Does anyone's Mi MIX with unlocked bootloader (no root) pass Safetynet check? - Xiaomi Mi MIX Questions & Answers

I just rooted my phone and found out that my MIX havent passed SafetyNet CTS profile check. However, even unrooted, the status remains the same. Since I didnt check it befor I rooted, I'm not sure if its even like this at the first place? My MIX bootloader has been unlocked anyway.

romeokk said:
I just rooted my phone and found out that my MIX havent passed SafetyNet CTS profile check. However, even unrooted, the status remains the same. Since I didnt check it befor I rooted, I'm not sure if its even like this at the first place? My MIX bootloader has been unlocked anyway.
Click to expand...
Click to collapse
Apparently the only way to get safetynet working is to use china stable rom (with locked bootloader)
http://en.miui.com/thread-405166-1-1.html
awaiting kernel sources to compile the bypass!

Related

Android Pay on rooted Mi Mix? Possible?

Hi Mi Mix fans!
Does anybody know how to run Android Pay on rooted Mi Mix?
I have tried Xposed + Rootcloak and it doesn't work...
Is there anybody who run Android Pay on Mi Mix with unlocked bootloader and root installed?
Even restore an app with the configured data doesn't work. After the app is started Android Pay clear the settings and want me to set up the payments cards again. Then after click on "Add card" it displays the message "You cannot run Andoid Pay on this device, because root...." etc. etc.
Any help will be very appreciated!
zencooler said:
Hi Mi Mix fans!
Does anybody know how to run Android Pay on rooted Mi Mix?
I have tried Xposed + Rootcloak and it doesn't work...
Is there anybody who run Android Pay on Mi Mix with unlocked bootloader and root installed?
Even restore an app with the configured data doesn't work. After the app is started Android Pay clear the settings and want me to set up the payments cards again. Then after click on "Add card" it displays the message "You cannot run Andoid Pay on this device, because root...." etc. etc.
Any help will be very appreciated!
Click to expand...
Click to collapse
until we get kernel sources and are able to patch the bootloader with SultanXDA's safetynet patch, no android pay on root
mlkemac said:
until we get kernel sources and are able to patch the bootloader with SultanXDA's safetynet patch, no android pay on root
Click to expand...
Click to collapse
Does SultanXDA also remove the other security requirements of android pay? Last I tried android pay it says, either I have unlocked bootloader, custom firmware or device is rooted.
Also, my company requires me to use MobileIron's suite of apps for email and such. It won't activate w/ Root and also usb debugging (WTF). If any of you guys are in IT and have the ability to recommend software, stay away from that POS.
Thorin78 said:
Does SultanXDA also remove the other security requirements of android pay? Last I tried android pay it says, either I have unlocked bootloader, custom firmware or device is rooted.
Also, my company requires me to use MobileIron's suite of apps for email and such. It won't activate w/ Root and also usb debugging (WTF). If any of you guys are in IT and have the ability to recommend software, stay away from that POS.
Click to expand...
Click to collapse
I think you would need to hide root as well with suhide or an equivalent.
the unlocked bootloader is the most important piece here, once that's done the rest is easy.
mlkemac said:
I think you would need to hide root as well with suhide or an equivalent.
the unlocked bootloader is the most important piece here, once that's done the rest is easy.
Click to expand...
Click to collapse
I'm hoping AOSP would come out sooner or later and then I would "relock" my bootloader if necessary.
mlkemac said:
until we get kernel sources and are able to patch the bootloader with SultanXDA's safetynet patch, no android pay on root
Click to expand...
Click to collapse
Thanks for the info. Seems it a bit long way ahead.
I come from Galaxy S7 where it wasn't an issue and I had unlocked bootloader with root, xposed etc. and fully working Android Pay...
Regards.
I have not unlocked or rooted yet and Android Pay is not available. Did it work before you unlocked?
gary.lavin said:
I have not unlocked or rooted yet and Android Pay is not available. Did it work before you unlocked?
Click to expand...
Click to collapse
Sure I read will on work on stable China ROM,
Not always though Google signed the stable ROM but not Dev.
I'm on China stable just tried it and said bootloader unlocked, which is true.
gary.lavin said:
I have not unlocked or rooted yet and Android Pay is not available. Did it work before you unlocked?
Click to expand...
Click to collapse
Unfortunately I didn't try before unlock and root so I'm not sure it worked before...
Can anybody confirm it was or wasn't working on locked bootloader, please?
Sent from my MIX using XDA Free mobile app
It doesn't even work on stock stable rom with locked bootloader lol
Leechoonhwee said:
It doesn't even work on stock stable rom with locked bootloader lol
Click to expand...
Click to collapse
Really??? How come???
zencooler said:
Really??? How come???
Click to expand...
Click to collapse
I dunno. Ask Google. It says either my phone is unlocked or rooted which is false. After that, I sort of gave up and just unlocked the bootloader and root the phone
Leechoonhwee said:
It doesn't even work on stock stable rom with locked bootloader lol
Click to expand...
Click to collapse
Did you check wasn't already unlocked. Even TWRP will stop it working, although I did read the last 2 stable ROM s it didn't work.
Leechoonhwee said:
I dunno. Ask Google. It says either my phone is unlocked or rooted which is false. After that, I sort of gave up and just unlocked the bootloader and root the phone
Click to expand...
Click to collapse
I had the exact same problem. it wasn't just google play. any NFC payment app would have the same or similar message
I got the phone with China stable rom, no root nor bootloader unlock. Android pay works fine.
Leechoonhwee said:
It doesn't even work on stock stable rom with locked bootloader lol
Click to expand...
Click to collapse
shinji21 said:
I got the phone with China stable rom, no root nor bootloader unlock. Android pay works fine.
Click to expand...
Click to collapse
Over on reddit, I was chatting with someone who was using Android Pay on his Mi Mix straight out the box but it was a vendor ROM. He flashed one of the official ROMs and it stopped working but that was because he'd unlocked his bootloader in the process.
After trial and error (and nearly bricking his phone), the conclusion was that it will work on the China Stable ROM, provided your bootloader is locked and you're not rooted.
I'm going to switch back to stable and re-lock my bootloader this weekend to see if it works for me.
Step666 said:
Over on reddit, I was chatting with someone who was using Android Pay on his Mi Mix straight out the box but it was a vendor ROM. He flashed one of the official ROMs and it stopped working but that was because he'd unlocked his bootloader in the process.
After trial and error (and nearly bricking his phone), the conclusion was that it will work on the China Stable ROM, provided your bootloader is locked and you're not rooted.
I'm going to switch back to stable and re-lock my bootloader this weekend to see if it works for me.
Click to expand...
Click to collapse
Thanks for a quick summary. Let us know if this check to relock bootloader and installation China ROM works.
Regards!
Sent from my MIX using XDA Free mobile app
I got a feeling that it works only when Google had approved of the rom. When I flash the china stable when I got my phone, it was newly updated and hence not approved by Google yet.
zencooler said:
Thanks for a quick summary. Let us know if this check to relock bootloader and installation China ROM works.
Click to expand...
Click to collapse
Seems to have worked - at least it let me set up a card etc.
Just need to use it to pay for something for 100% confirmation but I doubt it'll be an issue.
Downside is, I'd forgotten how China-y the Stable firmware is after using the Xiaomi.eu ROM.
OK, final update.
The app works on China Stable up to the point when you try to make a payment, that has never worked for me - it simply doesn't interact with the POS system.
Android Pay was about the only reason to go stock, IMO. Given it doesn't work, I'll probably switch back to Xiaomi.eu.

Xiaomi Mi Mix 2 Unlock security risks

Hi everyone,
I've recently unlocked my Xiaomi Mi Mix 2 that came with the chinese rom so that I could install the global rom.
I've been using it for a while and when I opened a banking app, I get the following message:
Warning
It seems your device has had unauthorized modifications to its operating system. Using this device for your banking could compromise the security of your personal information.
I didn't think unlocking the phone would be this much of a risk. I don't understand too much about the technology behind this so I wanted to see if anyone could explain whats happening and if I should refund my phone.
Thanks!
brian0306 said:
Hi everyone,
I've recently unlocked my Xiaomi Mi Mix 2 that came with the chinese rom so that I could install the global rom.
I've been using it for a while and when I opened a banking app, I get the following message:
Warning
It seems your device has had unauthorized modifications to its operating system. Using this device for your banking could compromise the security of your personal information.
I didn't think unlocking the phone would be this much of a risk. I don't understand too much about the technology behind this so I wanted to see if anyone could explain whats happening and if I should refund my phone.
Thanks!
Click to expand...
Click to collapse
You are probably using the global dev rom which doesn't pass Safetynet for various reasons. You shouldn't have any issues with the global stable rom.
Don't listen to the guy above. Flash Global Stable ROM if you haven't already and lock your bootloader. From then on all will be good.
Mr_Bartek said:
Don't listen to the guy above. Flash Global Stable ROM if you haven't already and lock your bootloader. From then on all will be good.
Click to expand...
Click to collapse
...
I said pretty much exactly the same thing as you?
It won't matter whether he uses Dev or Stable if his bootloader is left unlocked. He needs both Global Stable and a locked bootloader.
Mr_Bartek said:
It won't matter whether he uses Dev or Stable if his bootloader is left unlocked. He needs both Global Stable and a locked bootloader.
Click to expand...
Click to collapse
How do I lock my bootloader?? I've already unlocked my phone
brian0306 said:
How do I lock my bootloader?? I've already unlocked my phone
Click to expand...
Click to collapse
U don't need to lock the bootloader to get it to work, I'm on the global ROM with unlocked bootloader - safety net passes.
It also passes on Xiaomi EU ROM with unlocked bootloader. Just flash one of those ROMs, install magisk, and set magisk to hide.
@brian0306, have a look here: https://youtu.be/6u3Pg1JOXkI
brian0306 said:
Hi everyone,
I've recently unlocked my Xiaomi Mi Mix 2 that came with the chinese rom so that I could install the global rom.
I've been using it for a while and when I opened a banking app, I get the following message:
Warning
It seems your device has had unauthorized modifications to its operating system. Using this device for your banking could compromise the security of your personal information.
I didn't think unlocking the phone would be this much of a risk. I don't understand too much about the technology behind this so I wanted to see if anyone could explain whats happening and if I should refund my phone.
Thanks!
Click to expand...
Click to collapse
I am running Miui 9 global with unlocked bootloader and rooted with Magisk 14.3 and it passes safetynet and Android pay works just fine.
Guys, I know this is XDA but come on. Guy just wants a working phone without the hassle. He didn't ask for root or methods to bypass Safetynet with Magisk! Locking bootloader on an official Global Stable ROM is all he needs.
Mr_Bartek said:
Guys, I know this is XDA but come on. Guy just wants a working phone without the hassle. He didn't ask for root or methods to bypass Safetynet with Magisk! Locking bootloader on an official Global Stable ROM is all he needs.
Click to expand...
Click to collapse
You forgot to mention they also didn't ask for locking the bootloader either.
Do you really think someone who says this really cares about bypassing Safetynet?
I didn't think unlocking the phone would be this much of a risk. I don't understand too much about the technology behind this so I wanted to see if anyone could explain whats happening and if I should refund my phone.
Click to expand...
Click to collapse
Also, don't quote the post you are replying to if it's right above yours. It's bad netiquette.
Mr_Bartek said:
Do you really think someone who says this really cares about bypassing Safetynet?
Also, don't quote the post you are replying to if it's right above yours. It's bad netiquette.
Click to expand...
Click to collapse
Only the poster can decide if they care or not, it's better to have more options than 1.
It's not bad etiquette, it ensures that my comment addresses the comment I want it to address.
Mackay53 said:
Only the poster can decide if they care or not, it's better to have more options than 1.
It's not bad etiquette, it ensures that my comment addresses the comment I want it to address.
Click to expand...
Click to collapse
+1, installing magisk is definitely the easier fix. Won't need to wipe data or anything
@ssojyeti2, locking bootloader doesn't wipe data. Stop spreading misinformation. Also how is it easier if you have to flash (or at least boot TWRP) and then flash Magisk zip? To lock BL you need to run one command (fastboot oem lock) and you're done.
Mr_Bartek said:
@ssojyeti2, locking bootloader doesn't wipe data. Stop spreading misinformation. Also how is it easier if you have to flash (or at least boot TWRP) and then flash Magisk zip? To lock BL you need to run one command (fastboot oem lock) and you're done.
Click to expand...
Click to collapse
How exactly is that spreading misinformation?
Ssojyeti2 just clearly said that flashing magisk doesn't wipe your data or anything. Nothing about locking bootloader...
Mr_Bartek said:
@ssojyeti2, locking bootloader doesn't wipe data. Stop spreading misinformation. Also how is it easier if you have to flash (or at least boot TWRP) and then flash Magisk zip? To lock BL you need to run one command (fastboot oem lock) and you're done.
Click to expand...
Click to collapse
Stop being so butthurt bro
Mr_Bartek said:
Guys, I know this is XDA but come on. Guy just wants a working phone without the hassle. He didn't ask for root or methods to bypass Safetynet with Magisk! Locking bootloader on an official Global Stable ROM is all he needs.
Click to expand...
Click to collapse
Well said. I just got my phone and it's on the Chinese rom. I'm not a rom/flash xda member and I'm leaving my phone on the Chinese rom and stock. Bloat removed or frozen already with a 1.5gb update pending for download tonight (a nice option miui gave me) and a smaller update installed as I switched on the phone. I intend to keep this phone for a few years and I'm not f*cking with anything.
Gapps installed and working perfectly, including contacs sync which was an issue at some point. I haven't tried nfc yet but everything works including irrelevant apps asking for nfc access (lol). Nah, I'll stick with the Chinese rom until there's a compelling reason to change it.

Google starts blocking its apps on uncertified Android devices

From Endgadget: https://www.engadget.com/2018/03/26/google-starts-blocking-its-apps-on-uncertified-android-devices/
If you're fond of loading custom ROMs on your Android phone, life just became complicated. Google has quietly started blocking access to its apps on uncertified devices whose firmware was built after March 16th. If you're affected, you'll get a warning that a device is "not certified" and can't sign into a Google account. This won't prevent you from loading ROMs, but you'll have to register your device IDs on a white list every time you undergo a factory reset -- when there's a 100-ID limit, you could run into problems if you're routinely wiping your phone to install new firmware.
We've asked Google for comment on the move.
The company is already quite clear about the rationale, however. Vendors officially need to get certification to load Google apps (Android's licensing model is built around this), but some of them ignore this requirement and either load the apps regardless or encourage you to download them yourself. This new block theoretically pushes those less-than-scrupulous brands to clean up their acts by either obtaining certification or sticking to an AOSP version of Android, where they'd depend on third-party apps.
The problem, of course, is that it leaves custom ROM users caught in the crossfire. They may have to be more selective about when they install ROMs and skip minor updates. It's far from the end of custom firmware, but the era of anything-goes firmware (on phones that allowed custom ROMs in the first place, that is) might be winding down.
I was just posting a thread about this aswell. My thoughts are more focused around the app store. How will we access the app store? Are we able to hack / "pirate" the app store apk or is the mod community going to have to start a separate app store? Maybe even twrp install every app we use?
Stop using wonky ass roms, if your rom passes safetynet and certifies your device, you won't need to do this. DU has been passing as certified for like a week now, even before the issue was made public. I made 2 clean flashes yesterday and haven't faced the issue. SO if rom devs fix their stuff, there won't be any need for IMEI or androidID registration.
As you can see my OnePlus 5 is listed as uncertified and I'm on stock OpenBeta 7 with no root or any other mod. Only my bootloader is unlocked that's it. BTW I flash the OpenBeta 7 clean with a erase everything and setup the phone without any issues :good:
Sent from my OnePlus 5 using XDA Labs
Is the certification check is going to be based on Bootloader lock status or ROMs????
I am confused.....
smohanv said:
Is the certification check is going to be based on Bootloader lock status or ROMs????
I am confused.....
Click to expand...
Click to collapse
If I remember me right I look at that before I unlock my bootloader and it shows me certified after the unlock it shows me uncertified, to me it seems it is based on a locked or unlocked bootloader, but I can be wrong this have to answer the gurus here :good:
Sent from my OnePlus 5 using XDA Labs
GraveDigger176 said:
If I remember me right I look at that before I unlock my bootloader and it shows me certified after the unlock it shows me uncertified, to me it seems it is based on a locked or unlocked bootloader, but I can be wrong this have to answer the gurus here :good:
Sent from my OnePlus 5 using XDA Labs
Click to expand...
Click to collapse
mmmm....... so, if this is the case rooting is going to a an issue... until an exploit is found we may have to lock bootloader back and stay without rooting for a while.
Let us wait for more knowledge coming on this subject before we think of any action... at the moment my device is rooted and also I am running crDroid (Oreo 8.1) and also using magisk with Safety Net passed so that I am able to use Google Pay.
GraveDigger176 said:
As you can see my OnePlus 5 is listed as uncertified and I'm on stock OpenBeta 7 with no root or any other mod. Only my bootloader is unlocked that's it. BTW I flash the OpenBeta 7 clean with a erase everything and setup the phone without any issues :good:
Sent from my OnePlus 5 using XDA Labs
Click to expand...
Click to collapse
I clean flashed OB7 on my OnePlus 5, my bootloader is set back to locked as well and my device says certified.
Maybe it's because of the unlocked bootloader that you see uncertified?
dazr87 said:
I clean flashed OB7 on my OnePlus 5, my bootloader is set back to locked as well and my device says certified.
Maybe it's because of the unlocked bootloader that you see uncertified?
Click to expand...
Click to collapse
Yeah it seems so, but i have clean flash OpenBeta 7 with erase everything and unlocked bootloader and setup the Phone without any problems, I let it as it is now until i got problems with signing in google account after a clean flash :good:
I think certified or uncertified it depends on your rom, because my device still showed me certified status, with unlocked bootloader rooted with magisk, yes it's strange but somehow I'll look after it since I'm still waiting the open beta release to stable
Ps: sorry I can't upload screenshot because my xda app keeps saying bad request
sendashano said:
I think certified or uncertified it depends on your rom, because my device still showed me certified status, with unlocked bootloader rooted with magisk, yes it's strange but somehow I'll look after it since I'm still waiting the open beta release to stable
Ps: sorry I can't upload screenshot because my xda app keeps saying bad request
Click to expand...
Click to collapse
Well then is stock OpenBeta 7 crap :laugh:
BTW then all OOS stock roms crap since I unlock the bootloader it shows me uncertified :good:
Sent from my OnePlus 5 using XDA Labs
My OP5 is running stock OB 7, with an unlocked boot loader. I'm not rooted. When I got mine used off of Swappa, I made sure to unlock the bl and then flashed the OB 5 fw. Since then I've taken the OTA's for OB 6 and 7. No issues and my device is certified in the Play Store.
Mine is stock ROM Nougat 7.1 with unlocked bootloader and root and my device is uncertified.
AEX-Rom Oreo, decrypted, rooted with Magisk shows certified.
This is no problem with stock/nonstock/root etc.
Maybe Magisk helps to be certified
Google says that will not uncertified the custom roms
I'm on ob7 unlocked bootloader with magisk installed and shows me certified
OOS 5.04, unlocked bootloader, magisk 16.0 - uncertified!!
I'm on xXx NoLimits 10.1 Stable 5.04 and rooted (Magisk 16.3) with an unlocked bootloader. No problems here.

Netflix not compatible with XT1925-6?

anyone found a workaround? currently trying to install the apk from another phone, will report back
edit: apparently sideloading the apk works. does anyone know why it wouldnt be "compatible" according to the google play store?
Netflix is working on my end. Have you rooted or anything? I'm pure stock for now, just got her today and loving it so far.
GavinMazey said:
Netflix is working on my end. Have you rooted or anything? I'm pure stock for now, just got her today and loving it so far.
Click to expand...
Click to collapse
Nope, stock everything besides unlocked bootloader. I am liking the phone a lot other than this and the battery life
Check in settings on your Play Store account at the bottom to see if your phone listed as Certified. After I unlocked the Bootloader on my X4, phone became Uncertified and had to get Netflix app from other source.
jfalls63 said:
Check in settings on your Play Store account at the bottom to see if your phone listed as Certified. After I unlocked the Bootloader on my X4, phone became Uncertified and had to get Netflix app from other source.
Click to expand...
Click to collapse
yeah this is it, seems stupid to me
bird412 said:
yeah this is it, seems stupid to me
Click to expand...
Click to collapse
If your bootloader is unlocked, you may be tripping Safetynet as well - if SafetyNet is tripped, Netflix may not show up as compatible or show up at all: https://www.xda-developers.com/netf...lly-a-new-feature-in-the-google-play-console/ https://www.xda-developers.com/netflix-app-currently-unavailable-for-rootedunlocked-users/
You could try rooting with magisk to try to hide the bootloader unlocked status or re-lock your bootloader.
echo92 said:
If your bootloader is unlocked, you may be tripping Safetynet as well - if SafetyNet is tripped, Netflix may not show up as compatible or show up at all: https://www.xda-developers.com/netf...lly-a-new-feature-in-the-google-play-console/ https://www.xda-developers.com/netflix-app-currently-unavailable-for-rootedunlocked-users/
You could try rooting with magisk to try to hide the bootloader unlocked status or re-lock your bootloader.
Click to expand...
Click to collapse
ah that makes sense. i sideloaded the app and its working fine right now, ill probably wait for a more stable twrp release to try it out

Question Bootloader unlock

Hello everybody,
I've recently bought a Xiaomi Mi11 Ultra.
After using it for a couple months, i've noticed two things that don't work.
First, Netflix application is unavailable on the play store. I've downladed the apk from different sources but impossible to get it working.
Second, googlepay don't work because "my terminal is not safe".
I've read a lot of threads before posting it.
When my phone boot, there is an open padlock si i assume my bootloader is unlock.
I've checked my DRM info, and Widevine CDM security level is L1.
i've run Safetynet check and everything is in green except CTS profile matched who is in red
The advice is "lock bootloader".
I'm currently running MIUI Global 14.0.1 / 14.0.1.0 (TKAMIXM)
Why is my bootloader unlock if i am running an official global rom ? Was it a Chinese version ? It's not an official ROM ? How to know what was running before ?
What is the best way to get netflix and Gpay working ? Flashing a stock rom and the bootloader will lock itself or flash a xiaomi.eu rom with TWRP ?
I've read that xiaomi.eu rom hide unlock BL.
Thanks in advance for your answers
Regards
Sanghei said:
Hello everybody,
I've recently bought a Xiaomi Mi11 Ultra.
After using it for a couple months, i've noticed two things that don't work.
First, Netflix application is unavailable on the play store. I've downladed the apk from different sources but impossible to get it working.
Second, googlepay don't work because "my terminal is not safe".
I've read a lot of threads before posting it.
When my phone boot, there is an open padlock si i assume my bootloader is unlock.
I've checked my DRM info, and Widevine CDM security level is L1.
i've run Safetynet check and everything is in green except CTS profile matched who is in red
The advice is "lock bootloader".
I'm currently running MIUI Global 14.0.1 / 14.0.1.0 (TKAMIXM)
Why is my bootloader unlock if i am running an official global rom ? Was it a Chinese version ? It's not an official ROM ? How to know what was running before ?
What is the best way to get netflix and Gpay working ? Flashing a stock rom and the bootloader will lock itself or flash a xiaomi.eu rom with TWRP ?
I've read that xiaomi.eu rom hide unlock BL.
Thanks in advance for your answers
Regards
Click to expand...
Click to collapse
Your bootloader is unlocked. Probably your phone is Chinese version with installed global ROM. My advice is: flash xiaomi.eu or EliteRom (which is based on xiaomi.eu and has even more features). Both ROMs are with passed SafetyNet. You will not regret it. Cheers
Sanghei said:
Hello everybody,
I've recently bought a Xiaomi Mi11 Ultra.
After using it for a couple months, i've noticed two things that don't work.
First, Netflix application is unavailable on the play store. I've downladed the apk from different sources but impossible to get it working.
Second, googlepay don't work because "my terminal is not safe".
I've read a lot of threads before posting it.
When my phone boot, there is an open padlock si i assume my bootloader is unlock.
I've checked my DRM info, and Widevine CDM security level is L1.
i've run Safetynet check and everything is in green except CTS profile matched who is in red
The advice is "lock bootloader".
I'm currently running MIUI Global 14.0.1 / 14.0.1.0 (TKAMIXM)
Why is my bootloader unlock if i am running an official global rom ? Was it a Chinese version ? It's not an official ROM ? How to know what was running before ?
What is the best way to get netflix and Gpay working ? Flashing a stock rom and the bootloader will lock itself or flash a xiaomi.eu rom with TWRP ?
I've read that xiaomi.eu rom hide unlock BL.
Thanks in advance for your answers
Regards
Click to expand...
Click to collapse
use safetynet fix

Categories

Resources