Yes, of course, you can do this, but let's not pretend there aren't trade offs.
Sent from my iPhone (after 13 years of using Android)
Alternatively, you can use ADB + Frida to pull an APK from the device, inject a binary, and inject code at runtime using Javascript or Python. That's much easier for intercepting traffic than messing with certificate stores or eBPF ever was in my opinion.
Any quality documentation on how to do this would be great.
As a concept, Frida works by running a gadget on the phone (as root, or as part of an app) and a client on another device (or the same device, I suppose, if you're using a terminal emulator on Android).
To install the gadget, you either download the right binary and execute it on the phone as root, or use a tool like https://github.com/ksg97031/frida-gadget to inject the gadget into an APK.
Then, use Frida (https://frida.re/docs/Android) to connect to the gadget and load any script you want. There are a bunch of scripts that can be used to patch out certificate validation, or to exclusively use a certificate authority of your choice, or you can write your own.
You can download scripts and run them directly, or you can run Frida with a command line flag to open up a remote debugging port; you can connect to that port from the Chrome dev tools and get an interactive code execution prompt. From there, you can patch out Java methods, load native binaries, patch memory, whatever you want. It's a really powerful tool for debugging and reversing applications you don't have the source for.
Not much I can do with that data, other than sleep in comfort knowing that its the case.
There are plenty of pay2win games out there, but if the game doesn't tell you that paying will give you an unfair advantage /or what advantage you're getting, exactly) I'd consider that worth reporting on, especially if the game has a decently large following!
Are there some words in the parent comment that "pretend there aren't tradeoffs". Is it that he did not include a warning about "SafetyNet". What would this "pretending" look like.
Losing access to "a bunch of apps you may care about" seems to be dependent on an assumption: that the reader cares about certain unnamed apps. Yet we cannot even name these apps. We cannot know what apps a user cares about unless the user tells us. I know Android users that do not use any apps that rely on SafetyNet.
Nor do we know what device manufacturer the reader may be dealing with. It might be one where it's relatively easy to the computer owner to have root privileges.
Perhaps we can refrain from making assumptions about readers.
Yes. They quoted it! "you just need root". Especially the word just. That kind of phrasing implies that it's not flat-out impossible on many devices and that it doesn't break major functionality.
"I know users that don't use that feature" is praising with faint damnation.
Anyone know why there is an aarch64 nocore but not an x86_64 nocore.
It's all been slowly cooking for a decade, yet people will still claim "but you can still do it with root, so it's as free as before!" (or some other ridiculously complicated workaround with lots of nasty side-effects)
These are tempting choices, but they go a lot further than, for example, requiring only modern TLS ciphersuites to be used to communicate with my servers. They dictate the state of your entire device, and no one app or company should have that power, unless you work for the company and they issue you the device -- but even then, modern MDM/MAM can and should sandbox company apps from the rest of the device.
Google has little choice but to provide them with the tools to detect root access.
Some of the entities that want it do have pull.
And while for years the alternatives have been almost nonexistent, we do have at least two now : PinePhone and Librem 5.
You have to use pretty shaky workarounds to trick them, and there is a known way to make those workarounds impossible.
Features though? Maybe I don't realize all the great things I'm missing out on since I've only ever used rooted phones since I got my first Android device many years ago.
As for apps, I've only heard of certain games (I don't play games on my phone) and banking apps (thankfully mine doesn't care, though I'd rather use a desktop web interface for financial stuff).