On our security page we say there is no known way for anyone to sign in as you without physically holding your unlocked device. That is true — but it rests on your phone doing its part. This page explains the one situation where it doesn't.
What jailbreaking and rooting are
Phones ship locked down. Apple and Google decide what software may run, and each app is sealed into its own sandbox — a private area that other apps cannot reach into. Jailbreaking (on iPhone) and rooting (on Android) are ways of deliberately removing those restrictions to gain full control of the device.
People do it for understandable reasons: installing apps from outside the official stores, deep customisation, keeping an old phone running past its support window, or development and research. It is not inherently malicious, and on your own hardware it is your choice to make.
What it removes
The trouble is that the sandbox is not a nuisance to be worked around — it is the thing keeping other software out of yourTimecard's private area. Once it is off:
- Other apps can potentially read this app's data, including the keychain entry holding the private key that identifies your device.
- The guarantee that only trusted software is running is gone. Anything installed from an unofficial source has not been through Apple's or Google's review, and some of it is malicious precisely because jailbroken phones are a soft target.
- Security updates often stop. Jailbreaks are usually tied to a specific version, so staying jailbroken frequently means staying on old software with known, published holes in it.
Why that matters here specifically
yourTimecard's whole security model is that the private key never leaves your device. There is no password to steal from us, because the secret lives with you. The flip side is that the protection is only as good as the place it's kept. On a jailbroken or rooted phone, malicious software may be able to copy that key — and a copy of the key is the one thing that would let someone act as your device without ever touching it.
This isn't unique to us. It is equally true of passkeys, banking apps, password managers and two-factor apps: they all assume the operating system's protections are intact.
Keeping it simple
On a normal phone, someone would need your device in their hands and unlocked. On a jailbroken or rooted phone, that is no longer something we can promise.
What to do
- Don't pair yourTimecard on a jailbroken or rooted phone, especially one you didn't set up yourself.
- If a paired phone has since been jailbroken or rooted, ask your manager to unpair that device and issue a fresh invite once you are on a standard phone. Removing the device ends its access immediately.
- Keep your phone updated. Most of what a jailbreak exploits are holes the manufacturer has already fixed.
- If you're unsure whether a work phone has been modified, ask whoever supplied it.
Questions, or something you'd like us to look at? yourTimecard@liquidsteam.com.