Oneplus 5t security updates vs custom ROM newbie - OnePlus 5T Questions & Answers

Hi I've never wanted to root or custom ROM. I read the instructions and they are pages deep and the issues that come up and are discussed in threads have such confusing back and forth discussions using lingo and abbreviations that make my head spin.
However... Oneplus did their last update on my 5t my fourth oneplus phone... With an already old security update.
Is the only way to not throw away a perfectly working, phone with good Ram and a fairly new battery I paid to have installed just months ago?
If I'm wanting to hold on another year or 2 use the only option custom ROMs that contain security updates?
Is there a way to add security updates without a ROM? Or maybe at least just learn to root and then add just updates or is it only in ROMs?
I could probably happily use my phone as is but worried what effect no security updates really is to my use.
I really tried videos on doing so this myself I'm not comfortable if problems happen. Not very techy.
Any help appreciated

Unfortunately you can no longer get security updates once your device is deemed as old.
Your options will be to get an antivirus app on your phone, install a custom ROM (like LOS or pixel exp), or you can get a new phone.
Since you're new to this stuff I highly recommend you just get a new phone or simply install an antivirus.
Not sure which anti virus is better than which. But I'm confident in Avira, McAfee, and Norton. You may want to purchase their plan though.
Hope I helped.

Thanks alot for the reply. I'll start with an antivirus.

Hello,
I have similar issue, since I would need security patch update to keep running company mails and apps.
I have 2 doubts:
- if I root and install Android 11 custom ROM, security patches will be updated too?
- after this, would I be able to unroot and install company mail apps ( if rooted they will not work) ?
Thanks

Personally I think that your company has put an unfair burden on you to run company mail and apps on your personal phone while expecting you to have an updated phone at the same time. An updated phone should have been "given" to you.
That being said, you can actually flash and run a custom rom without root. Root is optional.
Process is as follows: (you'll need a PC for this)
1. Backup ALL your data
2. Unlock the bootloader
3. Install custom recovery and reboot to recovery
4. Wipe cache & system and format internal memory
5. Copy custom rom & gapps to internal memory
6. Flash custom rom & gapps and reboot system

miloinodense said:
Hello,
I have similar issue, since I would need security patch update to keep running company mails and apps.
I have 2 doubts:
- if I root and install Android 11 custom ROM, security patches will be updated too?
- after this, would I be able to unroot and install company mail apps ( if rooted they will not work) ?
Thanks
Click to expand...
Click to collapse
Yes if you install custom ROM you'll have security updates. It doesn't have to be Android 11 and you don't need root to install a custom ROM.
Also make sure to follow a precise guide about it so you don't encounter any issues. Always make a backup even if you're 100% sure you won't need it.
As far as I know mail apps don't check the integrity or do a SafetyNet check, so even if you root or don't it will work fine.
If you mean banking apps then you can install some modules to bypass the check or just completely remove root. Assuming that you rooted the device.

It shows my lack of knowledge never ever did I think you could Flash a ROM without being rooted.
Thanks

I successfully installed custom ROM w/o root.
But regarding company mail apps, I would need to hide bootloader unlocked status.
maybe it's impossible, if someone has a good idea...

miloinodense said:
I successfully installed custom ROM w/o root.
But regarding company mail apps, I would need to hide bootloader unlocked status.
maybe it's impossible, if someone has a good idea...
Click to expand...
Click to collapse
My banking apps working fine without root with crdroid 7.3 and flamegapps. Might work for your company mail app too.
Some roms readily hide bootloader status

Thanks for the hint, but these company mails apps are checking security patch date too. Last available for oneplus 5t are September 2020, and no further support from oneplus.

miloinodense said:
Thanks for the hint, but these company mails apps are checking security patch date too. Last available for oneplus 5t are September 2020, and no further support from oneplus.
Click to expand...
Click to collapse
Hence that's why the burden should be on the company to provide the "up to date" phone

miloinodense said:
Thanks for the hint, but these company mails apps are checking security patch date too. Last available for oneplus 5t are September 2020, and no further support from oneplus.
Click to expand...
Click to collapse
And that's why the burden should be on the company to provide the "up to date" phone

miloinodense said:
Thanks for the hint, but these company mails apps are checking security patch date too. Last available for oneplus 5t are September 2020, and no further support from oneplus.
Click to expand...
Click to collapse
I think if you change build.prop to some other phone with recent security patches you can bypass this.

XDHx86 said:
I think if you change build.prop to some other phone with recent security patches you can bypass this.
Click to expand...
Click to collapse
Today, I was thinking that this could be good way.
Root, change build.prop, and then unroot.
If you have a link for a good tutorial on change bulid.prop would be nice, thanks.

miloinodense said:
Today, I was thinking that this could be good way.
Root, change build.prop, and then unroot.
If you have a link for a good tutorial on change bulid.prop would be nice, thanks.
Click to expand...
Click to collapse
Just for update:
I tried to Root a stock ROM, edit build.prop (security patch date), unroot, and then lock bootloader.
But even if it was a stock ROM, OP5T was not booting.
Booloader was stopping boot since it was detecting a non-stock ROM.
Indeed, I had to unbrick OP5T since I was not possible to unlock bootloader.
So, still not solved

miloinodense said:
Just for update:
I tried to Root a stock ROM, edit build.prop (security patch date), unroot, and then lock bootloader.
But even if it was a stock ROM, OP5T was not booting.
Booloader was stopping boot since it was detecting a non-stock ROM.
Indeed, I had to unbrick OP5T since I was not possible to unlock bootloader.
So, still not solved
Click to expand...
Click to collapse
Just edit build.prop and use magisk hide module from magisk manager.

XDHx86 said:
Just edit build.prop and use magisk hide module from magisk manager.
Click to expand...
Click to collapse
Edit build.prop w/o root and unlock bootloader is not possible...
Moreover, hiding root will not work with more recent android updates and for sure it will not hide unlock bootloader.

miloinodense said:
Edit build.prop w/o root and unlock bootloader is not possible...
Moreover, hiding root will not work with more recent android updates and for sure it will not hide unlock bootloader.
Click to expand...
Click to collapse
Yeah I assumed you would know that you should root first. But seeing you even attempted to lock bootloader after modifying the device, seems I assumed wrong.
Magisk hide is working fine on later android versions like 8+. And for the bootloader it only trips CTS if your bootloader is using hardware backed key - Which is the case with OP5 - as CTS check also has hardware attestation. But it is possible to bypass said check by using SafetyNet Fix module, of course you will also install that from magisk manager.

Related

Root & Rom Advice from the Ground Up

I need some help and I've looked all over but the information is fragmented and there is too many unfamiliar acronyms used which make it incredibly difficult for some like myself to catch up. So for the benefit of others who may be new I wanted to get some additional guidance.
I got the Pixel XL Google Version
Objectives:
1. Root with the ability to hide root so other apps will work
2. Native Mobile Hotspot
3. The ability to easily receive android updates without having to reflash etc..
4. Stay close to stock if possible, but willing to explore other options as long as security is trusted, and has good
compatibility.
5. Security is a concern, I tried a rom in the past with a Galaxy S4 and swear it had a backdoor installed in the rom.
What do you guys recommend? And how do I go about doing it?
Thank you!
If security is truly a concern you will not unlock your bootloader and root your phone.
Otherwise it all depends on which version phone you have, Verizon or Google?
1. You need magisk root for that.
3. No updates when you are rooted
4.5. Never heard of any custom rom with a backdoor. That's absolutely bull****. More likely it was an app you installed.
Unlocked bootloader is a security issue, so better to stay on full stock.
Root is a big security issue so better stay on full stock.
Jokes aside the only security issue is your phone gets stolen or you install apps outside playstore.
If you stay encrypted and use a hard pattern with fingerprint you are fine and there is always the way to delete your phone when it gets stolen.
mikaole said:
1. You need magisk root for that.
3. No updates when you are rooted
4.5. Never heard of any custom rom with a backdoor. That's absolutely bull****. More likely it was an app you installed.
Unlocked bootloader is a security issue, so better to stay on full stock.
Root is a big security issue so better stay on full stock.
I have the Pixel XL - Google Version
Jokes aside the only security issue is your phone gets stolen or you install apps outside playstore.
If you stay encrypted and use a hard pattern with fingerprint you are fine and there is always the way to delete your phone when it gets stolen.
Click to expand...
Click to collapse
My point about security really was that it's quite possible a ROM could have a backdoor. That a side..
Root is not a big security issue for me as long as the rom is trusted etc..
Shouldn't I be able to turn root off then be able to update and turn it back on again?
jadensmith said:
1. Root with the ability to hide root so other apps will work
Click to expand...
Click to collapse
It's possible to root to one slot with SuperSU while the other slot remains unrooted, and then the phone can be switched between slots with TWRP or fastboot commands. Kernels have been posted with safetynet patches, to hide that the bootloader is unlocked, but I'm not sure if any are available with the software version on my phone's current slot. As noted, Magisk can also hide root and that the bootloader is unlocked, so it's probably less hassle than trying to root and hide using SuperSU.
3. The ability to easily receive android updates without having to reflash etc.
Click to expand...
Click to collapse
FlashFire can use the OTA to update and stay rooted with SuperSU. The past couple months I've used FlashFire to update my phone, and it seems quicker and easier than the sideloading and reinstalling process I had been using. I'm not aware of anything similar to FlashFire for Magisk users, so to me it seems like you would have to decide if 1 or 3 is more personally important.
jadensmith said:
Shouldn't I be able to turn root off then be able to update and turn it back on again?
Click to expand...
Click to collapse
While reading I got the impression that I might be able to uninstall SuperSU and use the OTA update, but that didn't work with SuperSU the times I tried it, so I presume something SuperSU changed or something I did with root must have caused the update to fail. I haven't read the Magisk threads as much, yet I've seen that other SuperSU users also indicate that OTA updates no longer worked for them after rooting the phone.
alluringreality said:
It's possible to root to one slot with SuperSU while the other slot remains unrooted, and then the phone can be switched between slots with TWRP or fastboot commands. Kernels have been posted with safetynet patches, to hide that the bootloader is unlocked, but I'm not sure if any are available with the software version on my phone's current slot. As noted, Magisk can also hide root and that the bootloader is unlocked, so it's probably less hassle than trying to root and hide using SuperSU.
FlashFire can use the OTA to update and stay rooted with SuperSU. The past couple months I've used FlashFire to update my phone, and it seems quicker and easier than the sideloading and reinstalling process I had been using. I'm not aware of anything similar to FlashFire for Magisk users, so to me it seems like you would have to decide if 1 or 3 is more personally important.
That didn't work with SuperSU the times I tried it, so I presumed that something I did with root must have caused the update to fail to install.
Click to expand...
Click to collapse
Wow thanks for the great reply! It's so refreshing!
What do you mean by root one slot?
The phone has two "slots" for Android. The basic idea is that you have two copies of Android on the phone that share the same user data. On a stock phone it's intended to allow for less noticeable updates, and it also can allow the phone to fall back to the previous software version if something goes wrong with an update. On the May update my phone did automatically switch between slots, due to what is discussed in the second link below. The first link below gives some information and additional links to discussion about the slots on these phones.
http://www.androidpolice.com/2016/1...-partition-changes-and-new-fastboot-commands/
https://forum.xda-developers.com/an...signing-boot-images-android-verified-t3600606
Is it possible to keep stock or near stock and just have root with the ability to hide root, and hotspot?
That's all I really need. What would be the best way to to do this?

Unlock, Root, Xposed and then relock

Hi, my Mix2 arrived few days ago and I find MiUI quite nice, yet lacking few things. Those are easily available via xposed, hence I need to root. I'm also not so lucky in these matters so before I start to tinker with it I'd like to learn few things.
What are least dangerous ways to unlock and root phone? (heard sth about magisk, its quite new for me, haven't been rooting phones for couple years now) Is it good?
Suppose I succeed unlocking, rooting and flashing xposed, can I relock bootloader? I want that because ie AndroidPay needs that to work, and I haven't found any working rootcloack or similar (at least on Note2)
How reliable is 'the most official tool' for xiaomi flashing (from eu.xiaomi.com ?)? I mean can it bring back the dead or revert phone back to where I started, without any trace of tinkering?
As a new xiaomi owner are there any critical things I need to know?
Thanks!
If you flash magisk, which is the best thing ever btw, you won't have to relock bootloader to get Android pay working.
yeyeoke said:
If you flash magisk, which is the best thing ever btw, you won't have to relock bootloader to get Android pay working.
Click to expand...
Click to collapse
Thanks, I read about that and intend to use it. Though, there might be some issues with magisk and different versions. What features does it have?
So far, need to wait 3 days to unlock bootloader.
Mighty_Ahti said:
Thanks, I read about that and intend to use it. Though, there might be some issues with magisk and different versions.
So far, need to wait 3 days to unlock bootloader.
Click to expand...
Click to collapse
I've been using magisk on my Note 3 Pro since release and I've never had an issue. Yes, I got my mix 2 today and I'm also waiting for 3 days..
Mighty_Ahti said:
Hi, my Mix2 arrived few days ago and I find MiUI quite nice, yet lacking few things. Those are easily available via xposed, hence I need to root. I'm also not so lucky in these matters so before I start to tinker with it I'd like to learn few things.
What are least dangerous ways to unlock and root phone? (heard sth about magisk, its quite new for me, haven't been rooting phones for couple years now) Is it good?
Suppose I succeed unlocking, rooting and flashing xposed, can I relock bootloader? I want that because ie AndroidPay needs that to work, and I haven't found any working rootcloack or similar (at least on Note2)
How reliable is 'the most official tool' for xiaomi flashing (from eu.xiaomi.com ?)? I mean can it bring back the dead or revert phone back to where I started, without any trace of tinkering?
As a new xiaomi owner are there any critical things I need to know?
Thanks!
Click to expand...
Click to collapse
It's generally considered to be dangerous to relock a bootloader with anything other than perfectly stock/factory firmware installed. It may be ok to do this technically but it sort of "ties your hands" in some ways after making an unofficial modification and makes it a bit harder to recover from a botched situation.
You can have an unlocked bootloader and still use Android Pay. This can be achieved either with a ROM that is built to accomplish this (Epic ROM is an example of this) or by using Magisk, which allows root without any sort of SafetyNet trip in many cases. I don't believe there's *any* way to install Xposed and also use Android Pay or any other SafetyNet apps...the best alternative if you really want Xposed is to use Magisk and then install the Xposed Magisk module...you still can't pass SafetyNet with this setup but Magisk allows you to disable Xposed if you're willing to uncheck it in the Magisk Manager app and reboot the phone, after which time SafetyNet should pass ok...at least with this setup you'll be able to kind of have your cake and eat it too, though it's not ideal as you'll have to reboot if you want to change the status of Xposed.
https://forum.xda-developers.com/xposed/unofficial-systemless-xposed-t3388268
Thank you for detailed answer. I didn't know that.
flyer_andy said:
the best alternative if you really want Xposed is to use Magisk and then install the Xposed Magisk module...you still can't pass SafetyNet with this setup but Magisk allows you to disable Xposed
Click to expand...
Click to collapse
I tried AndroidPay few times past few days and it didn't work at all. Perhaps terminals were not compatibile. So lets say I gave up on AndroidPay - can I use regular Xposed along with Magisk? Or does it have to be that module?
Mighty_Ahti said:
Thank you for detailed answer. I didn't know that.
I tried AndroidPay few times past few days and it didn't work at all. Perhaps terminals were not compatibile. So lets say I gave up on AndroidPay - can I use regular Xposed along with Magisk? Or does it have to be that module?
Click to expand...
Click to collapse
Oh! I think I may be able to help you with the Android Pay issue - my phone didn't work right with Android Pay until I made sure *all* Google apps' permissions were allowed via the Apps menu in Settings (along with "Autostart" via the security app)...and also toggled the NFC setting where it lets you select between "embedded secure element" and "HCE Wallet." It probably is on "HCE Wallet" but try toggling to "embedded secure element" and then back to "HCE Wallet" a couple of times. My Mix 2 would not make a terminal connection until I did this...it would just say "card read error." Seems like a firmware bug. Let me know if that helps!
But yeah if you don't want to use Android Pay then normal Xposed should be fine...you wouldn't need Magisk I don't think. Though, I'm not sure but I think the Magisk Xposed module probably functions the same as normal Xposed so I'm not sure there's an advantage in doing so. But of course it's all about personal preference!
Whoah, I'm still new to xiaomi/android7+ policies, where each app's permissions are reduced to bare minimum (messenger not being able to show notifications for example). I will definitely try this tomorrow.
So far I just managed to unlock BL, flash recovery and install magisk. SafetyNet checks ok. Will try xposed tomorrow after some payments ;D Thanks!
HCE wallet worked for me (I had it set to SIM wallet).
If I understand correctly here is the possible solution to xposed+magisk+androidPay.
I'd need phh's su binaries for that and keep crossing fingers for it to work on 7.1
I need to learn more about that stuff before I break something
So as I was expecting I experience troubles in installing Xposed.
I followed official way as in here And got bootloop.
I removed magisk stuff in recovery and fixed bootloop, then installed v89.0 (not .1) and also bootloop.
Im using SDK25, and miui 9 - 7.1.1 so it should be ok I think
Mighty_Ahti said:
So as I was expecting I experience troubles in installing Xposed.
I followed official way as in here And got bootloop.
I removed magisk stuff in recovery and fixed bootloop, then installed v89.0 (not .1) and also bootloop.
Im using SDK25, and miui 9 - 7.1.1 so it should be ok I think
Click to expand...
Click to collapse
Disable hooks from the xposed apps settings before flashing xposed
What hooks? I dont have any modules yet
Mighty_Ahti said:
What hooks? I dont have any modules yet
Click to expand...
Click to collapse
It's a toggle in the settings under experimental, disable resource hooks
Boot took longer but it works. Thanks! Do I have to keep it on all the time ?
Mighty_Ahti said:
Boot took longer but it works. Thanks! Do I have to keep it on all the time ?
Click to expand...
Click to collapse
Yeah, phone won't boot with it on. Don't think it makes much difference anyway
Hi @Mighty_Ahti, how much time was "longer"? it's been loading for over 5 minutes already. Thanks
Certainly below 5 minutes.

ok so updates...

Thought I read we getting a final December update.
We are, according to Google.
As for custom ROMs after the fact, most of the Android 11 versions seem to not want to include Active Edge support because it's proprietary. This is despite Active Edge functions being reverse engineered (which is, if I recall, totally legal). While a bit of a bummer, I'll have to get used to it: the 2020 Pixel models don't have Active Edge at all.
That happened rather silently, I was kind of expecting some sort of notification. Guess now I need to work out how to put a custom ROM on this thing so I get security updates, without disclosing its rooted thus breaking all my banking apps. Hopefully that's still an option, haven't rooted in years...
TheRealWhoop said:
That happened rather silently, I was kind of expecting some sort of notification. Guess now I need to work out how to put a custom ROM on this thing so I get security updates, without disclosing its rooted thus breaking all my banking apps. Hopefully that's still an option, haven't rooted in years...
Click to expand...
Click to collapse
Heres the basics of the steps forward
Going forwards only fastboot TWRP, do not install it
Backup your loved stuff on internal storage
1) unlock bootloader (instructions here)
2) reboot bootloader (at command prompt with platform tools installed: adb reboot bootloader)
3) at command prompt: fastboot boot twrp-xxxx.img
TWRP:
Walleye (Pixel 2)
Taimen (Pixel 2XL)
You want to download the latst .img file
4) wipe/factory reset accordign to ROM instructions and flash ROM (& G-Apps if needed - depending on ROM) and setup
5) reboot to bootloader adb reboot bootloader
6) fastboot twrp again fastboot boot twrp-xxxx.img
7) flash magisk (then enable MagiskHide in Magisk Manager - good enough for *most* banks - otherwise hide Magisk Manager itself, or other specific help in Magisk threads)
8) if need be (depending on ROM, some pass Safetynet out of box) use Magiskhide Props Config also in the magisk repo, to pass safetynet
9) if using Google Pay, theres a magisk module for that that i maintain. its NOT in the magisk repo (dont ask why)
TheRealWhoop said:
Guess now I need to work out how to put a custom ROM on this thing so I get security updates, without disclosing its rooted thus breaking all my banking apps.
Click to expand...
Click to collapse
You do know that installing a custom ROM doesn't require root? You simply need to unlock the bootloader, if you're not using a Verizon device that is.
Strephon Alkhalikoi said:
You do know that installing a custom ROM doesn't require root? You simply need to unlock the bootloader, if you're not using a Verizon device that is.
Click to expand...
Click to collapse
To pass safetynet and for banking (depending on the ROM), will probably need root....
Strephon Alkhalikoi said:
You do know that installing a custom ROM doesn't require root? You simply need to unlock the bootloader, if you're not using a Verizon device that is.
Click to expand...
Click to collapse
I did, long ago, but forgot Thanks for the reminder. Although as 73sydney says, sounds like I'm going to need root to get Google Pay and banking apps etc working.
TheRealWhoop said:
I did, long ago, but forgot Thanks for the reminder. Although as 73sydney says, sounds like I'm going to need root to get Google Pay and banking apps etc working.
Click to expand...
Click to collapse
I did say depending on the ROM, some ROM's will pass safetynet out of the box, others not so much
73sydney said:
I did say depending on the ROM, some ROM's will pass safetynet out of the box, others not so much
Click to expand...
Click to collapse
Interesting, was unaware of that, is this dependant on whether its a fork of the stock ROM or not? I was considering LineageOS, so presumably need the full works there.
TheRealWhoop said:
Interesting, was unaware of that, is this dependant on whether its a fork of the stock ROM or not? I was considering LineageOS, so presumably need the full works there.
Click to expand...
Click to collapse
HentaiOS, EvoX, ProtonAOSP.. all are rocking the safetynet hurdle in A11, LOS 17.1 for A10. All is not gloomy for Taimen for now atleast. However hardware-wise my device is showing its age - getting warmed up to IM apps and casual browsing , be it A10 or A11.
getting backl into custom ROMs now that the P2XL support is coming to an end - which ROMs are the most stable, most quick to be updated to the monthly security patch, and most stock-like update process (OTA-style ideally)?
2x4 said:
getting backl into custom ROMs now that the P2XL support is coming to an end - which ROMs are the most stable, most quick to be updated to the monthly security patch, and most stock-like update process (OTA-style ideally)?
Click to expand...
Click to collapse
LineageOS.

Question : widevine, mcdonalds, banking app and root?

Hello!
I will receive a oneplus 9 pro next week and wonder if i shall root it or not. I want to use titanium backup and a few other apps that need root permission, but i also dont want to loose widevine level 1 for netflix and amazon video in hd, want to use my banking app and mcdonalds app.
i havent followed the magisk/root discussion for maybe a year or two (used a unrooted stock phone), so i am not up to date how things are at the moment.
just to be clear, please can someone answer the following questions:
1.) is unlocking bootloader (no root afterwards) enough to loose widevine level 1? can level 1 be gained again when bootloader is locked again or is lost permanent (like triggering knox with samsung).
2.) any problems with mcdonalds app and magisk? google pay?
after reading to the internet on the subject totday, i get the impression that rooting nowadays causes more problems thn benefits, but maybe i get a wrong impression.
flotsch1 said:
Hello!
I will receive a oneplus 9 pro next week and wonder if i shall root it or not. I want to use titanium backup and a few other apps that need root permission, but i also dont want to loose widevine level 1 for netflix and amazon video in hd, want to use my banking app and mcdonalds app.
i havent followed the magisk/root discussion for maybe a year or two (used a unrooted stock phone), so i am not up to date how things are at the moment.
just to be clear, please can someone answer the following questions:
1.) is unlocking bootloader (no root afterwards) enough to loose widevine level 1? can level 1 be gained again when bootloader is locked again or is lost permanent (like triggering knox with samsung).
2.) any problems with mcdonalds app and magisk? google pay?
after reading to the internet on the subject totday, i get the impression that rooting nowadays causes more problems thn benefits, but maybe i get a wrong impression.
Click to expand...
Click to collapse
Use the canary builds of Magisk, enable MagiskHide, and toggle the apps in question, and you're golden. Also, just to be sure, toggle it on for Google stuff like the Google app, Google Play Store, Google Play Services, Google Services Framework, Netflix, McDonald's, GPay, and any other banking or streaming subscription apps. Might want to have Magisk hide its self by changing the app name and signature as well.
GuyInDogSuit said:
Use the canary builds of Magisk, enable MagiskHide, and toggle the apps in question, and you're golden. Also, just to be sure, toggle it on for Google stuff like the Google app, Google Play Store, Google Play Services, Google Services Framework, Netflix, McDonald's, GPay, and any other banking or streaming subscription apps. Might want to have Magisk hide its self by changing the app name and signature as well.
Click to expand...
Click to collapse
thank you for the information.
so i will definitely not loose widevine l1 with unlocking bootloader and root?
to hide magisk itself (change name and signature), i just need to turn this option on in magisk and not need to do this in a manual way?
flotsch1 said:
thank you for the information.
so i will definitely not loose widevine l1 with unlocking bootloader and root?
to hide magisk itself (change name and signature), i just need to turn this option on in magisk and not need to do this in a manual way?
Click to expand...
Click to collapse
Correct, by default it will change to a "default" app icon and rename itself to "Settings" but you can easily still tell it from the device's own system Settings app.
one last question.
following this root instruction https://forum.xda-developers.com/t/guide-magisk-unlock-root-keep-root-oos-11-2-7-7.4252373/ , do i have to use the provided boot images? i feel safer to download the full ota from oneplus official site and extract payload.bin and then use payload dumper to get a boot.img.
flotsch1 said:
one last question.
following this root instruction https://forum.xda-developers.com/t/guide-magisk-unlock-root-keep-root-oos-11-2-7-7.4252373/ , do i have to use the provided boot images? i feel safer to download the full ota from oneplus official site and extract payload.bin and then use payload dumper to get a boot.img.
Click to expand...
Click to collapse
If you are leery of using someone else's boot.img, feel free to do that if you'd like. But regardless, be sure to boot the image, don't flash it. Booting it not only gives you the temporary root access to install Magisk yourself, but also ensures that the patched boot.img is actually valid.
v23 has a fix for SafetyNet API. It looks like that supersedes anything from the last canary/debug builds, so it's probably safe to stick with that. Everything else is the same, though.
GuyInDogSuit said:
v23 has a fix for SafetyNet API. It looks like that supersedes anything from the last canary/debug builds, so it's probably safe to stick with that. Everything else is the same, though.
Click to expand...
Click to collapse
V23?
flotsch1 said:
V23?
Click to expand...
Click to collapse
Latest stable Magisk build. I'm saying you won't need to mess with canary/debug.
When you turn on hide then hide the app the in the settings then your allowed to do anything you like but also hide it in the menu of magisk then your all done don't flash to much crap and magisk hide module is not really finished yet for this device good luck
I rooted it the second i got it
And don't use canary builds of magisk only if you want to run your phone very unstable i recommend the stable version
thanks alot for the information.
i still hazzle to root. i had a oneplus 3 2 years ago and had magisk root/custom rom/twrp, but i also had issues on regular basis and spent alot of time on xda and with flashing. dont know if i want this again or just a phone that works.
and just to be sure:
in case i loose my widevine level 1 because of root or bootloader unlock: will it come back when locking bootloader again and/or unroot. or will it be level 3 forever?
Wildvine L1 is not always retained when unlocking the bootloader. If I unlock mine, I go to L3 every single time, but when I lock it back, I go back to L1. I've tested this 3 times and it happened all 3 times.
flotsch1 said:
thanks alot for the information.
i still hazzle to root. i had a oneplus 3 2 years ago and had magisk root/custom rom/twrp, but i also had issues on regular basis and spent alot of time on xda and with flashing. dont know if i want this again or just a phone that works.
and just to be sure:
in case i loose my widevine level 1 because of root or bootloader unlock: will it come back when locking bootloader again and/or unroot. or will it be level 3 forever?
Click to expand...
Click to collapse
Well to be honest I never had that problem and i need to have my binance hidden as well and everything works well but with some games like slime hunter i really need to hide magisk it self too from the settings but when you do they everything will be working okay. And so far I have seen with magisk hide module what you can download is that there are no keys yet for using in op9p (could be changed didn't check it for a while now)

CTS profile match failed

Hi there.
I have an unrooted realme 6 pro. 2 days ago I tried to use Google pay and it did not work. It said that "You can´t pay contactless using this device. It may be rooted or running uncertified software.
I went to google play and I saw that my device is certified. After running some SafetyNet checks it says that CTS profile match failed. evakuation type: BASIC HARDWARE_BACKED. And then after reading some blogs I saw that on Google Play my netflix isn´t supported on my device although I have already installed it.
Any help or advice?
Thanks
Is your bootloader unlocked?
There's only 2 reliable ways to pass SafetyNet including CTS. The first is a completely stock device running pure OEM firmware with a locked bootloader.
The second is with Magisk, using DenyList and 2 modules: Universal SafetyNet Fix and MagiskHide Props Config.
A stock ROM on an unlocked bootloader will fail.
A custom ROM on a locked bootloader will fail.
V0latyle said:
Is your bootloader unlocked?
There's only 2 reliable ways to pass SafetyNet including CTS. The first is a completely stock device running pure OEM firmware with a locked bootloader.
The second is with Magisk, using DenyList and 2 modules: Universal SafetyNet Fix and MagiskHide Props Config.
A stock ROM on an unlocked bootloader will fail.
A custom ROM on a locked bootloader will fail.
Click to expand...
Click to collapse
I have also checked that. It has always been locked. I do not know if the problem is caused due to the new android update since is now running on android 11. Plus I dont want to root my phone
V0latyle said:
Is your bootloader unlocked?
There's only 2 reliable ways to pass SafetyNet including CTS. The first is a completely stock device running pure OEM firmware with a locked bootloader.
The second is with Magisk, using DenyList and 2 modules: Universal SafetyNet Fix and MagiskHide Props Config.
A stock ROM on an unlocked bootloader will fail.
A custom ROM on a locked bootloader will fail.
Click to expand...
Click to collapse
... You cannot have custom rom on unlocked bootloader LOL. Just saying. Unless a device is ancient, back in the days where you could run custom roms without unlocked bootloader.
JhinCuatro said:
... You cannot have custom rom on unlocked bootloader LOL. Just saying. Unless a device is ancient, back in the days where you could run custom roms without unlocked bootloader.
Click to expand...
Click to collapse
But that's the thing. I don't have a custom from. I did not root my phone. The only thing I did is to open the developer options. The bootloader was always locked. That started happening after the update to android 11. I sent my phone to the customer service now but I do not think they will do anything.
JhinCuatro said:
... You cannot have custom rom on unlocked bootloader LOL. Just saying. Unless a device is ancient, back in the days where you could run custom roms without unlocked bootloader.
Click to expand...
Click to collapse
You can, you just have to set a custom root of trust. See Android Boot Flow
V0latyle said:
You can, you just have to set a custom root of trust. See Android Boot Flow
Click to expand...
Click to collapse
Oops I misstated. I meant custom rom on locked bootloader**.
manu3732 said:
But that's the thing. I don't have a custom from. I did not root my phone. The only thing I did is to open the developer options. The bootloader was always locked. That started happening after the update to android 11. I sent my phone to the customer service now but I do not think they will do anything.
Click to expand...
Click to collapse
Same problem with my OnePlus Nord.
oOEDGUYOo said:
Same problem with my OnePlus Nord.
Click to expand...
Click to collapse
Did you find any fix yet... Am having the same issue
happy619 said:
Did you find any fix yet... Am having the same issue
Click to expand...
Click to collapse
I ended up installing the Pixel Experience rom. It was the only way to fix it
oOEDGUYOo said:
I ended up installing the Pixel Experience rom. It was the only way to fix it
Click to expand...
Click to collapse
I have been on custom ROMs for over 6 months on nord ... Some have bad update cycles .. Some are unstable and many more issues although my Device was certified
I have the same problem, bootloader is normally unlocked and I have Universal SafetyNet Fix and MagiskHide Props Config installed, using lineage 18.1 on my redmi 9 pro device
I have flashed both ...( Magisk hide prop conf & universal safety net )
But still "CTS failed, can somebody help me please....
I have this problem too. Any solutions ? I tried magisk with prop conf and safety net-fix and still have cts failed...
Finally success
of course magisk with deny list setup and the rest
1. remove universal safety fix
2. reboot
3. install displax fork mod 3.0 here
4. reboot
5. clear cache from google wallet
The rest ? What you mean ? Cause i have problem with CTS failed and im desperatly looking for solution
Oshvitzon said:
Finally success
of course magisk with deny list setup and the rest
1. remove universal safety fix
2. reboot
3. install displax fork mod 3.0 here
4. reboot
5. clear cache from google wallet
Click to expand...
Click to collapse
The rest ? What you mean ? Cause i have problem with CTS failed and im desperatly looking for solution
Mrlama112 said:
The rest ? What you mean ? Cause i have problem with CTS failed and im desperatly looking for solution
Click to expand...
Click to collapse
The regular instructions:
Magisk with zygisk , hide app , configure deny list and then as i said in the previous post
Oshvitzon said:
Finally success
of course magisk with deny list setup and the rest
1. remove universal safety fix
2. reboot
3. install displax fork mod 3.0 here
4. reboot
5. clear cache from google wallet
Click to expand...
Click to collapse
Thank you! Worked like a charm! IDK why my CTS Profile suddenly started failing, but this seemed to have fixed it.
Oshvitzon said:
Finally success
of course magisk with deny list setup and the rest
1. remove universal safety fix
2. reboot
3. install displax fork mod 3.0 here
4. reboot
5. clear cache from google wallet
Click to expand...
Click to collapse
Thanks so much it worked well. Am I able to update the Google Wallet without it affecting the mod 3.0?

Categories

Resources