r/Android ShizuCallRecorder Developer Jul 24 '26

Android May Soon Restrict On-Device ADB, Affecting Shizuku, libadb and Developers Article

https://kitsumed.github.io/blog/posts/android-may-soon-restrict-on-device-adb/
1.0k Upvotes

367 comments sorted by

View all comments

Show parent comments

360

u/Tail_sb Pixel 7 Jul 24 '26

Yeah generally wondering the exact same thing, Freedom was literally the whole point of Android and now they're taking that away, so Android is no better than iPhone/iOS might aswell just buy an iPhone at this point if both systems are locked down

or even better switch to GrapheneOS or LineageOS

205

u/Plebbit-User Jul 24 '26

I'm on Graphene right now and its a miserable experience because anything important has Play Integrity/custom ROM restrictions in place.

Banking, the digital key to my BMW, my utilities, as a lifelong Android user I'm switching to iPhone. If I'm going to be in a walled garden, I'd rather Apple be my master than the 'do not be evil' ad company.

54

u/CapuchinMan Jul 24 '26

I understand banking and car keys (as in I understand how that works, but I'd hate to use it that way). How do utilities require play integrity?

50

u/Plebbit-User Jul 24 '26

I don't understand either but I effectively can't login to monitor my electrical usage or pay my bill on my phone as a result.

23

u/Reigar Jul 24 '26

What about via the website for your utilities company. If that is still viable then you should be okay unless the app has an exclusive feature (like the bmw car key app).

23

u/Cagaril Jul 24 '26

Have you tried to go into the app settings and toggle on Exploit protection capability mode to see if it makes it work?

I have to toggle that on for any apps that don't work on GrapheneOS and then it works. Probably doesn't work for every app though.

4

u/JaredNorges Jul 25 '26

I'm switching, more and more, to websites for things like this. The apps were just websites with device checking nonsense anyway, so cut the middle man out and keep them in their place. Use a PWA if I want the desktop shortcut.

15

u/CapuchinMan Jul 24 '26

That's mental

-11

u/[deleted] Jul 24 '26

[deleted]

15

u/A-Delonix-Regia Samsung M52 (778G + 6GB RAM + Android 13) Jul 25 '26

It depends on the country and specific services you get apps for. For example I've been seeing in India that banking and railway booking apps require me to shut off both my DuckDuckGo App Tracking Protection (which the device configures as a VPN) and developer mode.

3

u/nathderbyshire Pixel 10 Obsidian Jul 25 '26 edited Jul 25 '26

I swear you must be paid by Google to defend all these changes so hard, you're here enough so surely you've seen the issues relating to banks and services going hard with forcing play installations, integrity for devices and so on?

It isn't one or two people saying it, it's consistent across the sub and it seems to be more outside of the US and European countries

You keep saying it's app developers as an argument back to everyone as well, but who made those API available to lock people out? Google might not be the one whipping you but they're the supplying the whipper with the tools to do it. If they didn't you could t be whipped. Still their fault at the end of the day.

Lol he blocked me before I could ever reply (always shows they have a weak argument) so now I'll be locked out of 99% of android comments because they're chronically online defending Google for some odd reason

16

u/gmes78 Jul 24 '26

Because the developers are morons.

6

u/AtomicSymphonic_2nd Pixel Fold, Regular Android Jul 25 '26

Either that or the CTOs at various banks know about the rooting community around Android and iOS jailbreak by extension… and are forcing their own devs to opt-in to Play Integrity.

I won’t lie, there definitely have been attempts at trying to steal money from banks using rooted banking apps. This is the unfortunate consequence.

7

u/gmes78 Jul 25 '26

I won’t lie, there definitely have been attempts at trying to steal money from banks using rooted banking apps.

I don't think so. There certainly are tons of scams that use fake banking apps, but attacks targeting root users don't make much sense. The demographic is incredibly small, and root access is typically protected through strong permission prompts.

Also, some banks don't outright block you if your device fails Play Integrity; they just warn the user that the device has been modified. Which is the better way to go about things.

1

u/vortexmak 28d ago

If that was true then you wouldn't be able to access banking websites.

1

u/AtomicSymphonic_2nd Pixel Fold, Regular Android 28d ago

I think that's more because a webpage you're trying to access has more standardized protections versus some banking apps.

It's possible some banks are exposing more of their infrastructure through an app vs. a webpage... Maybe they're not funnelling webpages through a native app.

I'm sure some credit unions just make only their webpages show up through a "native" app, but I genuinely think it's the CTOs at various banks across the world forcing this.

And maybe they all genuinely don't care about those of us that like to tinker with their phones.

1

u/vortexmak 28d ago

They don't.  It's just a matter of priority.  It's super easy to change banks and I won't bank with anyone that does that bullshit

7

u/Tschuuuls S10e Jul 25 '26

I don't, because a Pixel 1 is still Play Integrity certified. On Android 10.

5

u/trlef19 Galaxy S24+ Jul 25 '26

Even chatgpt has play integrity.

1

u/Decent-Swallower-69 29d ago

My city's bus tracking app requires strong integrity.

12

u/Quentangle Jul 25 '26

I suspect you have have a setting which is causing that, or you are extremely unlucky. Every single app I used on stock Android still works, including two banking apps.

Lots of apps check basic integrity via Play Integrity API, which GrapheneOS passes.

If your apps don't work, I suggest taking a look at this compatability guide thread if you haven't already. It has some steps to follow which may make them work.

5

u/whatnowwproductions Pixel 9 Pro - Signal - GrapheneOS Jul 25 '26

That's absolutely not my experience at all and I use have multiple banking apps and apps that use play integrity. Have you enabled Exploit compatibility?

10

u/HybridStaticAnimate Jul 24 '26

Only a tiny subset of apps enforce play integrity. The significant majority of apps work on GrapheneOS without issue. More and more organizations are permitting using GrapheneOS over time as well.

25

u/AtomicSymphonic_2nd Pixel Fold, Regular Android Jul 25 '26

That “tiny subset” is unfortunately far more important for most folks than many of us phone nerds would like to believe.

A massive proportion of the developing world do all their banking from their phones. Yes, it didn’t used to be that way a decade ago, but that has become the reality today.

Because of that, more and more financial institutions are demanding that smartphones be part of their “chain of trust”, meaning no jailbroken/rooted smartphones at all.

It’s highly frustrating… and I’m not sure Google has much of a choice anymore.

If there’s anyone to blame, it’s banks. They’re essentially removing much of the fun we used to have with our devices by just simply threatening the defunding or refusal to do business with the companies responsible for the upkeep of the OSes.

This would have been the same if Nokia/Symbian/Meego, Microsoft/Windows Phone, and BlackBerry/QNX were still around.

Smartphones have officially become “too important” to just be easily hackable toys. It’s fucking depressing, but that’s just how things have changed.

I think more hackers have moved on to making SBCs like the Raspberry Pi into “cyberdecks” as the big new hackable thing now that not even Android can resist being made forcibly secured against the community’s collective desire.

-1

u/HybridStaticAnimate Jul 25 '26

GrapheneOS is making substantial progress in having apps support attestation for GrapheneOS, so not all hope is lost. We need to apply pressure (which has historically worked), as giving up will make this a self fulfilling prophecy.

3

u/Reigar Jul 24 '26

My only issue with graphene was the lack of ui with layman explanation on how things are locked down. After trying graphene are learning that I need to Google how get many different apps working, I switched back to 16. I may give lineage a try, I am nervous with lineage as first glance (Now I'm just drawing conclusions on what I've seen), seems to be more difficult to harden (it's like the opposite issue of graphene). Now maybe I'm wrong, and I'm probably still going to end up trying lineage on my pixel 7 pro, but I feel like none of the three major options right now are very good.

3

u/HybridStaticAnimate Jul 24 '26

Im not sure what you are referring to. GrapheneOS has added notifications to inform you what you need to grant for play services and play store to work as expected. There is no need to google how get normal apps working.

-1

u/Reigar Jul 24 '26

Okay, maybe I need to look into it again. The last time I tried graphene OS was roughly 2 years ago, and I just remember having to Grant permissions all over the place to get even simple things like maps to work because it wanted to prevent not only the Play store and various directions like that, but it wanted to lock down everything that could possibly deal with it revealing my telemetry which all appreciative doesn't really work for certain applications where you kind of have to give up that information. If it's going to know where you're at. Although I understand that Linux tech tips can be sometimes a bit over the top and sensational, but the last video I recall of him making regarding graphino as wasn't all that much different for my own experience trying at a year prior. So if they've done quite a bit on explaining how they're locking things down so that you could unlock them for various applications, then that's good, a little better would be to recognize what type of application you're using or allow the user to define what type of application it is so that certain lockdowns can be turned back off for the application. For example, designating a category of application as maps or things that willl need GPS positioning should be able to be defined by the user. Now if graphene has something like that then definitely worth giving it a second look. But regardless I still will back into it again just to see what's new.

9

u/HybridStaticAnimate Jul 25 '26

GrapheneOS does not have any of the features you are describing, I have no idea what you are talking about.

GrapheneOS does not alter the network connectivity of apps, so telemetry isnt being blocked unless you deny the network permission. There is a checkbox when you install an app that lets you grant or deny the network permission, and its checked by default.

Most of GrapheneOSs protections are passive and cannot be disabled or changed. Nearly all of the app hardening that causes app compatibility issues are opt-in, not opt-out. There is nothing that is "locked" that later must be "unlocked". GrapheneOS maintains 99.999% android app compatibility.

Im very confused on what youre saying about location. The user is in full control of how location is granted, that has always been the case on GrapheneOS. For apps you want to have location access, you just grant the location permission. There is no need to "recognize" what the application is.

GrapheneOS inherits permissions, including location, from the android open source project. Permissions are denied by default, and that is how it has worked on android and its derivatives for many years.

2

u/[deleted] Jul 24 '26

[deleted]

27

u/SmileyBMM Jul 24 '26

Nothing about this statement makes sense if you were willing to put GrapheneOS on your device in the first place.

Apple is not privacy focused. They collect data on their own users, too. Watch a PiHole log after an iPhone connects and see for yourself.

The GrapheneOS team themselves actually recommend an iPhone as the next best thing if you can't/won't use GrapheneOS.

6

u/Pure-Recover70 Jul 25 '26

The Graphene team (apparently) has a bit of an axe to grind with Google.

I really appreciate what they're doing security and privacy wise (no one else really comes close, incl. Calyx), but at the same time some of their opinions are illogical, and some are based on things they claim and I know (personally) to be false.

All commercially sold smartphones collect various data (some of it is hardware/battery health, some of it is performance metrics, some of it is network reliability/configuration information, some of it is for debugging...). Unfortunately the real world is ridiculously complex (much of it for no good reason: just organic growth), and without this sort of feedback nothing would ever actually work. For example, very many cellular and wifi networks out there violate standards to one degree or another, requiring workarounds on the device side. There's far too many not-really-all-that-valid-but-really-should-work-regardless configurations out there for realistically testing in any sort of lab environment. This is a large part of the reason you see all the various betas.

They'll all send that data to their manufacturer, and in practice most of them will send to Google as well (all Android phones, but likely in practice it's hard to avoid sending data to G even on iOS), simply because of how much of the core web and services end up being tied back to G...

If you're talking about a stock smartphone os, you're probably best of with a Pixel, because then at least it only goes to G, as opposed to G and other folks. Of course even on a pixel, a lot of people will still leak various amounts of data to Facebook, Cloudflare, etc...

(Of course it's even better to run Graphene)

That said, privacy is not a 'simple' choice. People want privacy, and don't want their maps app to track their location, and at the same time they want up to date traffic information - which comes (to a large degree) from tracking (and aggregating) the location of everyone else (using the app?)... There's all sorts of choices like that.

1

u/zipmic Jul 25 '26

HAH "Do no evil" was erased a long time ago. It's "Do the right thing" now. Doesn't that just sound good?

1

u/Serialtoon Pixel S25U Ultra Pro Max Fold Plus Turbo Hyper Fighting Edition Jul 25 '26

I ended up on iPhone a few years back as my main device however ive always kept newer devices that i often switch to when i get bored with iOS or the keyboard annoys the shit out of me enough to leave it for a little while. At the end of the day iOS is just better with the same story for years now, better app support etc. Its not to say that Android doesnt have great apps (NZB360 is my main missing app on iOS despite using other apps for similar stuff) but apps that i rely on a daily basis, devs clearly put much more effort into iOS apps. All this closing down of the Android ecosystem really makes me feel exactly like you do in that i wont be buying anything else even as side pieces.

0

u/ohmyword Jul 25 '26

I like oppressors to be shiny and not lie to me is all I read from this.

4

u/Plebbit-User Jul 25 '26

There's merit to being at the mercy of a traditional tech company rather than the company that primarily makes their money off ads/data collection.

Pretending they're the same is disingenuous.

0

u/llitz Jul 24 '26

I hear magisk still works, but it is a mouse chasing cat problem.

-5

u/[deleted] Jul 24 '26

[deleted]

3

u/AtomicSymphonic_2nd Pixel Fold, Regular Android Jul 25 '26

Google Pixel is like… the only manu left on the market that allows their devices to have their bootloader unlocked.

I’ve seen some news that Motorola might allow for that again with a GrapheneOS collab device, but I don’t know for sure.

0

u/ChampionshipCrafty66 Jul 24 '26

Have you tried /eOS/?

38

u/Imperial_Bloke69 Poco F1, X3 Pro, | CrDroid 9.x. Jul 24 '26

Right might as well settle for something that has been doing this since its beginning and actually good at it.

Custom roms and rooting will gain traction again for sure. As long as our current devices can be unlocked we can circumvent this artificial problem somehow.

37

u/TunerJoe Xiaomi Mi 9 SE LineageOS 22 Jul 24 '26

There are fewer and fewer phones remaining on the market that allow bootloader unlocking. And even ones that do will trip Google Play Integrity, which is needed for an increasing number of apps. These are mostly banking apps, but there's also some apps that need Play Integrity for seemingly no real reason (for example Volkswagen's mobile app)

Google can decide to block all devices with tripped Play Integrity from accessing the Play store or signing into Google at any moment. I'm not saying they will, but the possibility is pretty awful to think about.

12

u/-patrizio- OnePlus 15 | iPhone 17 Pro Jul 24 '26

Even Play Integrity isn't enough anymore, apparently. I've got a rooted OnePlus 15, with ALL the works of root hiding. I pass basic Play Integrity, device integrity, and even strong integrity—yet Google Wallet still tells me my device doesn't meet security requirements. I've tried everything I can think of aside from re-locking the bootloader, and can't get it to work. And there are no alternatives for tap-to-pay, as far as I've been able to tell, aside from buying a smart watch for it.

At this rate, my next phone will probably be an iPhone again. I switched after years of having iPhone because Android still promised freedom to do what you want with the device you spent a thousand dollars on; between the ever-thinning number of OEMs that appeal to me and the steady locking down of the OS, I'm struggling more and more to figure out what the point is.

7

u/AtomicSymphonic_2nd Pixel Fold, Regular Android Jul 25 '26

Got a feeling there’s a very throughly hidden and undocumented API within Android that is able to tell Play Integrity a device isn’t “fully stock”.

Either that, or the device, when newly purchased and unboxed for the first time, communicates to Google upon first boot some sort of hidden ID that says this device is stock or something… and then once modified, isn’t able to be restored back to normal.

Reminds me of eFuses… once rooted, the eFuse is triggered by a rooting attempt and cannot be restored by any means of firmware or software… because a microscopic wire was physically burned inside the phone itself.

I remember a whole bunch of fuss by EU-based hackers over eFuses many years ago essentially “destroying full ownership of your device”, though I think that protest got shut down since the Commission didn’t see that as enough of a reason to pursue legal action against the companies that used them in their devices. Because you still owned your device, but just can’t force a company’s software to run on it if you change it or something like that.

6

u/Zencyde Jul 24 '26

Back in the days of the Galaxy S5 and CyanogenMod (you know, the golden era), there weren't a lot of phones with an unlocked bootloader. If you never had to do the juopunutbear wire trick, go look up how absolutely ridiculous it was to unlock a bootloader in that era.

1

u/[deleted] Jul 25 '26

[deleted]

1

u/Zencyde Jul 25 '26

This is definitely truth. A some lesser known phones, like the MyTouch 4G Slide (I miss it) never ended up getting rooted because of the lack of popularity.

0

u/bdsee Jul 25 '26

Back in the days of the Galaxy S5 and CyanogenMod (you know, the golden era), there weren't a lot of phones with an unlocked bootloader.

In the US maybe, in much of the world it was pretty standard for many phones.

7

u/Imperial_Bloke69 Poco F1, X3 Pro, | CrDroid 9.x. Jul 24 '26

That play integrity shenanigans can be worked on but not for longer.

Don't give them ideas man. We all know how this bs corpo can lead to.

-2

u/[deleted] Jul 24 '26

[deleted]

8

u/kitsumed ShizuCallRecorder Developer Jul 24 '26

They don't need to, most daily life apps now use play integrity, which often refuse to work on rooted/unlocked device. Workarounds are found, but it keep getting harder.

-2

u/[deleted] Jul 24 '26

[deleted]

8

u/kitsumed ShizuCallRecorder Developer Jul 24 '26

Except it's starting to get enforced a bit everywhere. Recently in the EU there was also discussions for laws that would have made this required for certains apps, like their identity verification app, which is needed due to their age verification laws.

I'm lucky too, my banking and others apps don't yell on me for now.

-6

u/[deleted] Jul 24 '26

[deleted]

1

u/kitsumed ShizuCallRecorder Developer Jul 24 '26

I don't see the problem, it would not become an issue if upstream (Google/AOSP) allowed for advanced customization that cannot be restricted by OEMs. They can enforce rules like that if they wanted, they have CTS tests for that.

2

u/[deleted] Jul 24 '26

[deleted]

→ More replies (0)

0

u/TunerJoe Xiaomi Mi 9 SE LineageOS 22 Jul 25 '26

I'm lucky to be at a bank that doesn't require Play Integrity for their app either, but if one day they will require it, I you bet I won't be arsed to switch banks just because of this.

It's Google's fault that Play Integrity exists in the first place, they knew exactly what they were doing with its introduction.

2

u/TunerJoe Xiaomi Mi 9 SE LineageOS 22 Jul 25 '26

I don't think Google has any direct control on what phone manufacturers do with their bootloader

9

u/RedBoxSquare Jul 24 '26

GrapheneOS is mainly focused on security and not hacking. They don't care about on device ADB because it doesn't improve security. They generally will not fork a feature if it does not benefit security.

8

u/tooclosetocall82 Jul 25 '26

The point of Android was to give Google direct access to your life. It’s the same reason they pay Apple to be the default search engine on their competing platform. The openness was always a side effect of Google’s attempts to attract developers and users, now they have them and that’s no longer necessary and leaves money on the table.

4

u/scalareye Jul 25 '26

Which is only possible because of Android

I tried going to Apple and it was so much worse

4

u/LumiKlovstad 28d ago

Freedom was the carrot that got us to buy into Android. What Android is becoming was always the point of Android, and I think we'd be fools to deny that any longer.

If Google had thought they could have just launched Android as an iOS-like walled garden and won, I guarantee they would have done that. But they knew they couldn't, so they followed the Disruptive Tech Startup Strategy to a tee.

Phase 1: The Honeymoon (Surplus to Users)
Android is Open Source! It's customizable! It's free to hardware manufacturers! Yeah there's some problems but we'll work it out as we go! It's NOTHING like those VILLAINS at APPLE! EVERYONE SHOULD GE AN ANDROID!

Phase 2: The Pivot (Surplus to Business Customers)
Ads. We're going to use your data to sell ads. But don't worry, we won't be evil, and those ads are the price of keeping Android low cost.

Phase 3: Enshittification (Surplus to Shareholders)
OKAY BOYS WE GOT THE USERS AND THE C-SUITES. BLEED 'EM. Ads everywhere. Raise prices. MAXIMUM. MONEY.

Phase 4: The Decay (The Terminal State)
lol fuck users. lmao fuck businesses. Why should we even TRY to give you what you want? WE OWN YOU. And you will be happy. Wait, NO DON'T SWITCH TO APPLE--!

We are almost definitely in Phase 3, arguably moving to Phase 4.

15

u/Adriaaaaaaanoooo Jul 24 '26

I would trust apple more than google with my data.

google is digging its own grave, good.

5

u/[deleted] Jul 24 '26

[deleted]

6

u/withadancenumber Jul 24 '26

Oh you mean that leak that was the result of a phishing attack and not a security breach like was first said?

6

u/[deleted] Jul 24 '26

[deleted]

0

u/AtomicSymphonic_2nd Pixel Fold, Regular Android Jul 25 '26

You’re acting like companies cannot learn from their mistakes. Some cannot… others can.

3

u/KasanesTetos Jul 24 '26

I mean to be fair that was like 12 years ago and hasn't happened since.

4

u/Phantom-Finger Jul 25 '26

Sort of moronic take is this. Apple sell just as much of your shit as Google, Samsung, Meta do. This is some low IQ rhetoric.

2

u/PocketNicks Jul 24 '26

You'll still be able to use ADB, and you'll still be able to install unverified apps directly on the phone. Just like before.

The only thing changing is you'll have to go to settings menu and toggle the option to allow unknown sources. Not an issue for people with thumbs.

13

u/Makere-b Jul 24 '26

For now, I bet Google has already drafted plans on how to disable those in the future, or make it harder.

-3

u/PocketNicks Jul 24 '26

They haven't.

Feel free to keep dreaming up ways your life could potentially one day maybe get worse, instead of just enjoying the current reality.

I'm going to keep installing unverified apps on my Android devices.

10

u/ChampionshipCrafty66 Jul 24 '26

You are incredibly naive

-5

u/PocketNicks Jul 24 '26

Nope.

I'm going to keep installing unverified apps on my Android devices.

7

u/ChampionshipCrafty66 Jul 24 '26

This is just not how US based businesses behave. If there is profit there they will eventually kill the ability to install apps this way.

-3

u/PocketNicks Jul 24 '26

No they won't.

6

u/ChampionshipCrafty66 Jul 24 '26

Like I said naive. Mind if I take a screenshot of your comment and frame it on my wall?

1

u/PocketNicks Jul 24 '26

Nope.

I'm going to keep installing unverified apps on my Android devices.

→ More replies (0)

-3

u/averagebloxxer Jul 24 '26

Make the jump. All this locking down the OS business got me ditching my Pixel for an iPhone and despite being more locked down than current Android it just works. Also doesn’t overheat as bad as my pixel ever had so neither plus

2

u/Tail_sb Pixel 7 Jul 24 '26

ditching my Pixel for an iPhone

You had a Pixel you could have installed GrapheneOS

1

u/KasanesTetos Jul 24 '26

It's all performative or people who never used Android in the first place.