Appknox unveils two new features – Root Detection Bypass & Jailbreak Detection Bypass
Bengaluru, July 29th, 2022: Appknox, a leading mobile security testing platform, has announced two new featur es today – Root Detection Bypass and Jailbreak Detection Bypass. Through these features, Appknox users can identify if Root Detection has been implemented correctly in the Android applications and bypass it while runn ing Appknox’s Dynamic & API Scans. With this release, the Jailbreak implementation in iOS applications can be bypassed automatically. As a result, users can now upload .ipa files even with the Jailbreak Detection enabled and seamlessly run SAST, DAST & API scans.
- Android is very similar to Linux in that it runs on the Linux kernel. With access control similar to Linux, regular users of Android devices have very limited permissions compared to users who have rooted their devices. Without rooting, users cannot access or modify system files and folders. Once rooted, the user has full access to the device. Rooting allows the user to make changes to everything on the device. This allows users to do things that were previously impossible, like removing bloatware, customization, custom ROMs, etc.
Regarding these new features, Harshit Agarwarl, CEO of Appknox said, “Appknox’s vision is to make mobile app se curity as seamless as a thought, and in line with that, we have made Appknox platform accessible for Applications that have jailbreak and root detection check on as most of the apps on play store ensure they don’t run on a jailbroken or roo ted device. This is a first step towards making Appknox easy and simple to use for anybody at the company without hav ing technical knowledge and understanding the security posture of their app.”
Subho Halder, CISO of Appknox, shared a similar vision of the features and mentioned, “Appknox is committed to securing mobile applications with a holistic yet easy approach. Root & Jailbreak detections and their bypasses in the Ap pknox platform will ensure more coverage while performing vulnerability assessment. At Appknox, we will continue to build such features, making it comprehensive, smoother and easier for businesses to understand their security posture.”
What do We Need Root Detection for?
In addition to the benefits of rooting Android devices, many security issues are also associated with it. Once you have root privileges, you have full control to make changes across the device. But this also means your device is now an open target for threat actors. Rooted devices may contain many apps that process sensitive information, such as banking apps, payment apps, social media, and cloud storage. Malicious downloads can expose your devi ce to hackers. For these reasons, the apps installed on a device need to make sure that the device isn’t rooted. Th is acts as a precautionary measure to protect critical user and business information data.
iOS has always been considered a safe haven when it comes to mobile application security. Every year this oper ating system tries to come up with more and more efficient updates to make life easy for its users and the respe ctive application and security service providers. However, for tech-savvy users, these timely improvements may not sound enough and there are always people who consider that there is room for more improvement. And hen ce comes the term ‘Jailbreaking’.
What does ‘Jailbreaking’ Mean?
‘Jailbreaking’ is the process by which a user can gain access to the administrative commands and functions of an operating system. It gives the ability (or permission) to alter or replace system applications, files, and settings, re moving pre-installed applications, and running specialized applications (“apps”) that require administrator-level permissions. In a 2020 research on 425 million devices, Wandera highlighted that there had been a 50% increa se in the number of jailbroken devices from the previous year, a quite formidable jump! With jailbreaking, one ca n actually remove almost all the restrictions from their iOS device and open up gateways to make unimag inable modifications. While this may sound pretty fascinating at first, this also opens up innumerable avenues for secur ity vulnerabilities and threat actors to creep inside your device. So, let’s take a look at how application develope rs can take specific steps to ensure that their applications stay secure in the context of jailbroken devices.
“The features released now makes the lives of our users a little more easier. Now, they don’t have to disable these implem entations (Root detection & Jailbreak) to perform the vulnerability assessments. Once we’ve identified that there’s Root detection enabled in Android apps or the Jailbreak implementation is present in iOS apps, they can continue to perform the automated VA scans without any hindrance.” said Raghunandan J, Senior Product Manager at Appknox.
For additional links:
Founded in 2014 by Harshit Agarwal and Subho Halder, Appknox is a leading mobile security testing platform. Headquartered in Singapore and Bangalore, Appknox today is one of the most powerful plug-and-play security platforms which enables developers, security researchers, and enterprises to build safe and secure mobile ecos ystems using a system plus human approach. With its VAPT solutions (Vulnerability Assessment & Penetration Testing), Appknox has provided end-to-end mobile application security and testing strategies to over 500 busine sses & Enterprises globally. Appknox has also enabled some of the top government agencies with its On-Premis e s deployments. A champion of Value SaaS, Appknox has been recognized by Gartner as one of the recommended mobile app security vendors in its 2021 Application security Hype Cycle report.