Live data from Hacker News

Right to root access

medhir.com

71–80 of 428 posts

Re: Right to root access

#71
post #64

Earlier quoted context omitted.

> You’re kidding, right? You seem to have completely forgotten, or put the drunk glasses, on what living in the 2000s was like. Again, citation needed. I made it through the 2000s just fine, thank you. > What a stereotypical HN comment. Cite something that only applied to the 2nd generation of consoles to prove me wrong, even though my point spans almost all console generations. No, I was explaining the historical or…

Of course. As we all know here, any business that gets started will go on forever regardless of market fit.

This is a silly criticism. After all, as we all know here (right?), Atari itself fell on hard times. I was talking about the business model, not a specific business. Vendor lockdown and taking a cut of 3rd party software is clearly quite lucrative for vendors, and that's why they do it. There's of course no guarantee of success, but it's obvious why other vendors have emulated that business model.

It may be only for historical reasons that desktop computers aren't completely locked down too. It's a lot easier to lock down a new device class, like smartphones, than it is to lock down an existing open device class, without causing consumer outrage and rebellion.

Re: Right to root access

#72
post #53
post #39

Earlier quoted context omitted.

Yeah, this is just a fundamental misunderstanding of how bootloader unlocking works. The people repeating this argument seem to think that their bootloader will unlock if they look at their phone wrong, when in reality the bootloader unlock process can be made such that the user must consent. If some malware can bypass that, then it could bypass your bootloader in the first place.

It's not just about malware you might accidentally download, it's also about adversaries that may have physical access to your device and can provide that consent No matter how convoluted you make the rube goldberg machine to bypass the cryptography, if there's a way to bypass it it will be bypassed

There are ways to do it so that 'bypass' means you effectively wipe the device. If that's not good enough, how do you protect against them just replacing your device with a compromised one that looks similar?

Re: Right to root access

#73
post #62

Earlier quoted context omitted.

No, I don't think that's true. We got used to insecure systems, and then accepted Big Brother as a security model. We can have secure devices that aren't owned by a corporation, but judging by the comments section here, nobody knows that.

How might that work? You personally have the keys to the TPM? Then some confidence trickster will tell a naive user that to make big$buck$ on the internet you'll need to handover your TPM key. And people will.

Why would you need keys to a TPM? It's meant to store keys without ever getting them out.

Re: Right to root access

#74
post #6

Earlier quoted context omitted.

This is an extremely weak argument, and I'd like to stop seeing it perpetuated. If you don't want an unlocked bootloader, just don't unlock your bootloader. Why should we remove the ability to unlock the bootloader entirely just because some people don't want to use it?

> If you don't want an unlocked bootloader, just don't unlock your bootloader. That kind of logic cuts both ways: "If you don't want a device with a locked boot loader, just don't buy a device with a locked bootloader". Unfortunately, as consumers, we're trapped between a rock and a hard place. On the one hand, I would want 100% freedom to use my device exactly as I see fit and run any software I want, without any fo…

> And I think both types can coexist.

E.g. macos

Re: Right to root access

#75
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

Not only profits, but control. Remember the whole CSAM scanning debacle from Apple?

Re: Right to root access

#76

> I believe consumers, as a right, should be able to install software of their choosing to any computing device that is owned outright. Manufacturers will then claim that people don't own devices, merely a perpetual license to use it.

> Manufacturers will then claim that people don't own devices, merely a perpetual license to use it.

It would be refreshing for them to be honest about their monetary greed instead of telling false stories about "security" and what's "good for users".

Re: Right to root access

#77
post #22

Earlier quoted context omitted.

> If you don't want an unlocked bootloader, just don't unlock your bootloader. That kind of logic cuts both ways: "If you don't want a device with a locked boot loader, just don't buy a device with a locked bootloader". Unfortunately, as consumers, we're trapped between a rock and a hard place. On the one hand, I would want 100% freedom to use my device exactly as I see fit and run any software I want, without any fo…

I would also be happy with those restrictions on a traditional PC-class computing device (laptop or desktop). Would I personally buy one? Probably not, but I'd feel a whole hell of a lot better if my non-techie wife or mother or brother were using one and they were no more susceptible to some kind of exploit on their PC device than they were on their phone That's the whole thing--there should be choice

I could see Microsoft saying "we're only allowing apps installed through our 'store', for safety/security reasons, unless you opt out (gated by some scary warning that doing so is unsafe).

Even if they never charged a fee for running the store, I bet this would raise a lot of eyebrows.

Re: Right to root access

#78
post #57
post #53

Earlier quoted context omitted.

It's not just about malware you might accidentally download, it's also about adversaries that may have physical access to your device and can provide that consent No matter how convoluted you make the rube goldberg machine to bypass the cryptography, if there's a way to bypass it it will be bypassed

Please detail this attack vector where someone can compromise a phone with an unlockable bootloader but not one you can't unlock.

That's not what I claimed?

Re: Right to root access

#79
post #72
post #53

Earlier quoted context omitted.

It's not just about malware you might accidentally download, it's also about adversaries that may have physical access to your device and can provide that consent No matter how convoluted you make the rube goldberg machine to bypass the cryptography, if there's a way to bypass it it will be bypassed

There are ways to do it so that 'bypass' means you effectively wipe the device. If that's not good enough, how do you protect against them just replacing your device with a compromised one that looks similar?

So because we can't eliminate every possibility, we should just give up on all protections?

Re: Right to root access

#80
post #77
post #22

Earlier quoted context omitted.

I would also be happy with those restrictions on a traditional PC-class computing device (laptop or desktop). Would I personally buy one? Probably not, but I'd feel a whole hell of a lot better if my non-techie wife or mother or brother were using one and they were no more susceptible to some kind of exploit on their PC device than they were on their phone That's the whole thing--there should be choice

I could see Microsoft saying "we're only allowing apps installed through our 'store', for safety/security reasons, unless you opt out (gated by some scary warning that doing so is unsafe). Even if they never charged a fee for running the store, I bet this would raise a lot of eyebrows.

Microsoft has been going in the opposite direction. Nowadays you can post any win32 app to the store, they are loosening not tightening
Post reply on HN