Live data from Hacker News

Right to root access

medhir.com

41–50 of 428 posts

Re: Right to root access

#41
post #6

Earlier quoted context omitted.

This is an extremely weak argument, and I'd like to stop seeing it perpetuated. If you don't want an unlocked bootloader, just don't unlock your bootloader. Why should we remove the ability to unlock the bootloader entirely just because some people don't want to use it?

> If you don't want an unlocked bootloader, just don't unlock your bootloader. That kind of logic cuts both ways: "If you don't want a device with a locked boot loader, just don't buy a device with a locked bootloader". Unfortunately, as consumers, we're trapped between a rock and a hard place. On the one hand, I would want 100% freedom to use my device exactly as I see fit and run any software I want, without any fo…

Those restrictions aren't on your desktop, where you do have root. Why would they be on your phone if you had root on that?

Re: Right to root access

#42
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

This is a very popular HN opinion; but not a very popular real world opinion. The average customer wants a device that works consistently, every day, that is easy to use, with a collection of 3rd party apps who won’t steal their life savings. Windows failed to deliver this; the average customer never downloads an Exe from a newer publisher without terror. The average consumer is literally dozens of times more likely…

And consumers can have that. That doesn't mean I should be unable to unlock my phone and do whatever I want with it.

Re: Right to root access

#43
post #25

I detest Google, but I do think they made the right call with Android devices and Chromebooks. You can unlock either as long as you are willing to totally wipe the device first and start over as a new device under a new security context. This removes the risk of this being abused to compromise the data of stolen devices or evil maid attacks unless a user that knows what they are doing has explicitly opted themselves…

I contacted the Google through the BBB. Made the statement that lack of ability to install and configure a Kernel level firewall, edit the HOSTS file, and remove unwanted bloat-ware reduces the security of the product. Google agreed their actions do this and said they find the lack of security acceptable. Having a firewall like Little Snitch should be acceptable to know where the phone is communicate, with whom, and how to prevent it.

Re-imaging with a rooted image is not acceptable because this also reduces the device's security by prevent OTA updates!

Gated community is broken when the end user cannot improve the security of the device above and beyond the lack polices of Google and Apple. For instant there should be no reason my device ever communicates with organizations I do not support such as Facebook or X-Twitter. X-Twitter is often used as command and control service in plain site.

It is not just out-wards communicate to monitor but in-wards too. I've used Zone Alarm in the past at an international company to help find the infected servers and computers that where serving up viruses and other malware.

*I would argue that the "Gated Community" analogy is flawed. A real world gated community still allows for the home owner to improve the security. By installing cameras, security system, and guards. Apple & Google prevent such actions.

Re: Right to root access

#44
post #25

I detest Google, but I do think they made the right call with Android devices and Chromebooks. You can unlock either as long as you are willing to totally wipe the device first and start over as a new device under a new security context. This removes the risk of this being abused to compromise the data of stolen devices or evil maid attacks unless a user that knows what they are doing has explicitly opted themselves…

Agreed, that's a good solution. I can root my phone immediately when I buy it, or I can leave it locked if that's my choice. That's the best of both worlds.

Re: Right to root access

#45
post #42

Earlier quoted context omitted.

This is a very popular HN opinion; but not a very popular real world opinion. The average customer wants a device that works consistently, every day, that is easy to use, with a collection of 3rd party apps who won’t steal their life savings. Windows failed to deliver this; the average customer never downloads an Exe from a newer publisher without terror. The average consumer is literally dozens of times more likely…

And consumers can have that. That doesn't mean I should be unable to unlock my phone and do whatever I want with it.

The problem is not the ability to unlock your phone.

The problem is that 90% of people unlocking their phones will either be for piracy (against the company’s interests), or against the customer's own interests (stalkerware, data extraction, sale of stolen devices).

There is a reason malware is over 50 times as prevalent on Android.

Re: Right to root access

#46
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

This is a very popular HN opinion; but not a very popular real world opinion. The average customer wants a device that works consistently, every day, that is easy to use, with a collection of 3rd party apps who won’t steal their life savings. Windows failed to deliver this; the average customer never downloads an Exe from a newer publisher without terror. The average consumer is literally dozens of times more likely…

The average customer wants a car that doesn't explode because you installed a sketchy spark plug. Does that mean the manufacturers should install locks on the hood of every new car, with the threat of jail time if you pick the lock and look underneath?

Re: Right to root access

#47
post #20

Earlier quoted context omitted.

As the author mentions, desktop computers have always been (mostly) unlocked. This comment is just over the top scaremongering.

Even with access controls, people do things like download chrome from random web sites, then do their banking with the result. If the fake-chrome requested admin access then you'd never be able trust anything on that computer ever again. Even re-installing the OS wouldn't fix it. It would no longer be your computer.

So because it would no longer be our computer, we should buy one that's not ours from the start?

Re: Right to root access

#48

Earlier quoted context omitted.

This is a very popular HN opinion; but not a very popular real world opinion. The average customer wants a device that works consistently, every day, that is easy to use, with a collection of 3rd party apps who won’t steal their life savings. Windows failed to deliver this; the average customer never downloads an Exe from a newer publisher without terror. The average consumer is literally dozens of times more likely…

The average customer wants a car that doesn't explode because you installed a sketchy spark plug. Does that mean the manufacturers should install locks on the hood of every new car, with the threat of jail time if you pick the lock and look underneath?

A sketchy spark plug does not have the ability to make a car explode, so the analogy is pointless.

On that note, even if someone stole your car, at least your car does not have access to your bank account, your passwords, your messages, and even your sexual history. The personal and reputational cost of losing a car is not comparable.

Many people would actually probably prefer their car to be stolen than the contents of their phone be public.

I think a more accurate comparison would be to an electrician. In Australia, doing your own electrical work is a crime even for the homeowner, because it can cause physical death, and is too likely to be done wrong. Yes, you will possibly go to jail for replacing $2 light switches. I assure you that most people’s phones have things they would prefer physical death over being publicly distributed.

Re: Right to root access

#49
post #6

Earlier quoted context omitted.

This is an extremely weak argument, and I'd like to stop seeing it perpetuated. If you don't want an unlocked bootloader, just don't unlock your bootloader. Why should we remove the ability to unlock the bootloader entirely just because some people don't want to use it?

> If you don't want an unlocked bootloader, just don't unlock your bootloader. That kind of logic cuts both ways: "If you don't want a device with a locked boot loader, just don't buy a device with a locked bootloader". Unfortunately, as consumers, we're trapped between a rock and a hard place. On the one hand, I would want 100% freedom to use my device exactly as I see fit and run any software I want, without any fo…

> I am happy my iPhone doesn't allow Meta to say "to use WhatsApp, you must install the MetaStore®, give it root and install it from there".

I think the inverse is a much more credible threat, though. "Sorry, you cant sign in to your bank because you are using Linux. Please try again on windows 11 with secure boot turned on" doesn't seem far fetched at all.

Re: Right to root access

#50
post #28
post #3

Earlier quoted context omitted.

That is absolutely not what the author is saying here, just that users should have the ability to install their own software on their own hardware, and that locked bootloaders and the like should not be allowed.

Yes, that is exactly what the author is saying, wanting government regulation. For one, the government won't simply say "keep the device open for the end user" (or a "smart" government wouldn't), but even if they did, you've now opened that device to any attacker, law enforcement included.

So because I can sudo on my computer, my computer is open to any attacker? What's wrong with this comments section? Has anyone here used a computer before?
Post reply on HN