logoalt Hacker News

MIL-STDyesterday at 5:44 AM3 repliesview on HN

Root =/= insecure. You probably have administrator access on your home computer operating system, and can very likely do online banking via the web browser with no issues. A secure API is possible regardless of the host metal, operating system, or user permissions.


Replies

Itoldmyselfsoyesterday at 9:31 AM

Do you refer to app-accessible root or user root access? The former is absolutely inherently insecure and compromises the security model of Android/GOS.

fphyesterday at 8:56 AM

Root on computers is insecure. Malware can steal secrets from other applications. We're just used to it, but the Android security model is much better.

OtomotOyesterday at 5:56 AM

Bingo!

Compliance =!= Security