yourTimecard

Jailbroken & rooted phones

On our security page we say there is no known way for anyone to sign in as you without physically holding your unlocked device. That is true — but it rests on your phone doing its part. This page explains the one situation where it doesn't.

What jailbreaking and rooting are

Phones ship locked down. Apple and Google decide what software may run, and each app is sealed into its own sandbox — a private area that other apps cannot reach into. Jailbreaking (on iPhone) and rooting (on Android) are ways of deliberately removing those restrictions to gain full control of the device.

People do it for understandable reasons: installing apps from outside the official stores, deep customisation, keeping an old phone running past its support window, or development and research. It is not inherently malicious, and on your own hardware it is your choice to make.

What it removes

The trouble is that the sandbox is not a nuisance to be worked around — it is the thing keeping other software out of yourTimecard's private area. Once it is off:

Why that matters here specifically

yourTimecard's whole security model is that the private key never leaves your device. There is no password to steal from us, because the secret lives with you. The flip side is that the protection is only as good as the place it's kept. On a jailbroken or rooted phone, malicious software may be able to copy that key — and a copy of the key is the one thing that would let someone act as your device without ever touching it.

This isn't unique to us. It is equally true of passkeys, banking apps, password managers and two-factor apps: they all assume the operating system's protections are intact.

Keeping it simple

On a normal phone, someone would need your device in their hands and unlocked. On a jailbroken or rooted phone, that is no longer something we can promise.

What to do

Questions, or something you'd like us to look at? yourTimecard@liquidsteam.com.