Question MEETS_DEVICE_INTEGRITY fails after Feb update - Google Pixel 7

For anybody with unlocked bootloaders and root no longer passing the usual 2 out of 3 Play Integrity checks, maybe this helps.
After flashing yesterday's TQ1A.230205.002 update, MEETS_DEVICE_INTEGRITY consistently failed which was something new. Sometimes it would pass after repeated attempts and/or clearing the app's storage, but mostly it failed. Long story short, it's now passing after 1) switching from safetynet-fix 2.40 back to Displax's modified 2.3.1; and 2) uninstalled and reinstalled the Integrity Check app. Either one, the other or both seems to have helped. Occasionally I'll get a fail but it's mostly passing now instead of the other way around.

manjaroid said:
For anybody with unlocked bootloaders and root no longer passing the usual 2 out of 3 Play Integrity checks, maybe this helps.
After flashing yesterday's TQ1A.230205.002 update, MEETS_DEVICE_INTEGRITY consistently failed which was something new. Sometimes it would pass after repeated attempts and/or clearing the app's storage, but mostly it failed. Long story short, it's now passing after 1) switching from safetynet-fix 2.40 back to Displax's modified 2.3.1; and 2) uninstalled and reinstalled the Integrity Check app. Either one, the other or both seems to have helped. Occasionally I'll get a fail but it's mostly passing now instead of the other way around.
Click to expand...
Click to collapse
Yeah, a lot of people are having issues with USNF 2.4.0.

manjaroid said:
For anybody with unlocked bootloaders and root no longer passing the usual 2 out of 3 Play Integrity checks, maybe this helps.
After flashing yesterday's TQ1A.230205.002 update, MEETS_DEVICE_INTEGRITY consistently failed which was something new. Sometimes it would pass after repeated attempts and/or clearing the app's storage, but mostly it failed. Long story short, it's now passing after 1) switching from safetynet-fix 2.40 back to Displax's modified 2.3.1; and 2) uninstalled and reinstalled the Integrity Check app. Either one, the other or both seems to have helped. Occasionally I'll get a fail but it's mostly passing now instead of the other way around.
Click to expand...
Click to collapse
Hi,
may I ask exactly which version you went back to:
- v2.3.1-MOD_2.1
- v2.3.1-MOD_2.0 or
- v2.3.1-MOD
Greetings

jofa news said:
Hi,
may I ask exactly which version you went back to:
- v2.3.1-MOD_2.1
- v2.3.1-MOD_2.0 or
- v2.3.1-MOD
Greetings
Click to expand...
Click to collapse
I went back to 2.3.1-MOD_2.0 since it was already on the phone. I didn't even know about MOD_2.1 until you mentioned it, so that's what I'll do next. I didn't know about 2.4.0 problems either. I guess I need to get out more often, subscribe to an extra forum or two.

i had the same proplem
buy aftel clear data and cash memory about 3 times for google service and google play store and last google wallet , evrey think get bake norml

manjaroid said:
I went back to 2.3.1-MOD_2.0 since it was already on the phone. I didn't even know about MOD_2.1 until you mentioned it, so that's what I'll do next. I didn't know about 2.4.0 problems either. I guess I need to get out more often, subscribe to an extra forum or two.
Click to expand...
Click to collapse
I have read about the problems with USNF 2.4 here
MAGISK MODULE ❯ Universal SafetyNet Fix 2.4.0

salamdiab said:
i had the same proplem
buy aftel clear data and cash memory about 3 times for google service and google play store and last google wallet , evrey think get bake norml
Click to expand...
Click to collapse
Did you reboot the phone after clearing it? I've been wiping it a few time but it still not seemed to work.

seanho12345 said:
Did you reboot the phone after clearing it? I've been wiping it a few time but it still not seemed to work.
Click to expand...
Click to collapse
this morrning evrey thing not work
i try a lot of thing but no help

All seemed fine yesterday after installing safetynet-fix-v2.3.1-MOD_2.1 but it's a bigger mess today. Unlike yesterday, Safetynet CTS profile fails and Play Protect shows device not certified. I even managed to get an API throttle error from the Integrity Check app, which presumably means I'm SOL for a while.
More gory details...
MAGISK MODULE ❯ Universal SafetyNet Fix 2.4.0
Universal SafetyNet Fix Magisk module Magisk module to work around Google's SafetyNet attestation. This module works around hardware attestation and recent updates to SafetyNet CTS profile checks. You must already be able to pass basic CTS...
forum.xda-developers.com

Hiding the Magisk app solves the issue. Just hide then reboot phone. Profit.

Thanks to @Displax everything passes with safetynet-fix 2.3.1-MOD_3.0.
Release v2.3.1-MOD_3.0 · Displax/safetynet-fix
Google SafetyNet attestation workarounds for Magisk - Release v2.3.1-MOD_3.0 · Displax/safetynet-fix
github.com

manjaroid said:
Thanks to @Displax everything passes with safetynet-fix 2.3.1-MOD_3.0.
Release v2.3.1-MOD_3.0 · Displax/safetynet-fix
Google SafetyNet attestation workarounds for Magisk - Release v2.3.1-MOD_3.0 · Displax/safetynet-fix
github.com
Click to expand...
Click to collapse
Thanks, its working

Magisk hidden, Zygisk enabled, safetynet-fix 2.3.1-MOD_3.0 installed
Force stop, clear cache and storage for Google Play Services, Play Store and Wallet, reboot.
Repeat 4 times
Still Play Integrity API Checker shows red cross for MEETS_DEVICE_INTEGRITY
EDIT:
Uninstall USNF, reboot, check with Integrity API Checker - got 3 red crosses, predictable.
Reinstall USNF, reboot - MEETS_DEVICE_INTEGRITY is red

BesoC said:
Magisk hidden, Zygisk enabled, safetynet-fix 2.3.1-MOD_3.0 installed
Click to expand...
Click to collapse
Is Enforce DenyList enabled and DenyList configured?

manjaroid said:
Is Enforce DenyList enabled and DenyList configured?
Click to expand...
Click to collapse
DenyList is enforced, There are Google Play Store and Wallet in DenyList

BesoC said:
DenyList is enforced, There are Google Play Store and Wallet in DenyList
Click to expand...
Click to collapse
Try clearing storage for the Integrity Check app or uninstall and reinstall it. Avoid checking too often also, the app gave me an error about limits and throttling when problems were ongoing a couple days ago. Sorry, I don't have any other ideas.

manjaroid said:
Try clearing storage for the Integrity Check app or uninstall and reinstall it. Avoid checking too often also, the app gave me an error about limits and throttling when problems were ongoing a couple days ago. Sorry, I don't have any other ideas.
Click to expand...
Click to collapse
Still not working, but thanks for your efforts

BesoC said:
Still not working, but thanks for your efforts
Click to expand...
Click to collapse
Whats working on pixel 7 pro for me
SafetyNet displax mod 3.0
Shamiko module
Magisk hide
All Google apps hidden in deny list
Deny list enforced disabled
Clear cache from wallet and playstore
Reboot

Bxperiaz3 said:
Whats working on pixel 7 pro for me
SafetyNet displax mod 3.0
Shamiko module
Magisk hide
All Google apps hidden in deny list
Deny list enforced disabled
Clear cache from wallet and playstore
Reboot
Click to expand...
Click to collapse
Thank you for your advise. Did exactly as you wrote, still MEETS_DEVICE_INTEGRITY is red

BesoC said:
Thank you for your advise. Did exactly as you wrote, still MEETS_DEVICE_INTEGRITY is red
Click to expand...
Click to collapse
Maybe try the new USNF mod Displax just put out...
v2.4.0-MOD_1.0

Related

Local bus company crashes with magisk

Hi all,
My local bus company uses an app to buy ticket and stocks it in the phone.
When you enter in the bus, it uses nfc to validate your ticket
But the app doesn't work with rooted Phone. It crashes each times.
I installed magisk hide
Magisk is hidden in the settings
And the app is listed in the app hidden
But it still crashes.
Do you have an idea to solve it ?
My phone is a Poco F2 Pro and here the app https://play.google.com/store/apps/details?id=eu.mobeepass.ticketeasy
Thx
Trying using Riru with the latest Safetynet Fix and Exposed hiding tracking for Play Services and the app in question. Should do it. If the app has banned your device id, generate a new one using one of the tools out there (most likely it has no though, so should be good). If you install Riru - Install LSPosed - run latest Safetynet Fix - Add Play services and your apps, there is a big chance the app will pass.
Andrologic said:
Trying using Riru with the latest Safetynet Fix and Exposed hiding tracking for Play Services and the app in question. Should do it. If the app has banned your device id, generate a new one using one of the tools out there (most likely it has no though, so should be good). If you install Riru - Install LSPosed - run latest Safetynet Fix - Add Play services and your apps, there is a big chance the app will pass.
Click to expand...
Click to collapse
Is it this module ?
twingo_man said:
Is it this module ?
Click to expand...
Click to collapse
No, there should be a stand-alone Riru module just called Riru. That's the first component. You'll need a couple more things to pass the latest Safetynet and fully hiding some of the toughest apps.
This is one of the best guides I have seen (credits to the author who put it together):
[2023 FIX] Fix Magisk CTS Profile False Error - Bypass Safetynet
Magisk CTS Profile False Error is now popping up on almost everyone's device since Google made some changes in March. To Bypass Safetynet...
droidholic.com
Andrologic said:
No, there should be a stand-alone Riru module just called Riru. That's the first component. You'll need a couple more things to pass the latest Safetynet and fully hiding some of the toughest apps.
This is one of the best guides I have seen (credits to the author who put it together):
[2023 FIX] Fix Magisk CTS Profile False Error - Bypass Safetynet
Magisk CTS Profile False Error is now popping up on almost everyone's device since Google made some changes in March. To Bypass Safetynet...
droidholic.com
Click to expand...
Click to collapse
Thx. I will read it.
Well. No sucess.
Safetynet is OK but the app doesn't start.
I have hidden the app in xprivacylua. Do I have to do it anywhere else ?
I had no issues opening the app once I had added it to the Hide list. Magisk app repackaged with a random name, of course. Not using any Riru or Xposed modules...
Seems like Magisk can hide from the app, but maybe there's something else with your setup that triggers it. Some hiding tips:
https://www.didgeridoohan.com/magisk/MagiskHide#hn_Hiding_root_from_apps
Didgeridoohan said:
I had no issues opening the app once I had added it to the Hide list. Magisk app repackaged with a random name, of course. Not using any Riru or Xposed modules...
Seems like Magisk can hide from the app, but maybe there's something else with your setup that triggers it. Some hiding tips:
https://www.didgeridoohan.com/magisk/MagiskHide#hn_Hiding_root_from_apps
Click to expand...
Click to collapse
OK Thx.
It seems that the app is not compatible with my phone
I thought that the issue came from magisk, but it's not. It's my phone...
Thx for your help
Hi all,
A very simple has been found.
Nothing more has been installed, just magisk hide.
The solution was to delete thé folder "TWRP" and all is OK now.
Thx for your help

[Help] Can't reinstall magisk

I upgraded to Magisk v23 without thinking and I am trying to reinstall 22.1 so I can continue with magisk hide, but no matter how I flash the repackaged boot.img, after reboot, installed always shows N/A. I've tried with v22 as well, and the same result.
Am I missing something about downgrading, or am I just doing something way off? Thanks in advance.
Why v22.1? Magisk v23 still has the "normal" MagiskHide...
(And just as a FYI, the new Deny list that is included in the latest Canary, 23010, works just as good to hide Magisk from what I've seen so far.)
I've tried 23 as well, I am on it as we speak, yet no matter what, I cannot get the boot to flash...
I did try the new version before rolling back and I could not add the RSA app I need for work to the deny list, rather it caught on to root and crapped out.
If I missed how to add to the deny list, I am happy to try again.
DrSeussFreak said:
I've tried 23 as well, I am on it as we speak, yet no matter what, I cannot get the boot to flash...
I did try the new version before rolling back and I could not add the RSA app I need for work to the deny list, rather it caught on to root and crapped out.
If I missed how to add to the deny list, I am happy to try again.
Click to expand...
Click to collapse
I was on Magisk 23001 (albeit on Android 12) and MagiskHide + SafetyNet worked great for me.
I'm currently on 23010, and it's still working:
V0latyle said:
So Magisk Canary was released yesterday:
Magisk 23010
Someone who is temp rooting want to patch their boot image with this and see what happens?
Also, Magisk Hide is no longer, so here's what you have to do to pass Safetynet (the check is no longer in Magisk so you'll have to use an external app)
In Magisk:
Remove Universal Safetynet Fix and Riru, if you have them installed, Reboot.
Launch Magisk again
Settings > Magisk:
Enable Zygisk
Enable Enforce Denylist
Enable for Google Play Services components: (I just enabled for all subcomponents)
com.google.android.gms
com.google.android.gms.unstable
That should be enough to pass Safetynet. Don't forget to hide other apps such as banking, GPay, DRM (Netflix, Amazon Prime Video, etc)
Click to expand...
Click to collapse
V0latyle said:
I was on Magisk 23001 (albeit on Android 12) and MagiskHide + SafetyNet worked great for me.
I'm currently on 23010, and it's still working:
Click to expand...
Click to collapse
Google play services is what I was missing in my earlier attempts. I cannot thank-you enough!
DrSeussFreak said:
Google play services is what I was missing in my earlier attempts. I cannot thank-you enough!
Click to expand...
Click to collapse
No problem. Google Play Services actually provides the security information for applications that depend on it, so it's one of the most important ones to hide.
Don't forget to hide other apps too. I've come across some weird ones; for example, I have a Honeywell WiFi smart thermostat, and for some odd reason the app not only checks for root, but prevents me from remotely controlling the thermostat if root is detected.
In most cases, you should be able to tell if something needs to be hidden or not; some apps just won't work (like Netflix or Amazon Prime Video).
V0latyle said:
No problem. Google Play Services actually provides the security information for applications that depend on it, so it's one of the most important ones to hide.
Don't forget to hide other apps too. I've come across some weird ones; for example, I have a Honeywell WiFi smart thermostat, and for some odd reason the app not only checks for root, but prevents me from remotely controlling the thermostat if root is detected.
In most cases, you should be able to tell if something needs to be hidden or not; some apps just won't work (like Netflix or Amazon Prime Video).
Click to expand...
Click to collapse
I just went through and re-did all my financials and streaming (plus all Amazon apps). I just forgot I had enabled it for these services.
V0latyle said:
No problem. Google Play Services actually provides the security information for applications that depend on it, so it's one of the most important ones to hide.
Don't forget to hide other apps too. I've come across some weird ones; for example, I have a Honeywell WiFi smart thermostat, and for some odd reason the app not only checks for root, but prevents me from remotely controlling the thermostat if root is detected.
In most cases, you should be able to tell if something needs to be hidden or not; some apps just won't work (like Netflix or Amazon Prime Video).
Click to expand...
Click to collapse
Sorry, 1 additional question I didn't get a clear answer from the forums. I have 4 modules active in Magisk, 3 of them related to safetynet, Riru, MagiskHide Props Config and Universal Safetynet Fix. I disabled them and everything is still working, and I am guessing I do not need them anymore, since it's a whole new setup.
Am I correct that I no longer need these modules anymore? Once again, I appreciate the help.
DrSeussFreak said:
Sorry, 1 additional question I didn't get a clear answer from the forums. I have 4 modules active in Magisk, 3 of them related to safetynet, Riru, MagiskHide Props Config and Universal Safetynet Fix. I disabled them and everything is still working, and I am guessing I do not need them anymore, since it's a whole new setup.
Am I correct that I no longer need these modules anymore? Once again, I appreciate the help.
Click to expand...
Click to collapse
Correct, I was using the same solution as you - I had Riru, USNF, MagiskHide Props Config, and Systemless Hosts. I removed everything and reenabled Systemless Hosts after a reboot. The reason this is necessary is because 23010 uses a different language to interface with modules, so a lot of modules are going to have to be rewritten.
I may end up going back to 23001 because my banking app (Navy Federal) now refuses to start.
V0latyle said:
Correct, I was using the same solution as you - I had Riru, USNF, MagiskHide Props Config, and Systemless Hosts. I removed everything and reenabled Systemless Hosts after a reboot. The reason this is necessary is because 23010 uses a different language to interface with modules, so a lot of modules are going to have to be rewritten.
I may end up going back to 23001 because my banking app (Navy Federal) now refuses to start.
Click to expand...
Click to collapse
Thank you for confirming and good luck with your banking app, I checked all mine, so far so good. New system news bugs
V0latyle said:
I was on Magisk 23001 (albeit on Android 12) and MagiskHide + SafetyNet worked great for me.
I'm currently on 23010, and it's still working:
Click to expand...
Click to collapse
Hi, gpay does not work anymore....Say system rooted....but safetynet pass....
Aldo there Is no way ti install back 23001
pippo45454 said:
Hi, gpay does not work anymore....Say system rooted....but safetynet pass....
Aldo there Is no way ti install back 23001
Click to expand...
Click to collapse
That is what i saw. I've been rooted for almost a decade and I've never seen this issue before with magisk. I don't use gpay often, so that is ok, but i appreciate the info.
pippo45454 said:
Hi, gpay does not work anymore....Say system rooted....but safetynet pass....
Aldo there Is no way ti install back 23001
Click to expand...
Click to collapse
Did you use DenyList to hide both GPay, Google Play Services, and Google Play Store?
GPay works for me, but I am getting a CTS profile mismatch on Magisk 23010, so there's more work to be done. For now, I've downgraded to 23001.
I'll confirm gpay working, i hadn't checked earlier, but I'd marked it for the deny list earlier
How you downgrade to 23001?could you write entire procedure please?
I pur all exclusion, in Witch way you obtain CTS profile?
V0latyle said:
The reason this is necessary is because 23010 uses a different language to interface with modules, so a lot of modules are going to have to be rewritten.
Click to expand...
Click to collapse
Not quite true. 23010 introduces Zygisk that gives module developers way more options on how to create advanced modules. We'll now be able to have Xposed style Magisk mods. Really cool. Old modules still work just as fine though...
V0latyle said:
I am getting a CTS profile mismatch on Magisk 23010
Click to expand...
Click to collapse
Could be because you removed the modules that can help you pass CTS...
MagiskHide Props Config if you need a certified print on a custom ROM (no need on the stock ROM) or if you need to reapply sensitive prop changes that are no longer included in Magisk (although these are also included in Universal SafetyNet Fix v2.1+).
Universal SafetyNet Fix to get around hardware backed key attestation and spoofing model props for Play Services (although currently Magisk Canary 23010 isn't compatible with Riru, so you'll probably have to use an older USNF release for now, and spoof props with MHPC).
I passeri CTS profile with safetynet but anytime i try ti add my card on gpay the band Will block automatically mi credito card...seems that they found that the phone Is not secure do to root....how i can go back ti 23001?
pippo45454 said:
I passeri CTS profile with safetynet but anytime i try ti add my card on gpay the band Will block automatically mi credito card...seems that they found that the phone Is not secure do to root....how i can go back ti 23001?
Click to expand...
Click to collapse
Go into Magisk and tap Uninstall > Restore Images, then Uninstall Completely. Allow Magisk to reboot the phone. When it reboots, Magisk and root will be gone.
Install Magisk 23.0. Manually patch the boot image, reboot to bootloader, and flash the patched boot image. Reboot again and you should come back into root with 23.0.
Didgeridoohan said:
Not quite true. 23010 introduces Zygisk that gives module developers way more options on how to create advanced modules. We'll now be able to have Xposed style Magisk mods. Really cool. Old modules still work just as fine though...
Click to expand...
Click to collapse
Thank you for the explanation. I was under the impression that most modules would have to be rewritten to work with Zygisk.
Didgeridoohan said:
Could be because you removed the modules that can help you pass CTS...
MagiskHide Props Config if you need a certified print on a custom ROM (no need on the stock ROM) or if you need to reapply sensitive prop changes that are no longer included in Magisk (although these are also included in Universal SafetyNet Fix v2.1+).
Universal SafetyNet Fix to get around hardware backed key attestation and spoofing model props for Play Services (although currently Magisk Canary 23010 isn't compatible with Riru, so you'll probably have to use an older USNF release for now, and spoof props with MHPC).
Click to expand...
Click to collapse
Well, I tried USNF 2.0.0, CTS profile still failed, so I removed Magisk and went back to the last version that worked for me, 23001. I only use 4 modules: USNF, Riru to support it, MagiskHide Props, and Systemless Hosts. I'm on the stock ROM. I'll just wait until USNF is updated to work with Zygisk.

What is the go-to replacement for MagiskHide & the central module repo?

I just realized there was a new public Magisk release yesterday, v24, and reading through the changes I see there are two that kind of impact me: MagiskHide and the central module repository removals.
So far I had been using MagiskHide because of its ease of use, list apps, tick box, and that's it (I haven't encountered apps that detected Magisk or root status, although I know it's insufficient for some). For modules, for example, the one that moves user certs to the system store, I just searched directly from the Magisk app and it was all good as well.
But things change from now on with those things being deprecated and removed and because there isn't much to go about in the release notes I was wondering if someone could direct me to the way of doing things now.
- What's the most apt, prevalent, or recommended replacement for MagiskHide? From the release notes I gather its a module, but I'm clueless as to which one or whether there are more than one option.
- If searching for mods and directly installing them is not available through the app, is there anything like it? Or is it all manual now? I.e. look for a module around the net, download it, copy it / decompress it somewhere in the device and install it.
Thanks for everything!
KaoDome said:
I just realized there was a new public Magisk release yesterday, v24, and reading through the changes I see there are two that kind of impact me: MagiskHide and the central module repository removals.
So far I had been using MagiskHide because of its ease of use, list apps, tick box, and that's it (I haven't encountered apps that detected Magisk or root status, although I know it's insufficient for some). For modules, for example, the one that moves user certs to the system store, I just searched directly from the Magisk app and it was all good as well.
But things change from now on with those things being deprecated and removed and because there isn't much to go about in the release notes I was wondering if someone could direct me to the way of doing things now.
- What's the most apt, prevalent, or recommended replacement for MagiskHide? From the release notes I gather its a module, but I'm clueless as to which one or whether there are more than one option.
- If searching for mods and directly installing them is not available through the app, is there anything like it? Or is it all manual now? I.e. look for a module around the net, download it, copy it / decompress it somewhere in the device and install it.
Thanks for everything!
Click to expand...
Click to collapse
[Discussion] Magisk - The Age of Zygisk.
This is a discussion and help thread for the newer versions of Magisk. The main goal of this thread is to help users migrate to Magisk v24+ SafetyNet Basic integrity Pass CTS profile match Pass Play Protect certification Device is certified...
forum.xda-developers.com
Here. First 5 post and you should know all you need
So, I read through that thread. It certainly solved a few issues for me. Like getting safety net, getting a repository, etc.
But it didn't have anything I see to replace magisk hide, even in the Fox Magisk Module Manager.
Do I just need to know other terminology now? Or is there something else I'm missing?
Quantumrabbit said:
So, I read through that thread. It certainly solved a few issues for me. Like getting safety net, getting a repository, etc.
But it didn't have anything I see to replace magisk hide, even in the Fox Magisk Module Manager.
Do I just need to know other terminology now? Or is there something else I'm missing?
Click to expand...
Click to collapse
I don't get it, Magisk Hide is good for passing SafetyNet and you said you got it. Anyway, for SafetyNet you can use the Universal SafetyNet Fix module.
If you meant the hide list, there's now the Deny list. To quote:
The Deny list is similar but instead of hiding Magisk from the process, Magisk is unloaded so there is nothing to hide.
Click to expand...
Click to collapse
Porpet said:
I don't get it, Magisk Hide is good for passing SafetyNet and you said you got it. Anyway, for SafetyNet you can use the Universal SafetyNet Fix module.
If you meant the hide list, there's now the Deny list. To quote:
Click to expand...
Click to collapse
Yes, it's for some banking apps, Concur, and others, none of which have any business checking for root, but all check for Magisk and such in other ways, and prevent usage.
If the deny list is how to do that now, I'll give that a go. Thank you
Quantumrabbit said:
Yes, it's for some banking apps, Concur, and others, none of which have any business checking for root, but all check for Magisk and such in other ways, and prevent usage.
If the deny list is how to do that now, I'll give that a go. Thank you
Click to expand...
Click to collapse
And where did you find the deny list?
fusk said:
And where did you find the deny list?
Click to expand...
Click to collapse
Settings enforce deny list. You need to enable zygisk and reboot prior also in settings.
Also there is an add on module shamiko that has more hide features after you configure denylist
H
toolhas4degrees said:
Settings enforce deny list. You need to enable zygisk and reboot prior also in settings.
Also there is an add on module shamiko that has more hide features after you configure denylist
Click to expand...
Click to collapse
How to add modules shamiko & how to more hide features
Spartacus500 said:
H
How to add modules shamiko & how to more hide features
Click to expand...
Click to collapse
Shamiko is a flashable only need to slash magisk module. You can find it in the magisk alpha thread on telegram. You need to configure denylist first and reboot then turn off the enforce denylist toggle and flash the shamiko module.
If you are using lsposed download hide my applist xposed module and search how to use it if you want more coverage
Pm me if you want links
I'm having a lot of trouble. Duo Mobile (a 2FA app) is still able to detect that I'm rooted. Here's what I've done:
1) Installed Magisk & Manager app version 24.1 (24100)
2) Enabled Zygisk (and rebooted of course)
3) Enabled Enforce DenyList
4) Added com.duosecurity.duomobile and ALL Google Play Services submodules to the DenyList
5) Installed Universal SafetyNet Fix v2.2.1 from https://github.com/kdrag0n/safetynet-fix/releases/tag/v2.2.1
6) Hidden the Magisk app
7) Completely uninstalled & reinstalled Duo Mobile (and verified that it's still on the DenyList
This is incredibly annoying, is there anything I'm doing wrong? Is there a way to verify that the SafetyNet Fix is working as expected? Magisk doesn't have a "Check SafetyNet" option on the app anymore.
Drakinite said:
I'm having a lot of trouble. Duo Mobile (a 2FA app) is still able to detect that I'm rooted. Here's what I've done:
1) Installed Magisk & Manager app version 24.1 (24100)
2) Enabled Zygisk (and rebooted of course)
3) Enabled Enforce DenyList
4) Added com.duosecurity.duomobile and ALL Google Play Services submodules to the DenyList
5) Installed Universal SafetyNet Fix v2.2.1 from https://github.com/kdrag0n/safetynet-fix/releases/tag/v2.2.1
6) Hidden the Magisk app
7) Completely uninstalled & reinstalled Duo Mobile (and verified that it's still on the DenyList
This is incredibly annoying, is there anything I'm doing wrong? Is there a way to verify that the SafetyNet Fix is working as expected? Magisk doesn't have a "Check SafetyNet" option on the app anymore.
Click to expand...
Click to collapse
This is quite weird and definitely shows how different devices handle root detection. I a Samsung S10+ and just installed Magisk 24 with enforce DenyList earlier this week. Today I just installed Duo Mobile and it works fine. I do not have it in the DenyList, and Magisk is not hidden. I use a custom SafetyNet fix that was installed when I originally installed an AIO TWRP/Magisk/SafetyNet fix after unlocking my bootloader. I also fail SafetyNet checks.
Have you tried Shamiko? It didn't help me pass SafetyNet so I removed it.
Unfortunately I don't have any other fixes for you but you can check SafetyNet with apps from the play store, I use YASNAC and SafetyNet 'attest'.
What phone are you using?
Drakinite said:
This is incredibly annoying, is there anything I'm doing wrong? Is there a way to verify that the SafetyNet Fix is working as expected? Magisk doesn't have a "Check SafetyNet" option on the app anymore.
Click to expand...
Click to collapse
There are SafetyNet checker apps you can download from the Play Store or F-Droid such as YASNAC.
danbest82 said:
Have you tried Shamiko? It didn't help me pass SafetyNet so I removed it.
Unfortunately I don't have any other fixes for you but you can check SafetyNet with apps from the play store, I use YASNAC and SafetyNet 'attest'.
What phone are you using?
Click to expand...
Click to collapse
I'm using a Oneplus 6. At your suggestion, I tried Shamiko, but so far it hasn't worked.
anonymous-bot said:
There are SafetyNet checker apps you can download from the Play Store or F-Droid such as YASNAC.
Click to expand...
Click to collapse
I tried Momo from the Magisk alpha telegram channel, and it's been helpful so far, but it's detecting Magisk/TWRP files and I don't know where they are located. Is there a way to find where these files it's detecting are? This might be what Duo is detecting.
When I run YASNAC, it passes the SafetyNet check.
Drakinite said:
I'm using a Oneplus 6. At your suggestion, I tried Shamiko, but so far it hasn't worked.
I tried Momo from the Magisk alpha telegram channel, and it's been helpful so far, but it's detecting Magisk/TWRP files and I don't know where they are located. Is there a way to find where these files it's detecting are? This might be what Duo is detecting.
When I run YASNAC, it passes the SafetyNet check.
Click to expand...
Click to collapse
Get VD Infos and use it to scan your files. You can find it on XDA.
Drakinite said:
I'm using a Oneplus 6. At your suggestion, I tried Shamiko, but so far it hasn't worked.
Click to expand...
Click to collapse
Hmm ok. Like I said shimako didn't work for me either. I'm not sure why Duo is still detecting root. For reference this is what is on my DenyList:
Drakinite said:
I tried Momo from the Magisk alpha telegram channel, and it's been helpful so far, but it's detecting Magisk/TWRP files and I don't know where they are located. Is there a way to find where these files it's detecting are? This might be what Duo is detecting.
When I run YASNAC, it passes the SafetyNet check.
Click to expand...
Click to collapse
YASNAC is the replacement for Momo it looks like since Momo is Riru based (https://github.com/canyie/Riru-MomoHider)
simplydat said:
Get VD Infos and use use to scan your files. You can find it in XDA
Click to expand...
Click to collapse
Ok so this one is more helpful, but I'm not sure how to hide these that appeared. Any idea what ro.kernel.qemu.gles is? I looked through my list of installed apps and nothing like that showed up.
Should we switch to private messages to not spam the thread? Or perhaps staying in here can be helpful for those with the same problem?
Drakinite said:
Ok so this one is more helpful, but I'm not sure how to hide these that appeared. Any idea what ro.kernel.qemu.gles is? I looked through my list of installed apps and nothing like that showed up.
Should we switch to private messages to not spam the thread? Or perhaps staying in here can be helpful for those with the same problem?
Click to expand...
Click to collapse
OMG WAIT, it finally worked! I don't know what changed, but Duo is now no longer detecting root. Gotta love when things magically start working when you don't know what changed.
Drakinite said:
OMG WAIT, it finally worked! I don't know what changed, but Duo is now no longer detecting root. Gotta love when things magically start working when you don't know what changed.
Click to expand...
Click to collapse
Awesome. Hope it stays that way!
Hi,
I've switched to the new method with the DenyList & Shamiko (v0.5.0) on OnePlus 6 recently - Magisk (v24.3), however it doesn't seem to hide root from Google Pay. Can it still be a bug with Magisk, when it can't hide system apps? In the changelog of Shamiko it mentioned that it was fixed in Magisk "24102+", I'm not sure what version is this, but I imagine it's not released yet. If so, is there a way of installing this version early?
Thank you!
antivirtel said:
Hi,
I've switched to the new method with the DenyList & Shamiko (v0.5.0) on OnePlus 6 recently - Magisk (v24.3), however it doesn't seem to hide root from Google Pay. Can it still be a bug with Magisk, when it can't hide system apps? In the changelog of Shamiko it mentioned that it was fixed in Magisk "24102+", I'm not sure what version is this, but I imagine it's not released yet. If so, is there a way of installing this version early?
Thank you!
Click to expand...
Click to collapse
Version 24102 would be v24.102. So your Magisk 24.300 is newer.

How to hide my custom rom or simulate the stock rom for bank apps?

Well, a month ago I installed ArrowOS12 in my A30, but something I don't knew about custom roms is bank apps blocking cuz'... "SECURITY" (funny AF), At first it just was blocked cuz' i have magisk root, but i activated many things to hide magisk and I realize that was not my root, but the custom OS.
I can't use my UNIQUE bank account by a STUPID SECURITY POLICY, How i solve this? I tried magiskhide props config for change my fingerprint prop or whatever.
If i can emulate a fake device in my own device only for this i will, ciz that's anoying
Hi, try download this two magisk modules
Shmaiko - Direct Link | Link
Universal SafetyFix - Direct Link | Link
Hide you Magisk APP in Magisk Settings and Turn On ZYGISK install this two modules.
Open Magisk Settings and in Enforce Settings Apps, mark your Bank Apps.
It worked for me (Galaxy A40)
I already tried both, didn't worked
AysllanHiro said:
I already tried both, didn't worked
Click to expand...
Click to collapse
Pass safety before
SirKosichka said:
Pass safety before
Click to expand...
Click to collapse
i found a way to pass the app checker, but thx for your help, i already passed safetynet too
TELL US HOW!
AysllanHiro said:
i found a way to pass the app checker, but thx for your help, i already passed safetynet too
Click to expand...
Click to collapse
How?
acerfreak said:
TELL US HOW!
Click to expand...
Click to collapse
I think people are good asking questions but not sharing the solution when they get it.
for me it was:
downloading "Universal SafetyFix" (and reboot)
hidding Magisk with MagiskHide in Magisk settings
Enable Zygisk, enable"Enforce DenyList" (again in Magisk settings) and selecting banking app in it (don't forget to reboot).
Also check if you passed SafetyNet with app like YASNAC for example. And clear storage, cache of banking app.
This was working on my phone with original google services like gapps (custom ROM of course).
On my secondary phone with MicroG implementation it's not working (play store required and something more i guess).
darukutsu said:
On my secondary phone with MicroG implementation it's not working (play store required and something more i guess).
Click to expand...
Click to collapse
Were you passing safetynet on it?
ShaDisNX255 said:
Were you passing safetynet on it?
Click to expand...
Click to collapse
Of course there's the problem...I had microG installed with fakestore (passing safetynet) but I had to install playstore (to install bank app from it) and now i'm not passing safetynet even with magisk module installed.

Question Not passing safetynet(Play Integrity API) on pixel 7

I made a big mistake yesterday. I saw threads about the new Play Integrity API thing and download the Integrity API checker. At that time, the integrity API checker cannot pass MEETS_DEVICE_INTEGRITY but my YASNAC can pass CTS profile. So I installed the Displex mod of the universal safetynet fix. I saw that my DEVICE_INTEGRITY passed but after testing a bit I found that it's not very consistent. Then after checking out the original repo knowing that there will be a release about this fix soon, I Installed back v2.4.0. This is when everything goes wrong. My device can no longer pass CTS profile. I tried wiping storage of the GAPPS, install back the modded module, remove Magiskhide props config. It is still not working. I cannot use my GPay now. Please help me get my GPAY back. Thanks for all the help.
To clarify my current setup, I have the modded v2.3.1_MOD2.1 installed now and props config removed.
Also a small question, do I need to wait for the device to get certified to get the CTS profile match or it should immediately work if everything is right.
seanho12345 said:
To clarify my current setup, I have the modded v2.3.1_MOD2.1 installed now and props config removed.
Also a small question, do I need to wait for the device to get certified to get the CTS profile match or it should immediately work if everything is right.
Click to expand...
Click to collapse
safetynet-fix 2.3.1-MOD_2.1 should get you back on track. It's a popular topic today for those of us caught off guard.
Waiting for Play Protect certification should work but clearing storage for Play Store and Play Services will speed it up.
manjaroid said:
safetynet-fix 2.3.1-MOD_2.1 should get you back on track. It's a popular topic today for those of us caught off guard.
Waiting for Play Protect certification should work but clearing storage for Play Store and Play Services will speed it up.
Click to expand...
Click to collapse
Yeah I already have USNF 2.3.1_MOD2.1 installed. However, my question is that is the CTS profile a prerequisite for the device to get certified or it should first get certified then the CTS profile match will work.
Hi
Im having sort of same problem, untill today my phone passed everything, gpay worked and all good..
from nothing it started to fail, not passing CTS profile match, gpay doesnt work.
tried everything, reinstalled magisk, reinstalled the modules, tried 2.3.1 mod, tried 2.4.0. Nothing works.
best i've achieved, is passing safetynet once, but after 2-3 min, it doesnt pass anymore.
any ideas what to do now?
manjaroid said:
safetynet-fix 2.3.1-MOD_2.1 should get you back on track. It's a popular topic today for those of us caught off guard.
Waiting for Play Protect certification should work but clearing storage for Play Store and Play Services will speed it up.
Click to expand...
Click to collapse
I'm Play Store certified but I don't pass CTS profile match
I am not sure if anyone has the same problem as mine. I configured magisk denylist as picture attached which included "play store service". The restarted the phone, went back to the denylist "play store service" gone
tinhsoftware said:
I am not sure if anyone has the same problem as mine. I configured magisk denylist as picture attached which included "play store service". The restarted the phone, went back to the denylist "play store service" gone
Click to expand...
Click to collapse
If you mean Google Play Services, that's normal and intended behavior if using a USNF mod. It's "denied" in the background.
Can confirm that the new 3.0 MOD from Displax works flawlessly. I just installed it and everything is working.
https://github.com/Displax/safetynet-fix/releases/download/v2.3.1-MOD_3.0/safetynet-fix-v2.3.1-MOD_3.0.zip
seanho12345 said:
Can confirm that the new 3.0 MOD from Displax works flawlessly. I just installed it and everything is working.
https://github.com/Displax/safetynet-fix/releases/download/v2.3.1-MOD_3.0/safetynet-fix-v2.3.1-MOD_3.0.zip
Click to expand...
Click to collapse
I you still have issues with Banking / Wallet app (even passing SN checks) then install Shamiko Module, disable Enforce Deny List and try. This module takes charge of DenyList hidding Zygisk itself and Zygisk modules.
good morning
after maby 20 hours of hiding the magic by Shamiko moldes
itis ok
and fine
I have a Google Pixel 7 with Magisk V25.2, Universal SafetyNetFix V2.4.0 and I still can't install some apps and some other are not even visible in the results.
I've tried with and without the deny list (clearing cache and storage of Google Play service/store/protect), but nothing.
I've spent the last 2 days banging my head on the wall looking for solution, but...nothing.
Do you guys know something that works?
andrea_x said:
Do you guys know something that works?
Click to expand...
Click to collapse
Yes, Canary builds 25206 (831a398b) or 25209 (2717feac) and patch accordingly. Plus the modified safetynet-fix module.
manjaroid said:
Yes, Canary builds 25206 (831a398b) or 25209 (2717feac) and patch accordingly. Plus the modified safetynet-fix module.
Click to expand...
Click to collapse
Wait wait, I'm not familiar with that, how do I get the APK or if it's a Magisk module where do I get the .ZIP?
And what do you mean with "patch accordingly"?
Thanks a lot!
andrea_x said:
Wait wait, I'm not familiar with that, how do I get the APK or if it's a Magisk module where do I get the .ZIP?
And what do you mean with "patch accordingly"?
Thanks a lot!
Click to expand...
Click to collapse
Browse the repo and download app-release.apk. On a PC click the <> symbol to the right. If you're navigating from a phone tap the Browse files button to locate the file. I suggest caution and go with 25206. Anything after it has problems except maybe 25209, which worked ok for me but not for everybody. Once Canary is installed avoid the update button.
First, uninstall your current Magisk and restore init_boot.img back to stock. The phone is unrooted at this point.
Whichever Magisk release you install next, patch init_boot.img with that release. The phone should be rooted at this point.
Then your modules and Magisk configuration.
The safetynet-fix module you want is named safetynet-fix-v2.4.0-MOD_1.2.zip.
andrea_x said:
Wait wait, I'm not familiar with that, how do I get the APK or if it's a Magisk module where do I get the .ZIP?
And what do you mean with "patch accordingly"?
Thanks a lot!
Click to expand...
Click to collapse
magisk-files/canary.json at master · topjohnwu/magisk-files
Magisk File Host. Contribute to topjohnwu/magisk-files development by creating an account on GitHub.
github.com
ziddey said:
magisk-files/canary.json at master · topjohnwu/magisk-files
Magisk File Host. Contribute to topjohnwu/magisk-files development by creating an account on GitHub.
github.com
Click to expand...
Click to collapse
Thanks for your help, but I've installed and the "CTS profile match" test stil fails. and I still can't install some apps.
manjaroid said:
Once Canary is installed avoid the update button.
Click to expand...
Click to collapse
Thanks a lot fr your detailed explanation, you're very kind!
Buuut...the update button is exactly where the install button is, how can I patch the init_boot.img?
Should I really go back to the original init_boot.img first?
andrea_x said:
Thanks a lot fr your detailed explanation, you're very kind!
Buuut...the update button is exactly where the install button is, how can I patch the init_boot.img?
Should I really go back to the original init_boot.img first?
Click to expand...
Click to collapse
I don't know what's up with the buttons. Install is needed to select your file to patch. And yes, when starting over it's usually best to clean patch the boot image with the Magisk release that's running, although not always. If you don't mind posting a screen shot of Magisk it might help get a better perspective.
manjaroid said:
I don't know what's up with the buttons. Install is needed to select your file to patch. And yes, when starting over it's usually best to clean patch the boot image with the Magisk release that's running, although not always. If you don't mind posting a screen shot of Magisk it might help get a better perspective.
Click to expand...
Click to collapse
Here it is the screenshot

Categories

Resources