> I wouldn't say it's a solved problem. Just have to find an exploit that works with verified / attested boot
In general though on devices that are rootable, white-hat hackers are more inclined to responsibly disclose vulnerabilities instead of releasing them as a way to root said device. So having a rootable phone does increase security.
What doesn't increase security is when bank apps that are essential to daily life start detecting that a device has been rooted and force a lot of people into using closed source extensions to hide the fact that the devices is rooted.
The thing is, the whole topic is not fully binary.
I agree with you that having a rootable phone does increase security in certain ways.
> What doesn't increase security is when bank apps that are essential to daily life start detecting that a device has been rooted and force a lot of people into using closed source extensions to hide the fact that the devices is rooted.
I'll ask naively: Why not?
I can come up with a bunch of arguments why it does help the bank and why it might reduce the risk of certain attacks.
Because a lot of people will install whatever closed source magisk module or lsposed extension they can find to go around the bank jailbreak detection and end up actually weakening their security posture. Those modules are a prime target for trojan attacks.
In general though on devices that are rootable, white-hat hackers are more inclined to responsibly disclose vulnerabilities instead of releasing them as a way to root said device. So having a rootable phone does increase security.
What doesn't increase security is when bank apps that are essential to daily life start detecting that a device has been rooted and force a lot of people into using closed source extensions to hide the fact that the devices is rooted.