Apps deliberately refusing to work on modded devices
Apps running on Android and potentially other operating systems (OS) can detect if the device has been modded and refuse to function if that is the case. This can happen if the device allows the user to run applications as root or administrator, has an unlocked bootloader or runs a different OS than the one provided by the manufacturer.[1][2]
Effective March 1st 2026, all banking apps in Vietnam must detect whether the app is running on a device that has an unlocked bootloader, is rooted or has ADB enabled and cease to function if that is the case [3]
How it works
[edit | edit source]Some phones and PCs include a Trusted Platform Module [4]: a chip independent from the device's CPU which can only run software signed by the device manufacturer. This chip allows applications to use a technique called remote attestation to detect if the operating system has been tampered with, and if so will block functionality or refuse to work altogether. If done properly, remote attestation is impossible to spoof, even by the owner of the device.
Why it is a problem
[edit | edit source]The owner of the phone is unable to do the following (while continuing to use applications that block modded devices)
- update the device operating system once it is no longer supported by the device manufacturer
- use alternative operating systems such as Linux or other Android-based operating systems that add new features
- remove all bloatware
- access all data stored on the device
Since many businesses and governments require their customers to download their proprietary application to their phones in order to use their services (see Forced app download), and many of those applications refuse to work on a modded device, people are left unable to modify their phone as they wish, as they then couldn't interact with those businesses which require or heavily encourage their app.
Enforcement of Google's power over the Android Open-Source Project
[edit | edit source]Although Android is an open-source project, these measures effectively prevent the use of Android as such. In order for device manufacturers to ship Google Play, pass Play Integrity checks, and not have their devices be treated as modded by these apps, they must work with Google and follow their requirements to obtain certification and licensing. In 2018, the European Commission found that Google illegally misused this power to force manufacturers into bundling other Google apps and services.[5]
This affects Linux phones that can otherwise run Android apps normally in Android containers,[6][7] as they are not certified by Google, and likely would not be for competing with Google's ecosystem.
Examples
[edit | edit source]Android
[edit | edit source]- Main article: Google Play Integrity API
- Google Wallet
- VPN by Google for Pixel
- Netflix
- McDonald's App
- Google Messages (RCS does not work when device is modded)
- Uber Driver
- X Corp
- Twilio Authy Authenticator
- ChatGPT[8][9]
References
[edit | edit source]- ↑ "Apps & Games need PI". XDA Forums. Archived from the original on 22 Feb 2026.
- ↑ "Configure API responses". Google. Archived from the original on 4 Feb 2026.
- ↑ "[Discussion] The root-and-mod-hiding / fingerprint-spoofing / keybox-stealing cat-and-mouse game". Archived from the original on 29 Jan 2026.
- ↑ "Trusted Platform Module". Archived from the original on 3 Aug 2016.
- ↑ "Antitrust: Commission fines Google €4.34 billion for illegal practices regarding Android mobile devices to strengthen dominance of Google's search engine". 2018-07-18. Archived from the original on 2026-07-15.
- ↑ "PinePhone and Bank authentication apps". 2023-04-20. Archived from the original on 2026-07-18.
- ↑ "Android App Containers". 2024-08-30. Archived from the original on 2026-02-11.
- ↑ "PlayIntegrity Verification failed - ChatGPT / Bugs". OpenAI Developer Community. Archived from the original on 23 Feb 2026.
- ↑ "Question - ChatGPT error: Preauth Playintegrity verification failed". XDA Forums. Archived from the original on 23 Feb 2026.