Skip to content

[ADVISE] Root hiding measures and advise to Mi Bancolombia's app future service blocking #112

Description

@Rayden-Berzerk409

Hey, this is more of an advise request. I'm frequent user of AOSP, Tricky Store, and often unlocked bootloader phones. My main banking app, Mi Bancolombia (only for Colombian users), usually runs just fine on rooted devices that don't necessarily pass Strong Integrity and just meets Basic and Device.

However, I noticed that they sent me an email about an upcoming change to the app in terms of "security" (which in practice means lose access to manage my own money on rooted devices, and zero freedom), coming from June 30th:

"Starting June 30th, the Mi Bancolombia app will stop working on some devices that don't meet the necessary security measures to protect you and function correctly.

Check if this applies to the phone or tablet you currently use to access the app. If your device:

  • Is in its original condition; no one has modified its Android operating system.
  • Allows official app and system updates.
  • Has apps downloaded only from certified stores like the Play Store.

You can use the Mi Bancolombia app normally; this change and information do not apply to you.

If your device doesn't meet any of these criteria, explore these alternatives to access your products:

  • Log in to the app from another phone or tablet. (Honestly, full BS)
  • Manage your requests online through your Personal Online Banking account (oftenly doesn't work)
  • Visit one of our physical locations: branches, banking correspondents, or ATMs (REALLY UNNECESSARY PROCESS, AND ALSO BS).
    "

I'm really worried about this, since I often use AOSP and therefore phones with unlocked bootloader. So I'm asking you guys, knowing exactly what this app is going to look for after June 30th, what exactly should I apply to the device in terms of root hiding (using, obviously, Tricky Store, PIF, HMA-OSS, TreatWheel, etc.), so I can keep using this app without having to stick strictly to have a locked phone?

Also, if this may be useful for improving root hiding for this app, I'm leaving this also so you guys the devs can take notice on this.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions