Itsme not working

Search This thread

Timmmmaaahh!

Sr. Mod / Mod Cmte / Recognized Xmas Avatar Themer
Staff member
Sep 11, 2012
6,148
1
16,134
Bruges
OnePlus One
OnePlus 6T
It's in the playstore app : on the Itsme page, select the 3 dots "..." and uncheck "automatic updates". This setting is per package, but I don't know if istme will be forced if I select "update all"
When any installed app on your device has auto update disabled in the Play Store, and you tap 'update all', it will ask you every time for each such app if you want to update it anyway. Play Store is very persistent about updating apps and at some point it will even update (or trick you into updating) these apps, regardless of your settings. It's notoriously known for re-enabling the auto update setting of individual apps after some time. There's more rigorous ways of preventing this, like with TeMeFi, but these are quite destructive so use these at your own risk. It's safer and easier to just revert to an older version using something like TitaniumBackup.
 

oniemjan

Senior Member
Feb 16, 2012
516
102
When any installed app on your device has auto update disabled in the Play Store, and you tap 'update all', it will ask you every time for each such app if you want to update it anyway. Play Store is very persistent about updating apps and at some point it will even update (or trick you into updating) these apps, regardless of your settings. It's notoriously known for re-enabling the auto update setting of individual apps after some time. There's more rigorous ways of preventing this, like with TeMeFi, but these are quite destructive so use these at your own risk. It's safer and easier to just revert to an older version using something like TitaniumBackup.
i'm using mindetach to prevent updating. No issues so far...
 

onimorza

Senior Member
May 14, 2010
336
120
Mechelen
Xiaomi Mi A2
OnePlus Nord
When any installed app on your device has auto update disabled in the Play Store, and you tap 'update all', it will ask you every time for each such app if you want to update it anyway. Play Store is very persistent about updating apps and at some point it will even update (or trick you into updating) these apps, regardless of your settings. It's notoriously known for re-enabling the auto update setting of individual apps after some time. There's more rigorous ways of preventing this, like with TeMeFi, but these are quite destructive so use these at your own risk. It's safer and easier to just revert to an older version using something like TitaniumBackup.
You can also use HMA to hide itsme from playstore
 
  • Like
Reactions: Timmmmaaahh!

onimorza

Senior Member
May 14, 2010
336
120
Mechelen
Xiaomi Mi A2
OnePlus Nord
I can only find a VPN app under that name, is it that?
No, it's the one @oniemjan has mentioned above this post.
Please note that you need lsposed for this to work. You could say that HMA is an lsposed module, and lsposed is a magisk module.
Do some research on xda prior to diving into this. Read different tutorials up front.
There is also a very good and recent HMA tutorial here on xda on how to configure it.
I use HMA to hide amongst other apps: itsme, youtube and youtube music from the play store (the youtube's are because they've been altered by revanced).
If you look up those hidden aps in the play store, they'll appear as not yet installed, so the button asks you to install. Logically, you should never click on it ;)
 
  • Like
Reactions: Bubble-be

dewingerd

Senior Member
Jun 1, 2014
72
28
All versions of Itsme work perfect for me with Magisk Delta Canary .


Make sure that zygisk is disabled, the magisk app is hidden and that Magisk hide is active. Then add all necessary apps to denylist.

Make sure to add following apps to denylist :

Carrier Services

Google play

Google Play Store

Google Play- services

Google Services Framework

and of course Itsme and all the other apps you want to hide root and magisk from.

Itsme, Payconiq, Belfius, KBC,.... all work.

No need for CTS module.
No need for Shamiko. ( Shamiko does not work with Magisk Delta Canary)
 
Last edited:
  • Like
Reactions: Bubble-be

bobfrantic

Senior Member
All versions of Itsme work perfect for me with Magisk Delta Canary .


Make sure that zygisk is disabled, the magisk app is hidden and that Magisk hide is active. Then add all necessary apps to denylist.

Make sure to add following apps to denylist :

Carrier Services

Google play

Google Play Store

Google Play- services

Google Services Framework

and of course Itsme and all the other apps you want to hide root and magisk from.

Itsme, Payconiq, Belfius, KBC,.... all work.

No need for CTS module.
No need for Shamiko. ( Shamiko does not work with Magisk Delta Canary)
did all that and banking apps are ok, its me 3.12 still sees root.

Edit: Installed the Debug version of Magisk Delta and hid magisk and used magisk hide to work with banking app and its me and its me worked this time. I didn't hide any of the other apps you listed btw....
 
Last edited:
  • Like
Reactions: Timmmmaaahh!

Pandoriaantje

Member
Dec 25, 2009
36
23
Samsung Galaxy S10+
Is there a specific reason you need to pass safetynet, like Google Pay or something?
I believe a lot of apps use that as a basic tool/framework/API to detect a modified/rooted systen. It is imperative to pass safetynet and google play (store) protect certification (playstore settings/About/Play Protection certification) as wel as 'phone status' "official" under stettings/about phone/status information. Another trap could be developer options/USB debugging.

Other then that, apps can use custom code to detect (as they see fit) unwanted apps. And therein usually lies the cat and mouse game.
 
Last edited:

Bubble-be

Senior Member
I have seen the USB debugging warning, but I have not encountered anything that trips over Safetynet other than Google Pay, which I don't use. So I don't feel it is imperative as you state. It keeps things a lot simpler because there's fewer running parts to keep track of.
 
  • Like
Reactions: Timmmmaaahh!

Pandoriaantje

Member
Dec 25, 2009
36
23
Samsung Galaxy S10+
I have seen the USB debugging warning, but I have not encountered anything that trips over Safetynet other than Google Pay, which I don't use. So I don't feel it is imperative as you state. It keeps things a lot simpler because there's fewer running parts to keep track of.
It is a API/framework that can be implemented in any app, to do basic systen integrity attestation. So it could be a first line of defence in any app. So i'dd say it does help in some cases, depending on the app and if it uses the API.

But, I also found this:
In order to call the methods of the SafetyNet Attestation API, you must use an API key. Because the SafetyNet Attestation API is deprecated, new keys are only granted for exceptional cases.
Source: https://developer.android.com/training/safetynet/attestation

So it might indeed not be that 'imperative' anymore?

But it surely doesnt hurt, that's a fact. I always found it good practice to make sure safetynet passes.
 

dewingerd

Senior Member
Jun 1, 2014
72
28
Also important if not passing safetyNet Attestation : You also won't be able to install some streaming services like Netflix, (if you already installed Netflix your quality will be limited to 480p) since they don't want you to possible download their content on modified devices
 

plekszy

New member
May 9, 2011
4
6
I would like to report about my personal experience:
  • Phone: Google Pixel 6 Pro
  • OS. Android 13 (TQ1A.230105.002)
  • Rooted, with Magisk Delta Canary latest version (a8bbf631)
  • Zygisk not enabled
  • MagiskHide enabled
  • In MagiskHide all of the apps below, and anything else which looks necessary
  • No modules installed
  • Magisk Delta hidden

Working:
  • ItsMe version 3.12.0
  • Microsoft Authenticator
  • Google Authenticator
  • Keytrade Bank
  • BNP Paribas Fortis Easy Banking
  • AusweisApp2
  • Commerzbank photoTAN
  • SpardaSecureApp
  • And many others where I am not certain whether anything special needs to be done, but which I added to the Deny List just in case

Not working:
  • Google Wallet
  • Microsoft Outlook via Company Portal

Google Wallet used to work with the Universal Safety Net Fix. For that, Zygisk needs to be enabled, but then ItsMe doesn’t work.

Microsoft Outlook via Company Portal never worked reliably, whatever I tried.
 

Top Liked Posts

  • There are no posts matching your filters.
  • 7
    Let's hope that this will not only be so for the beta version, and that the release version doesn't re-introduce root check...
    I wouldn't count on it. As far as i've concluded in trying to disassemble the app (as a total beginner) they use a 3rd party root check (and possibly obfuscation) API (see my previous post). My guess is that this beta still includes an older version. So we just got lucky...

    I've also uploaded it to apkmirror for whoever doesn't trust some random guy posting APK files on the forum (they didn't have itmse on there yet, but they approved my submission, and also posted the 3.12.1 version)

    4
    I've started going down another path, by looking into patching the app itself. see where the version check is happening (the strings are easily found), maybe even just changing versionCode/versionname in the AndroidManifest.xml. or maybe just patching the root checks... Not sure yet. I did find out APKTool is having a hard time with it though... not sure whats going on there.. 🧐

    *edit:
    From what i've gathered going through the code, it references com.gemalto.idp.mobile.core.root, which seems to be part of Ezio Mobile SDK So there might be some obfuscation going on also...
    3
    Just a little heads up in case anyone got their hands on Magisk ff648628-delta, dont use it. You may want to read this.
    3
    I'm currently able to get both itsme and Belfius mobile working as intended with the following setup:

    Magisk Delta Canary cb580e75-delta(25210) with:
    • MagiskHide
    • Enforce SuList
    • Zygisk
    • New Zygisk loader
    • Bootloop Protection
    • Universal SafetyNet Fix (2.4.0) module

    itsme version is beta 4.0.0, tested working on various "official" websites.

    Zygisk and Universal SafetyNet Fix are not strictly necessary, but without them Belfius mobile won't let you use the fingerprint reader to log in or sign operations.
    On a side note, non-beta (i.e. 3.12.1) itsme does detect Zygisk even with the "New Zygisk loader" option enabled 😔
    2
    See screenshots attached. The amount of hidden apps/services is probably overkill but didn't feel like performing much trial & error. Google Services Framework doesn't appear to be selected but it is, it's just a visual bug. Canary + no Zygisk indeed and just a module for call recording and some for aesthetics. Plain and simple, really.
    I use "Enforce SuList" under Magisk Hide settings. After rebooting you can configure SuList and only add those apps to the list that are allowed to see root. You don't have to worry about adding apps and services to the hidelist. With hidelist magisk is mounted for the whole system and you hide it by adding apps and services to the hidelist.
    When using SuList magisk is only mounted to apps and modules that need it. So in my opinion it is much more clean and efficient.
    You can always revert back to Hidelist by disabeling SuList and reboot.
    (Magisk keeps the configurations of both lists)
  • 7
    Let's hope that this will not only be so for the beta version, and that the release version doesn't re-introduce root check...
    I wouldn't count on it. As far as i've concluded in trying to disassemble the app (as a total beginner) they use a 3rd party root check (and possibly obfuscation) API (see my previous post). My guess is that this beta still includes an older version. So we just got lucky...

    I've also uploaded it to apkmirror for whoever doesn't trust some random guy posting APK files on the forum (they didn't have itmse on there yet, but they approved my submission, and also posted the 3.12.1 version)

    7
    Any suggestions on how to get the latest itsme working (identity from gouvernance BE). Magisk was renamed and the app is added on the denylist.

    For Keytrade bank I have to freeze magisk to get this app working.


    Hey all!

    This has been brought up before here and I'm in the same boat as you guys: itsme is throwing "Rooted device detected" while KeyTrade, Payconiq etc. is working just fine. Please do provide technical details in order to speed up the process of solving this.

    My setup:
    • Magisk 34b2f525 (24316), Zygisk: Yes, Ramdisk: Yes
    • Magisk App: 34b2f525 (24316) (31), hidden as 'MagicalUnicorn'
    • DenyList configured and hiding itsme but also Google Play services & Play Store
    • LSPosed Zygisk 1.8.3 (6552) - Parasitic manager (app isn't installed)
      • SudoHide is hiding 'Hide My Applist', 'MagicalUnicorn', 'SudoHide' & 'XPrivacyLua' from 'Android System', itsme, etc.
      • Hide My Applist V2.3.2 is basically doing more of the same
      • XPrivacyLua 1.30 enables 'Force stop automatically' on 'Use tracking' for itsme & Keytrade
    Yet Applist Detector V1.3.2 still detects the following:
    • abnormal environment
      • XPrivacyLua (Suspicious)
    • libc file detection
      • org.lsposed.manager (Found)
    • syscall file detection
      • org.lsposed.manager (Found)
    So I'm guessing itsme is tripping over LSPosed's parasitic manager and haven't found how to circumvent this. Where is it detecting this package name?

    Same here... Hoping somebody finds a way
    Itsme detects zygisk ( ONLY ) , follow the few steps below to get it worked properly ( tested on the latest Itsme v3.8.1 ) :

    1- Install Magisk alpha. Link
    2- Keep Zygisk DISABLED & Enable MagiskHide.
    3- Add Itsme to the Configure DenyList and DONE.


    Note:
    1. Don't use Magisk Canary ( because you can't configure Denylist if you keep Zygisk disabled )
    2- No need to add Itsme as effective app in HMA or using ANY additional apps ( sudohide, XPrivacyLua, ...etc ).
    6
    what does shamiko do? and since i see you have it activated: what effect has the systemless hosts setting?

    however, I just realised that the kbc app isn't working anymore. sigh.
    Can confirm @citroene's report that latest Itsme can be made to work easily:
    • Stock magisk (v25201 installed)
    • Zygisk enabled
    • Universal SafetyNet Fix by kdrag0n (v2.3.1 installed)
    • Shamiko by LSPosed Developers (v0.5.2 installed)
    • Magisk app hidden
    • Magisk Enforce Denylist option disabled to allow Shamiko to work
    Itsme, KBC, and other banking apps working. Rootbeer doesn't see anything. Fingers crossed.
    6
    Good news, itsme works with the last version of shamiko, i have official magisk 25.2 installed.
    Screenshot_20220726-091017_Settings.jpg
    Screenshot_20220726-091006_itsme.jpg
    Screenshot_20220726-090920.jpg
    Screenshot_20220726-090858.jpg
    4
    I would like to report about my personal experience:
    • Phone: Google Pixel 6 Pro
    • OS. Android 13 (TQ1A.230105.002)
    • Rooted, with Magisk Delta Canary latest version (a8bbf631)
    • Zygisk not enabled
    • MagiskHide enabled
    • In MagiskHide all of the apps below, and anything else which looks necessary
    • No modules installed
    • Magisk Delta hidden

    Working:
    • ItsMe version 3.12.0
    • Microsoft Authenticator
    • Google Authenticator
    • Keytrade Bank
    • BNP Paribas Fortis Easy Banking
    • AusweisApp2
    • Commerzbank photoTAN
    • SpardaSecureApp
    • And many others where I am not certain whether anything special needs to be done, but which I added to the Deny List just in case

    Not working:
    • Google Wallet
    • Microsoft Outlook via Company Portal

    Google Wallet used to work with the Universal Safety Net Fix. For that, Zygisk needs to be enabled, but then ItsMe doesn’t work.

    Microsoft Outlook via Company Portal never worked reliably, whatever I tried.