SecurID 4.0 for iOS and Android App Does Not Support Jailbroken or Rooted Devices
2 years ago
Originally Published: 2021-11-22

December 8, 2021

To ensure that your users will be ready to use the SecurID 4.0 for iOS and Android app, make sure your users know that the app does not support devices that are jailbroken or rooted. This situation occurs when the user gains root access to the device operating system to allow installation of unsupported applications or make other unsupported modifications to the device. Jailbreaking or rooting a device bypasses the protections put in place by the operating system and provides a malicious actor with greater access to attack the SecurID app and its security features.

The SecurID 4.0 app protects your organization by automatically disabling itself on jailbroken or rooted devices. This important security feature follows best practices for secure software app deployment and maintains the security posture of the device by limiting malicious actors who might try to attack the device. 

Attempting to install the SecurID app on a jailbroken or rooted device has the following impact.

User ScenarioConsequences  
User installed the SecurID 3.0 app on a jailbroken or rooted device.The app displays a message warning that the device is jailbroken or rooted, but allows installation.
SecurID 3.0 user on a jailbroken or rooted device upgrading to SecurID 4.0.User cannot open the app.
User with SecurID 4.0 already installed subsequently jailbreaks or roots the device.The app automatically becomes disabled and the user cannot authenticate.


You can help users understand that securing their devices is important to ensure the confidentiality, integrity, and availability of company assets. Instruct users to update their devices to an authorized (pre-jailbroken) state before they download the app.

For your reference, here are some of the links to published advisories and documents where we highly recommend not running apps on jailbroken or rooted devices:

Users who attempt to install software on a jailbroken or rooted device will see the following app behavior.

GeorgeSpagnoli_1-1638893814680.png

RSA Authenticate app
(Since January 2020)

Warns that the device is not compliant and prevents installation.

GeorgeSpagnoli_5-1638895118866.jpeg

GeorgeSpagnoli_4-1638894623622.png

SecurID 3.0 app
(Since June 2021)

Displays a warning message. Provides time to prepare for the upcoming SecurID 4.0 app which prevents installation on jailbroken or rooted devices.

GeorgeSpagnoli_6-1638895147249.jpeg

GeorgeSpagnoli_3-1638894560914.png

Upcoming SecurID 4.0 app
(Expected in January 2022)

Warns that the device is not compliant and prevents installation.

GeorgeSpagnoli_7-1638895169948.jpeg

 

Announcement