• Login:

Welcome to the Xoom Forum - Motorola Xoom Forum.

Register ButtonIf this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed.

CyanogenMod: No Longer Enable Root Access By Default

This is a discussion on CyanogenMod: No Longer Enable Root Access By Default within the Motorola Xoom General Discussion forums, part of the Motorola Xoom Forum category; Security and You Many of you may not give it a second glance, but among all the furor and concern about permissions requested by market ...

+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Super Moderator

    Member #
    11318
    Join Date
    Aug 2011
    Location
    Singapore
    Posts
    7,294
    Liked
    720 times
    Twitter
    It's a bird

    CyanogenMod: No Longer Enable Root Access By Default

    Security and You


    Many of you may not give it a second glance, but among all the furor and concern about permissions requested by market apps and privacy, all Custom ROMs (CyanogenMod included) ship with one major security risk — root!

    We have been struggling with how to handle this for quite a bit, and took a first step with the first public CyanogenMod 9 alpha builds, by disabling the previously-default root access over USB. You can still get adb root access by running “adb root” in terminal, should you ever need it.


    We recently merged 3 patches into CyanogenMod 9, to further address this: Gerrit Code Review Gerrit Code Review and Gerrit Code Review.


    What follows is an explanation of the changes, how they affect you and our reasoning behind them.


    What do the patches do?

    They disable root selectively and in a configurable way. Users will be able to configure their exposure to root as:
    • Disabled
    • Enabled for ADB only
    • Enabled for Apps only
    • Enabled for both

    How does this change affect the usage of your device, and root apps you have installed?

    On a default CyanogenMod installation, root usage will have to be explicitly enabled by the user. This means that the user is fully aware that any application that uses root may perform actions that could compromise security, stability and data integrity. Once enabled, the process mirrors that of the current process, apps that request root will be flagged by the SuperUser.apk and the user will have to grant selective access.


    Why the change?

    At CyanogenMod, security has always been one of our primary concerns, however, we were hesitant to make a change that might disrupt the current root ecosystem. With CyanogenMod 9 we have the opportunity to do things better, whether its the code in the OS, UI/UX, or security – we are taking this time to do things with a fresh approach.

    Shipping root enabled by default to 1,000,000+ devices was a gaping hole. With these changes we believe we have reached a compromise that allows enthusiasts to keep using root if they so desire but also provide a good level of security to the majority of users.

    What concerns remain?

    Many of you reading this are savvy enough to note a remaining hole in this approach – recovery and unlocked bootloaders. The bootloaders are out of our hands, there is little to nothing we can do on that front.

    Regarding recovery – with unlocked bootloaders, a malicious user could just flash a new recovery image (without any potential security we could apply) or just dump the data partition. This however, requires physical access to the device. As such, the security standards for this are highly reliant on you, the device owner. Data encryption is available in ICS to safeguard your data. (Warning for emmc only users – encrypted /data means recovery will be non-functional.)
    The onus is on you to secure your device; take care of your possessions, and this risk is minimal. Always make sure you take devices out of your car before you go into the mall and remove them from pockets before washing laundry. Common sense is a basic security tool.

    But Why?

    We honestly believe there are limited uses for root on CyanogenMod, and none that warrant shipping the OS defaulted to unsecured.


    Source:

  2. # ADS
    Ads


  3. #2
    Administrator

    Member #
    2101
    Join Date
    Mar 2011
    Location
    Wichita Falls
    Posts
    34,251
    Liked
    2181 times
    Twitter
    mgrant76308
    I read this yesterday, not sure if I'm on board with it or not.

    SGS-IV-Stock_Rooted
    Nexus 4 - CyanMod 10.1
    SGS-II - Rooted - Jedi Mind Trick VX3
    Samsung Note II - Jedi Master 13
    Motorola Xoom - WiFi - Rooted - EOS 4.2.1 Nightlies

  4. #3
    Super Moderator

    Member #
    1535
    Join Date
    Mar 2011
    Posts
    3,903
    Liked
    232 times
    If I remember correctly, the new superuser by chainfire lets you root/unroot with a click. It would make CM9s stance very feasible. I don't believe the device should always remain in a rooted state just like I don't believe people should run an admin account on a windows box by default.
    SDcard System Image Backup Using ClockworkMod Recovery v3.2.0.0.(RC4). Back yours up today!


 

Ads

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Similar Threads

  1. Will Google ever enable write access for the external microSD?
    By teddybear in forum ICS General Discussion
    Replies: 2
    Last Post: 03-12-2012, 09:31 AM
  2. any way to un root Xoom, WITHOUT computer access?
    By 6.2 in forum Motorola Xoom WiFi General Discussion
    Replies: 2
    Last Post: 01-22-2012, 09:52 PM
  3. Rooted xoom, can no longer access market ?!
    By sirlagalot in forum Motorola Xoom Help
    Replies: 9
    Last Post: 11-13-2011, 08:16 AM
  4. can we still gain root access after the 3.2.1 update?
    By initialjdg in forum Motorola Xoom General Discussion
    Replies: 9
    Last Post: 09-22-2011, 04:49 PM
  5. Charging Xoom takes longer after root and new Kernel
    By SirDragonx in forum Motorola Xoom Development
    Replies: 4
    Last Post: 05-11-2011, 11:51 AM

Search tags for this page

cyanogen unroot
,
cyanogenmod 9 unroot
,
cyanogenmod not rooted
,

cyanogenmod unroot

,
cyanogenmod xoom
,
disable permissions on xoom
,
flash cyanogen on non rooted xoom?
,
flash cyanogenmod without computer
,
how to grant superuser privileges on cyanogenmod 9 alpha 2
,
how to unroot afer cyanogenmod 9 intall
,
how to unroot cyanogenmod
,

how to unroot cyanogenmod 9

,
root access xoom
,
root unrooted cyanogen
,
unroot after cyanogenmod
,

unroot cyanogenmod

,
unroot cyanogenmod 10
,

unroot cyanogenmod 9

,
unroot cyanogenmod 9 kindle fire
,
xoom root access
Click on a term to search for related topics.