Live data from Hacker News

Google shifting to “upstream first” Linux kernel approach for Android features

phoronix.com

81–90 of 116 posts

Re: Google shifting to “upstream first” Linux kernel approach for Android features

#81
post #24

Earlier quoted context omitted.

The problem is SafetyNet uses remote attestation. And if the bank app is implemented properly that won't work because the server will check they attestation and fail your login. They very well may not bother with this though since they offer a web version anyways... which kind of makes the whole idea of putting root checking in the app pointless. Right now at least, there's no hardware attestation on many devices so…

> Right now at least, there's no hardware attestation on many devices How long do you think it will be before a country requires that all smartphones support this? And how long before it is a requirement for laptops too?

not sure about smartphones but Windows 11 will require a TPM, presumably for remote attestation

Re: Google shifting to “upstream first” Linux kernel approach for Android features

#82

Earlier quoted context omitted.

Most people with most android devices don't remotely care about this. If you do care, it is reasonable to buy a specific device.

Still, what's the point in telling someone "to vote with their wallet" instead of complaining? Why not both? Where, if not on HN, should we voice our opinion that tech is going down some path we aren't excited about? Avoiding Google/FB/Amazon/Microsoft or whatever your megacorp of choice is is becoming increasingly hard, and it absolutely deserves being talked about. As do any other things in which our choices and fr…

> but I don't think there's a way out any more.

The poster wasn't just complaining about "most phones" but claiming there was no solution.

It seems perfectly reasonable to point out that there is a solution that works at both the individual and global levels. If you want to control your own android devices, there are several good options and if more people start making those choices then the overall situation will also improve.

Re: Google shifting to “upstream first” Linux kernel approach for Android features

#83

Earlier quoted context omitted.

Most people with most android devices don't remotely care about this. If you do care, it is reasonable to buy a specific device.

Still, what's the point in telling someone "to vote with their wallet" instead of complaining? Why not both? Where, if not on HN, should we voice our opinion that tech is going down some path we aren't excited about? Avoiding Google/FB/Amazon/Microsoft or whatever your megacorp of choice is is becoming increasingly hard, and it absolutely deserves being talked about. As do any other things in which our choices and fr…

The general problem I have (personally) with these type of complaints is that there is no real way for any of these companies to act on it further. In the case of Google, they already have acted on it. It's just noise to them at this point.

If you believe something else is being snuffed out, it would help to mention what it is so people can help you. Because making that statement without context doesn't really stand alone, it's also just noise.

Re: Google shifting to “upstream first” Linux kernel approach for Android features

#84

Earlier quoted context omitted.

Still, what's the point in telling someone "to vote with their wallet" instead of complaining? Why not both? Where, if not on HN, should we voice our opinion that tech is going down some path we aren't excited about? Avoiding Google/FB/Amazon/Microsoft or whatever your megacorp of choice is is becoming increasingly hard, and it absolutely deserves being talked about. As do any other things in which our choices and fr…

The general problem I have (personally) with these type of complaints is that there is no real way for any of these companies to act on it further. In the case of Google, they already have acted on it. It's just noise to them at this point. If you believe something else is being snuffed out, it would help to mention what it is so people can help you. Because making that statement without context doesn't really stand…

>In the case of Google, they already have acted on it.

And in the case of vendors who haven't...?

Re: Google shifting to “upstream first” Linux kernel approach for Android features

#85
post #84

Earlier quoted context omitted.

The general problem I have (personally) with these type of complaints is that there is no real way for any of these companies to act on it further. In the case of Google, they already have acted on it. It's just noise to them at this point. If you believe something else is being snuffed out, it would help to mention what it is so people can help you. Because making that statement without context doesn't really stand…

>In the case of Google, they already have acted on it. And in the case of vendors who haven't...?

Which vendors are those? I could try to name some, but they might not necessarily be the ones you would come up with.

Re: Google shifting to “upstream first” Linux kernel approach for Android features

#86

This seems like the natural lifecycle. 1. There are many features that we feel very valuable to our OS, so we will implement them and ship our OS without blocking on upstream approval and acceptance. 2. Maintaining these patches is expensive. We will try to upstream as much as possible. 3. Most of our patches have been upstreamed and most new kernel requirements are lower priority, we should prefer to upstream first…

I remember Google went through much the same process with their own private server kernel fork.

Re: Google shifting to “upstream first” Linux kernel approach for Android features

#87
post #33
post #31

Earlier quoted context omitted.

Changing the root of trust doesn't mean applications can suddenly take over other applications. It also requires granting the malicious app sufficiently elevated permissions for that takeover. The user made several choices along the way. If your argument is that there's the possibility that they could make the wrong choice then this is in my opinion security theater because it posits that a thing can only be secured…

On this kind of devices the security chain of trust needs to take into consideration the same kind of users that fill their Internet Explorer with random toolbars from website popups. Not the user with a CS degree that knows what they are doing.

"Of all tyrannies, a tyranny sincerely exercised for the good of its victims may be the most oppressive." - C.S. Lewis

Freedom to do what you want with the device you purchased is a right that is not to be infringed upon, especially not for the reason "the users might hurt themselves".

Setting up a technically nontrivial flow to unlock the bootloader (e.g. connect the device to a machine with an SSH client, approve SSH connection request with scary message, SSH to the phone, execute a shell script that tells you that you shouldn't unlock this unless you know what you're doing, and after confirmation the script unlocks the bootloader) is more than enough of a deterrent for the vast majority of non-technical users.

The remainder are acceptable casualties - people who refuse to read warning labels are going to have other bad things happen to them anyway (drinking poisons, injuring themselves while working with power-tools) as a result of their foolishness, and the solution to that is not to take away the power-tools from the whole population, but to train them to read and follow warning labels in the first place.

Those technically skilled users who want to unlock their bootloaders (and, you know, do what they want with the devices they paid for) should not have to pay for the stupidity of a small minority of foolish people who refuse to read warning messages.

Re: Google shifting to “upstream first” Linux kernel approach for Android features

#88
post #30
post #18

Earlier quoted context omitted.

> With Google's eventual transition to Fuschia OS I still have yet to see even the most remotely reliable source that indicates Fuschia is actually going to replace Android. Reminds me of when people were so absolutely sure that Android and ChromeOS were going to be merged. Never happened. I really wish people would stop repeating hare brained tech blog gossip and speculation as confirmed roadmaps.

Maybe some Gerrit commits will help, https://android-review.googlesource.com/q/fuchsia Also in case you missed, Android apps now run on ChromeOS.

>Maybe some Gerrit commits will help

These commits don't show that they're replacing Linux with Fuchsia, they show that they haven't killed Fuchsia.

Re: Google shifting to “upstream first” Linux kernel approach for Android features

#89
post #81

Earlier quoted context omitted.

> Right now at least, there's no hardware attestation on many devices How long do you think it will be before a country requires that all smartphones support this? And how long before it is a requirement for laptops too?

not sure about smartphones but Windows 11 will require a TPM, presumably for remote attestation

That's a good point. Anyone who suspects that the government pressured Apple to add on-device file scanning (under the guise of "think of the children") should also conclude that making TPMs a requirement is intended to lay the groundwork for a future legislative change (presumably under the guise of "cyber-security").

Re: Google shifting to “upstream first” Linux kernel approach for Android features

#90
post #84

Earlier quoted context omitted.

>In the case of Google, they already have acted on it. And in the case of vendors who haven't...?

Which vendors are those? I could try to name some, but they might not necessarily be the ones you would come up with.

Allow me to rephrase.

You say that such complaints are just noise to Google because they have already acted on these complaints (ie, Pixel bootloaders are unlocked). On that, I think you and I agree re: pointless complaining.

I'm asking, why not continue to complain in an effort to push vendors with locked bootloaders to unlock them? Specific vendors are irrelevant, I'm just curious if you do/don't think people should complain to them, as well.

Post reply on HN