Paytm App Stops Asking For Root Access On Android Phones

Last week, Paytm app asking for root access on Android phones had raised major concerns. Now after being flagged by a French security researcher, the digital payments player has fixed the sensitive issue in its app on Android phones.
As per a TOI report, the security researcher, Baptiste Robert, who goes by the name of Elliot Alderson on Twitter, told TOI that Paytm in a new update on its app has stopped seeking ‘root access’ from users after he highlighted the issue with the company.
If a user allows the app to gain administrative access also known as root access or superuser access it will, in theory, have complete control over the device.
Rooting allows users to gain privileged control of their Android devices, thus removing any barriers to modification and teaking of the device’s software. Once a device is rooted it can be used to modify the device’s behaviour. Normally this is restricted to the user himself. However certain apps though can be given this privilege that allows them complete access to the device and its system software.
Thus earlier, if a user allowed the app root access, Paytm would virtually have complete control over the device.
Alderson pointed out that root access is essentially one of the most significant entry points for any Android device which can manipulate the operating system of the phone. It can access other app information, chat details, among many other things on the device. This is not an Android permission like having access to text messages and a user’s phone book.
Powered By Inc42 BrandLabs
Hence unless a user is totally savvy with technology, allowing root access is not advised by tech experts.
When the issue was raised, Paytm had stated that it was seeking root access due to requirements laid out by the payments umbrella body, NPCI which mandates checking if a device is rooted.
At that issue, Paytm founder and CEO Vijay Shekhar Sharma had said that NPCI had asked the app maker to check for rooted devices before enabling access to UPI payments.
“We are still checking if a device is rooted or not but the method has changed with a different coding. While the earlier method was foolproof, the latest one means to check if a device is rooted or not with a success rate of about 70-80%,” a Paytm spokesperson told TOI without divulging details.
As per the company’s message to Alderson, the fix does not require a new app on the Google Play Store. The engineering team pushed a configuration change.
Alderson said root access goes beyond standard permissions sought by various apps which is what raises concerns. Because with root access, the Paytm app can do anything it wants on the phone, read a user’s messages or go through his call history. Even though Paytm had pointed out that it doesn’t intend to do any of this but still it raises concerns about the privacy of the user, the security of the device, and of a possible threat from hackers.
Given the rise in threat from malware and hackers, it is natural that Paytm app asking for root access on Android phones has raised concerns as it does lead to a possibility of breach in cyber security. With the issue being resolved, users can at least now rest assured that sensitive data on their phones cannot be accessed easily now with the Paytm app.

Trending News

Xiaomi pumps Rs 3,500 crore into India business

BlackBuck's out to raise $150M in new round, valuation likely to jump to $800 M

With $21 Billion, Azim Premji among world’s top philanthropists

Google agreed on a $45M exit package for India-origin exec accused of sex abuse

HSBC pegs Zomato's valuation at $3.6 billion ahead of Swiggy

PayU in talks to acquire online payments firm Wibmo for $60M

Quikr close to acquiring refurbished goods marketplace Zefo in all-stock deal

What life looks like after a layoff from an IT company

General Atlantic & Tencent pump in another Rs 80 Cr in ed-tech unicorn Byju's

US Senator Warren vows to break up Amazon, Facebook, Google

SoftBank extends tech reach with $5B Latin American fund

Coverfox hits the market to raise $50M in new financing round

Cognizant faces US lawsuit alleging discrimination

China's Huawei sues US over federal ban on using its products

Germany's Delivery Hero acquires Zomato's UAE biz, invests in India ops

Ahead of deadline, debate rages on e-commerce policy

Flipkart rejigs reporting of Myntra-Jabong head Amar Nagaram

Grofers raises fresh funds from existing investors, valuation hits $425M

Sachin Bansal invests Rs 250 Cr each in NBFCs Altico & IndoStar: Report

I-bank Wolet files $800k suit over Flipkart’s Upstream buy

Flipkart FY18 revenue up 50%, but losses grow 5x

Pine Labs in talks to acquire Amazon-backed Qwikcilver for $100M

India can become 2nd largest 5G market in 10 years: Huawei

Alibaba rival Pinduoduo seeks to raise $1.5B

Twitter Q4 revenue grows to $909M as video ad sales surge

Mukesh Ambani to invest $1.4B in West Bengal, will help e-commerce expansion

Etail may lose Rs 40,000 crore, retail to get a 3rd of it

Steadview Capital invests $74M in Ola valuing it at around $6B

Byju’s ups revenue to Rs 490 cr in FY 18, losses drop by half

Agritech startups Sabziwala and LivLush merge their business under new entity Kamatan

Avail Finance lands $17.2M from Matrix Partners & Ola, Freecharge and Flipkart founders

RBI suggests tax sops, self-regulation to build fintech space

Swiggy hires new CEO for its Access Service, gets new CFO

Logistics company Delhivery registers 44% increase in FY17 revenues

WeWork to acquire one of the oldest social networks, Meetup

Qualcomm rejects Broadcom's $103 billion offer

EasyRewardz gets $2 million Series-A funding

'Anemic' iPhone 8 demand drags Apple shares lower

Lending platform Lenden Club gets Rs 3.5cr in Equity Investment

On festive sales, Flipkart says 65% clients from Tier-II cities