Live data from Hacker News

Right to root access

medhir.com

51–60 of 428 posts

Re: Right to root access

#51
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

This is a very popular HN opinion; but not a very popular real world opinion. The average customer wants a device that works consistently, every day, that is easy to use, with a collection of 3rd party apps who won’t steal their life savings. Windows failed to deliver this; the average customer never downloads an Exe from a newer publisher without terror. The average consumer is literally dozens of times more likely…

> with a collection of 3rd party apps who won’t steal their life savings.

This is blatant unempirical scare mongering. How many desktop computer users have had their life savings stolen by 3rd party apps? Citation needed.

> The average consumer is literally dozens of times more likely to trust a new smartphone app than a new desktop app.

This is a false dichotomy. Almost all desktop computer users have a smartphone too. The people who have enough disposable income buy both smartphones and desktop computers. There's no inherent conflict between the two.

> the locked down console market will be with us forever because even Windows can’t deliver a simple experience that reliably works.

That's a competely ahistorical interpretation. Originally, the gaming consoles had no third-party games: the games were all written by the vendors. The first third-party game development company was Activision, a group of former Atari programmers who learned that their games were responsible for most of Atari's revenue, but Atari refused to give them a cut, so they left and formed their own company. There was a lawsuit, and it was ultimately settled, allowing Atari to get a cut of Activision while allowing Activision to otherwise continue developing console games. It had nothing to do with "reliablity" or "security" or any kind of made-up excuse like that.

Re: Right to root access

#52
post #30

not sure if your in the US, but we can't even get net neutrality. Unfortuantely the likelyhood of this is a hell freezing over situation. I would start with, laws should be logical and informed and go from there... the number of prerequisite changes required to come mildly close to this is unreal. Including but not limited too: copyright law, insurance law, patents, contract law, federal vs state law, an agency compe…

California is typically pro consumer, tenant, employee. If it could be passed in California it would trickle down elsewhere. e.g. California emissions mandates leading to less emissions in the entire country because it makes more sense at scale to build 1 SKU.

I agree states can more quickly change laws, but thats a far cry from what's proposed here. Can you imagine enforcement of such a law? Can you imagine a state employee checking for root access? You break at least five California laws an hour there just walking around as the beauracratic machine consumes any reasonable enforcement. This would be considered absolutely niche and no politician would likely care because it wont get them reelected. Call me cynical I guess but our track record of change for the better is pretty poor in this arena.

In my dream we abolish copyright all together but alas we live in a profit oriented society not a knowledge oriented one.

Re: Right to root access

#53
post #39
post #14

Earlier quoted context omitted.

Because the fact that it can't be unlocked makes me reasonably reassured that I can trust the software running on it comes from the vendor of the device It's the same reason I don't want "the good guys" to have decryption keys to my messaging service, because even if I did trust the FBI, the fact that there is a backdoor at all means it could be exploited by someone I don't trust Again, if you don't want to use a dev…

Yeah, this is just a fundamental misunderstanding of how bootloader unlocking works. The people repeating this argument seem to think that their bootloader will unlock if they look at their phone wrong, when in reality the bootloader unlock process can be made such that the user must consent. If some malware can bypass that, then it could bypass your bootloader in the first place.

It's not just about malware you might accidentally download, it's also about adversaries that may have physical access to your device and can provide that consent

No matter how convoluted you make the rube goldberg machine to bypass the cryptography, if there's a way to bypass it it will be bypassed

Re: Right to root access

#54
post #42

Earlier quoted context omitted.

And consumers can have that. That doesn't mean I should be unable to unlock my phone and do whatever I want with it.

The problem is not the ability to unlock your phone. The problem is that 90% of people unlocking their phones will either be for piracy (against the company’s interests), or against the customer's own interests (stalkerware, data extraction, sale of stolen devices). There is a reason malware is over 50 times as prevalent on Android.

Why do I give a shit about the company? I bought the phone, it's mine, I should be able to unlock it. If I catch malware, I'm an adult and I'll live with my choices.

> There is a reason malware is over 50 times as prevalent on Android.

What's the reason for that bogus-sounding statistic?

Re: Right to root access

#55
post #51

Earlier quoted context omitted.

This is a very popular HN opinion; but not a very popular real world opinion. The average customer wants a device that works consistently, every day, that is easy to use, with a collection of 3rd party apps who won’t steal their life savings. Windows failed to deliver this; the average customer never downloads an Exe from a newer publisher without terror. The average consumer is literally dozens of times more likely…

> with a collection of 3rd party apps who won’t steal their life savings. This is blatant unempirical scare mongering. How many desktop computer users have had their life savings stolen by 3rd party apps? Citation needed. > The average consumer is literally dozens of times more likely to trust a new smartphone app than a new desktop app. This is a false dichotomy. Almost all desktop computer users have a smartphone t…

[flagged]

Re: Right to root access

#56

Earlier quoted context omitted.

The average customer wants a car that doesn't explode because you installed a sketchy spark plug. Does that mean the manufacturers should install locks on the hood of every new car, with the threat of jail time if you pick the lock and look underneath?

A sketchy spark plug does not have the ability to make a car explode, so the analogy is pointless. On that note, even if someone stole your car, at least your car does not have access to your bank account, your passwords, your messages, and even your sexual history. The personal and reputational cost of losing a car is not comparable. Many people would actually probably prefer their car to be stolen than the contents…

> On that note, even if someone stole your car, at least your car does not have access to your bank account, your passwords, your messages, and even your sexual history. The personal and reputational cost of losing a car is not comparable.

You're conflating vendor lockdown with device encryption. The latter does not require the former.

Re: Right to root access

#57
post #53
post #39

Earlier quoted context omitted.

Yeah, this is just a fundamental misunderstanding of how bootloader unlocking works. The people repeating this argument seem to think that their bootloader will unlock if they look at their phone wrong, when in reality the bootloader unlock process can be made such that the user must consent. If some malware can bypass that, then it could bypass your bootloader in the first place.

It's not just about malware you might accidentally download, it's also about adversaries that may have physical access to your device and can provide that consent No matter how convoluted you make the rube goldberg machine to bypass the cryptography, if there's a way to bypass it it will be bypassed

Please detail this attack vector where someone can compromise a phone with an unlockable bootloader but not one you can't unlock.

Re: Right to root access

#58
post #47

Earlier quoted context omitted.

Even with access controls, people do things like download chrome from random web sites, then do their banking with the result. If the fake-chrome requested admin access then you'd never be able trust anything on that computer ever again. Even re-installing the OS wouldn't fix it. It would no longer be your computer.

So because it would no longer be our computer, we should buy one that's not ours from the start?

I guess, pretty much. For the vast majority of computer users, all we can do is buy it from someone we mostly trust (to be competent and trustworthy).

Pretty sad state of affairs, huh?

Re: Right to root access

#59

I used to think this way but then I saw how non-techy people use their devices. Something like this would inevitably be abused and result in wave of malware so massive that it would render the internet too hostile for all but the most careful, knowledgable and paranoid users.

"everyone is too stupid to be trusted with general purpose computers" is a pretty grim position to hold

A grim position that is completely accurate for over 90% of people.

Re: Right to root access

#60
Every time this issue comes up, an army of people who've never unlocked a phone comes out of the woodwork to talk about their theoretical fears of malware and piracy and rain falling from the sky if you dare to own your device.

If you've never unlocked a phone, please educate yourself on how the process works before opining. It's really not as terrifying as you imagine.

Post reply on HN