A Root Check is a type of Check that detects whether the application is running on an Android device that has been rooted.
Rooted devices can create security risks for applications and users. An attacker might run the application on a rooted device to access the application binary, reverse engineer it, extract sensitive data, or manipulate the application's behavior.
Regular users may also root their devices for reasons unrelated to your application. However, rooting a device breaks the secure environment provided by the Android operating system and may expose user data or accounts to additional risk.
For applications that handle sensitive data or are subject to data-processing regulations, running on rooted devices may be an unacceptable risk.
Root Checks can detect when the application is running on a rooted device and react by notifying the application or hindering the attacker.
Configure Root Checks
To have Dotfuscator inject Root Checks into your Android application:
- In the source code, add and configure the Check attributes directly in your application.
- In the Config Editor, add the Check and configure its properties and locations.
Both methods allow you to specify the properties that determine how the Check operates.
To configure a Root Check in the Config Editor:
- Go to the Checks tab in Dotfuscator’s Config Editor.
- Select Add Root Check….
- Configure the Check properties.
- Configure the Check locations.
For the full list of available properties, see the RootCheckAttribute section in the Check Attributes article.
If you are adding a Tamper Check to a Xamarin Android application, see the Root Check for Xamarin Android section in the Enhance Protection After Your First Build article.
Supported Application Types
Root Checks apply to Android applications.
Use Root Checks for Xamarin Android and MAUI Android applications when you need to detect rooted Android devices at runtime.
Test Root Checks
To test how Root Checks react when a rooted device is detected:
- Build the protected Android application with Root Checks configured.
- Run the protected application on a rooted Android device or environment.
- Exercise the locations of your Root Checks.
- Observe how the application reacts when the rooted device is detected.
A Root Check only runs when one of its configured locations is called. If the application starts on a rooted device but the configured location has not run yet, the Check does not detect the rooted device until that location is called.