Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My supermarket's loyalty app refuses to run on rooted devices, I imagine they are using something like this to detect if the device is rooted (e.g. looking for Magisk). It makes no sense, because all it does is show what offers are available that week (which you can also see on their website) and provide the same QR code that is on the physical card. I imagine some PM at whatever agency they used decided they wanted to make it secure (and upsell that to the client), and installed some nonsense SDK like this.

My bank's app have no issues with my phone being rooted :-) Fortunately Magisk Hide fixes it.



Brute forcing coupon and gift card codes and selling them is a big business.


Big business means it would've been defeated or just completely worked around - truth is that if you're doing this at scale you'd just reverse engineer how the application talks to the backend and replicate that in your software.

Just like DRM, it inconveniences legitimate use while doing little to defend against malicious use.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: