen" Kondik [Image Source: Google+]

In other words, Google is restricting root for security reasons.  But Mr. Kondik says Android's open source make this a virtual non-issue:

This isn't a problem for me, since I use CM. When there is a situation that I'd need root, I just modify the system to accomodate what I'm trying to accomplish in a secure way.
A few good use cases for root are:

* Firewalls and network software, potentially requiring raw sockets.
* Managing the DNS resolver
* Tweaking various sysfs nodes to control the kernel

All of these can be done without exposing root, and they can be done in a very secure way.

Cyanogen Mod
CyanogenMod is aiming to provide alternatives to full blown root access.

In a follow-up post, he continues to push his philosophy that deep firmware fan mods (such as his own CyanogenMod framework) are a superior alternative to using a stock ROM and simply leaving exploit-granted root privileges open.  He writes:

Now you can write your app and a whole new class of applications that you couldn't do without using the root sledgehammer before. Yeah, it's harder, and you need to learn the system architecture a bit, but the result is much better and more importantly it's not a gaping security hole.
I might be exploiting this as an opportunity to sell the ideas behind CM, but I think it's a powerful concept. If your app needs to do something that normally can't be done, you can easily bend the system to your will and do it right.

Android 4.3 cracks down on root's capabilities.

For those users who want root he reassures that he will continue to support it, writing in yet another follow-up:

Just to be clear- I have no intention of removing root from CM. What I want to see is the common use cases supported by the platform so that we can write more powerful apps.

But it's clear that he feels that leaving root open is a dangerous proposition, even for your average power-user. He also feels that regimented privilege extension via new API frameworks are a superior alternative.

Sources: Steve "Cyanogen" Kondik [1], [2], [3]

Comments     Threshold

This article is over a month old, voting and posting comments is disabled

Cool stuff.
By retrospooty on 7/29/2013 11:45:18 AM , Rating: 2
I just got a Nexus 7 2013 over the weekend and rooted it right away. It rid run really smooth and clean, not a lot of garbage. If not for several apps I use that require root, I wouldn't have needed it. Hopefully in a few months when newer version are written taking advantage of these new API's we wont need it as much.

BTW, this tablet rocks. I am SOOOOOOOO happy with it. It has finally gotten to the point of perfection. The only thing I would make different would be screen size. A Nexus 8 would be perfect to me.... Add it looks like its coming.

RE: Cool stuff.
By tayb on 7/29/2013 1:59:24 PM , Rating: 2
I picked one up on Friday and I am pretty happy with it. Best Buy must have received a bad batch because I went through two before finding one that didn't have a bad OS that kept erroring. A little nervous about that but otherwise loving it. I haven't needed to root it yet but I may eventually.

It seems pretty fast thus far. The anand review actually indicates that this thing is running an underclocked Snapdragon 600.

The only thing I wish this thing had was an active digitizer a la the Note 8.0. If these two devices could be combined it would be the perfect table in my opinion. I would definitely pay more for that. Otherwise I'm pretty happy.

RE: Cool stuff.
By Monkey's Uncle on 7/29/2013 7:33:44 PM , Rating: 2
Good to hear 'spooty. Those look like sweet devices. & inc tablets are my sweet spot since they are the perfect size to use as a book reader. A bigger screen is better for HD porn, but meh! 7" displays will do in a pinch!

Reading this article reminded me that I still needed to re-root my 4.3 image on my 1st gen Nexus 7 (I installed a recovery image from Google so it wiped my old root/TWRP recovery) :/

As an argument for rooting - Titanium Backup requires root access to take full images of your device. Kinda need it for Nandroid backups too. I'm a backup freak and you really can't do a good image backup without rooting.

"If a man really wants to make a million dollars, the best way would be to start his own religion." -- Scientology founder L. Ron. Hubbard

Copyright 2016 DailyTech LLC. - RSS Feed | Advertise | About Us | Ethics | FAQ | Terms, Conditions & Privacy Information | Kristopher Kubicki