Live data from Hacker News

Right to root access

medhir.com

101–110 of 428 posts

Re: Right to root access

#101
The way to balance security and freedom is with a hardware switch. By default, keep secure boot etc. But if someone opens the case, takes out the battery, and moves a little switch on the board? Start with a fresh, unprotected context. Because it's a hardware switch, it can't be remotely hacked. An adversary who gets the hardware anyway can get control (are we going to pretend otherwise?). So just do the right thing and make it easier for people to take over their own hardware.

Re: Right to root access

#102
post #42

Earlier quoted context omitted.

And consumers can have that. That doesn't mean I should be unable to unlock my phone and do whatever I want with it.

The problem is not the ability to unlock your phone. The problem is that 90% of people unlocking their phones will either be for piracy (against the company’s interests), or against the customer's own interests (stalkerware, data extraction, sale of stolen devices). There is a reason malware is over 50 times as prevalent on Android.

> The problem is that 90% of people unlocking their phones will either be for piracy (against the company’s interests), or against the customer's own interests (stalkerware, data extraction, sale of stolen devices).

Why would you think that?

Many Android phones can be unlocked, so it's not a hypothetical situation. I does not enable software piracy, since piracy doesn't depend on root. I know a few persons would install of sort of shit on their phone, including obvious malware, and they lack the knowledge to root their phones.

The data extraction problem happens today on unrooted phones in a "legal" way, it's done by your regular friendly companies like TikTok, Google or Meta. Rooting enables limiting this which is likely why they are against it.

If you look around on forums that discuss the topic of unlocking/rooting Android phones you will see that there is little discussion of piracy and people seem mostly driven by the will to control their own machine instead.

Re: Right to root access

#103
post #41

Earlier quoted context omitted.

> If you don't want an unlocked bootloader, just don't unlock your bootloader. That kind of logic cuts both ways: "If you don't want a device with a locked boot loader, just don't buy a device with a locked bootloader". Unfortunately, as consumers, we're trapped between a rock and a hard place. On the one hand, I would want 100% freedom to use my device exactly as I see fit and run any software I want, without any fo…

Those restrictions aren't on your desktop, where you do have root. Why would they be on your phone if you had root on that?

They are on your desktop. Have you tried installing any game you bought through Steam lately? They all install a custom launcher / updater / stuff that ends up in startup.

Re: Right to root access

#104
post #27

Earlier quoted context omitted.

Stupidest take I've seen today. There are already myriad unlockable devices. What a bizarre fantasy you have constructed.

Let me clarify .. if you have an unlocked device, then software vendors should be able to ensure that their software is non-functional on such a device. Given that, then anything very useful would be rendered non-functional, resulting in the device probably being useless.

[flagged]

Re: Right to root access

#105
The amount of hand-waving in this comments section is truly outstanding. Then again, it shouldn't really surprise me considering how many HN users work for the very companies that profit from vendor lockdown. "You will own nothing and you will be happy!"

Re: Right to root access

#106
> I believe consumers, as a right, should be able to install software of their choosing to any computing device that is owned outright.

I agree with this, as well as most (or all) of the other stuff mentioned in that article.

However, sometimes it might be reasonable to have a switch inside that you must unscrew it (using a commonly available screwdriver, rather than an obscure one) to switch it (and then later be able to switch it back), in order to enable some functions (e.g. to be able to upgrade EEPROM, or to bypass a secure boot loader). If the user puts glitter on it, then this allows the user to detect tampering, while remaining secure and allowing full control.

Re: Right to root access

#107
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

Thanks, but no. I'm never buying a device with easy root access for a non technical family member ever again. Freedom is great, and I'm using this freedom to buy something with exactly the capabilities I need.

Just because the device is capable of root access does not mean all users need to be

Re: Right to root access

#108
post #30

not sure if your in the US, but we can't even get net neutrality. Unfortuantely the likelyhood of this is a hell freezing over situation. I would start with, laws should be logical and informed and go from there... the number of prerequisite changes required to come mildly close to this is unreal. Including but not limited too: copyright law, insurance law, patents, contract law, federal vs state law, an agency compe…

California is typically pro consumer, tenant, employee. If it could be passed in California it would trickle down elsewhere. e.g. California emissions mandates leading to less emissions in the entire country because it makes more sense at scale to build 1 SKU.

Let's not have more of a single state passing de facto laws for the entire country, please. You're right that this happens, but it's an awful thing that we need to fight, not promote more of.

Re: Right to root access

#109
post #6

Earlier quoted context omitted.

This is an extremely weak argument, and I'd like to stop seeing it perpetuated. If you don't want an unlocked bootloader, just don't unlock your bootloader. Why should we remove the ability to unlock the bootloader entirely just because some people don't want to use it?

> If you don't want an unlocked bootloader, just don't unlock your bootloader. That kind of logic cuts both ways: "If you don't want a device with a locked boot loader, just don't buy a device with a locked bootloader". Unfortunately, as consumers, we're trapped between a rock and a hard place. On the one hand, I would want 100% freedom to use my device exactly as I see fit and run any software I want, without any fo…

I think that making a suitable operating system design can help with avoiding some of these problems (and others mentioned elsewhere) (I had mentioned some of my ideas about operating system design before on Hacker News). In combination with this, there is also hardware design to consider (including considerations having to do with the instruction set), and you can also have a package manager with a package repository where whoever manages the package repository will verify them (something that is already done in many systems, although the verification that is already done is often not good enough in some ways); this package repository management is not actually necessary for the security features of the system but makes it more difficult for authors of programs to work around these security features.

Re: Right to root access

#110
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

Thanks, but no. I'm never buying a device with easy root access for a non technical family member ever again. Freedom is great, and I'm using this freedom to buy something with exactly the capabilities I need.

It doesn’t have to be easy enough to let through a person who doesn’t understand what they’re doing (aka blindly click through the annoying popups - that’d be bad).

And non-owners shouldn’t be able to have access solely based on their physical possession - quite the contrary, owner should have means to fully use hardware security features for their personal benefit, locking their own device as tight as they want (within the device’s technical capabilities).

Post reply on HN