Live data from Hacker News

Right to root access

medhir.com

61–70 of 428 posts

Re: Right to root access

#61
post #53
post #39

Earlier quoted context omitted.

Yeah, this is just a fundamental misunderstanding of how bootloader unlocking works. The people repeating this argument seem to think that their bootloader will unlock if they look at their phone wrong, when in reality the bootloader unlock process can be made such that the user must consent. If some malware can bypass that, then it could bypass your bootloader in the first place.

It's not just about malware you might accidentally download, it's also about adversaries that may have physical access to your device and can provide that consent No matter how convoluted you make the rube goldberg machine to bypass the cryptography, if there's a way to bypass it it will be bypassed

Every device I've ever unlocked warns you on boot that it's unlocked. So if that's your threat model, just reboot the phone after the maid hands it back to you and see if you get a scary warning.

Re: Right to root access

#62
post #47

Earlier quoted context omitted.

So because it would no longer be our computer, we should buy one that's not ours from the start?

I guess, pretty much. For the vast majority of computer users, all we can do is buy it from someone we mostly trust (to be competent and trustworthy). Pretty sad state of affairs, huh?

No, I don't think that's true. We got used to insecure systems, and then accepted Big Brother as a security model. We can have secure devices that aren't owned by a corporation, but judging by the comments section here, nobody knows that.

Re: Right to root access

#63
post #35
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

There's a difference between being able to buy something dangerous and being forced to do so

Forced? I'm not sure I understand.

My guess is that you're assuming, wrongly, that vendor locked devices are "safe" and unlocked devices are "unsafe".

All computers that are connected to the internet are unsafe in some ways. The most dangerous apps on your computer are the vendor's own built-in web browser and messaging app.

Also, the vendor-controlled software stores are unsafe cesspools. You will never find a more wretched hive of scum and villainy. Moreover, the vendors deliberately make it impossible for you to protect yourself. For example, iOS makes it difficult or impossible to inspect the file system directly, and you can't install software such as Little Snitch on iOS that stops 3rd party apps—as well as 1st party apps!—from phoning home.

In any case, most computers, including Apple computers, have parental controls and the like, so you can lock down your own device to your heart's content if you don't trust yourself, or you don't trust the family member that you're gifting the device.

Re: Right to root access

#64
post #51

Earlier quoted context omitted.

> with a collection of 3rd party apps who won’t steal their life savings. This is blatant unempirical scare mongering. How many desktop computer users have had their life savings stolen by 3rd party apps? Citation needed. > The average consumer is literally dozens of times more likely to trust a new smartphone app than a new desktop app. This is a false dichotomy. Almost all desktop computer users have a smartphone t…

[flagged]

> You’re kidding, right? You seem to have completely forgotten, or put the drunk glasses, on what living in the 2000s was like.

Again, citation needed. I made it through the 2000s just fine, thank you.

> What a stereotypical HN comment. Cite something that only applied to the 2nd generation of consoles to prove me wrong, even though my point spans almost all console generations.

No, I was explaining the historical origin of the game console business model. Of course the business model continued, as these things usually do, through a combination of monetary incentives and inertia.

Re: Right to root access

#65
post #27

I used to think this way but then I saw how non-techy people use their devices. Something like this would inevitably be abused and result in wave of malware so massive that it would render the internet too hostile for all but the most careful, knowledgable and paranoid users.

Stupidest take I've seen today. There are already myriad unlockable devices. What a bizarre fantasy you have constructed.

Let me clarify .. if you have an unlocked device, then software vendors should be able to ensure that their software is non-functional on such a device.

Given that, then anything very useful would be rendered non-functional, resulting in the device probably being useless.

Re: Right to root access

#66
post #64

Earlier quoted context omitted.

[flagged]

> You’re kidding, right? You seem to have completely forgotten, or put the drunk glasses, on what living in the 2000s was like. Again, citation needed. I made it through the 2000s just fine, thank you. > What a stereotypical HN comment. Cite something that only applied to the 2nd generation of consoles to prove me wrong, even though my point spans almost all console generations. No, I was explaining the historical or…

Of course. As we all know here, any business that gets started will go on forever regardless of market fit.

Re: Right to root access

#67
post #62

Earlier quoted context omitted.

I guess, pretty much. For the vast majority of computer users, all we can do is buy it from someone we mostly trust (to be competent and trustworthy). Pretty sad state of affairs, huh?

No, I don't think that's true. We got used to insecure systems, and then accepted Big Brother as a security model. We can have secure devices that aren't owned by a corporation, but judging by the comments section here, nobody knows that.

How might that work? You personally have the keys to the TPM? Then some confidence trickster will tell a naive user that to make big$buck$ on the internet you'll need to handover your TPM key. And people will.

Re: Right to root access

#68
post #38

Earlier quoted context omitted.

Phones with unlockable bootloaders aren't going to be sold for much longer just like dumb TVs aren't sold anymore. There's just too much profit to be earned by corporations locking devices, plus banks and governments want to lock down phones. And once they lock down phones they'll go for desktops as well.

Dumb TVs are still sold, they just cost more. Same will probably be true for the low volume, no-stolen-data (or no-apple-tax) unlockable phones, too

Maybe in the US, but not in my country. I tried looking for "signage displays" but all I could find was Samsung professional monitors that still had the smart stuff

Re: Right to root access

#69
post #6

Earlier quoted context omitted.

This is an extremely weak argument, and I'd like to stop seeing it perpetuated. If you don't want an unlocked bootloader, just don't unlock your bootloader. Why should we remove the ability to unlock the bootloader entirely just because some people don't want to use it?

> If you don't want an unlocked bootloader, just don't unlock your bootloader. That kind of logic cuts both ways: "If you don't want a device with a locked boot loader, just don't buy a device with a locked bootloader". Unfortunately, as consumers, we're trapped between a rock and a hard place. On the one hand, I would want 100% freedom to use my device exactly as I see fit and run any software I want, without any fo…

> I am happy my iPhone doesn't allow Meta to say "to use WhatsApp, you must install the MetaStore®, give it root and install it from there". I would not be happy with those restrictions on my desktop.

You fix that by making root access inconvenient enough that companies can't rely on the average random user having it enabled.

For example force you to wipe the device to unlock it as another person said in another comment. Or make it so that if you don't unlock it within 7 days of the device purchase and first boot, you cannot unlock it anymore.

Re: Right to root access

#70
post #25

I detest Google, but I do think they made the right call with Android devices and Chromebooks. You can unlock either as long as you are willing to totally wipe the device first and start over as a new device under a new security context. This removes the risk of this being abused to compromise the data of stolen devices or evil maid attacks unless a user that knows what they are doing has explicitly opted themselves…

This, or even sell "dev units" with the bootloader unlocked so that you explicitly have to accept the risk before purchasing the device. The problem though is that rooting by itself is not that useful when a lot of apps use remote attestation to deny you service if you're rooted. We don't just need root access, we need undetectable root access.

> We don't just need root access, we need undetectable root access.

At some point the argument morphs from 'I should be able to do whatever I want with my device' to 'I should be able to access your service/device with whatever I want'.

The fact that Google allows this shows that

1. Apple could do it with zero security impact on anyone who doesn't opt in

2. They could keep any service-based profit source intact

But they still would never do it. Because it's not only service based profit they want to protect. They want to restrict customers from running competitor's software on their hardware, to ensure they get their cut.

Post reply on HN