Live data from Hacker News

Right to root access

medhir.com

131–140 of 428 posts

Re: Right to root access

#131
post #25

I detest Google, but I do think they made the right call with Android devices and Chromebooks. You can unlock either as long as you are willing to totally wipe the device first and start over as a new device under a new security context. This removes the risk of this being abused to compromise the data of stolen devices or evil maid attacks unless a user that knows what they are doing has explicitly opted themselves…

It does create an interesting choice, though. For example, certain apps will enforce attestation based on the bootloader status. Even if the user wipes their device and relocks their bootloader with their own keys, this doesn't count as fully secure per the bootloader status. Only Google's keys count. Of course, it is also almost prohibitively difficult to deliver yourself OTA updates after this point. I worry that one day I will have to keep two mobile phones; one for bank apps, which has not been altered from the vendor's security defaults, and one for everything else, that I am actually allowed to modify.

At the moment, I just run GrapheneOS and don't bother with any modification. It is not worth the hassle. I've already had my bank account locked out because a Google Store-bought Pixel phone was flagged as "stolen", probably due to some attestation measure (they could not tell me why). They recommended that I purchase a new phone.

Re: Right to root access

#132
post #121

Earlier quoted context omitted.

You left out the vital clause. "... if they have total unfettered control". Also, not everyone. Obviously. It's a position I came to rather regretfully and sadly.

How do you propose we limit access to general-purpose computing without doing so across the board for everyone? How would you block bad actors from general-purpose computing? Require licensing to use development tools, and track what they're used for so you can react when someone crosses that "line"? Congratulations, you've just destroyed computing.

While obviously not perfect, what we have today is

> limit[ing] access to general-purpose computing without doing so across the board for everyone

I imagine the vast majority of people on this site run (or at least have used) Linux, *BSD, etc. on a daily basis. No average person is going to set up Arch on their main PC, but lots of us do. Your average person enjoys their locked-down Samsungs and iPhones, while we enjoy unlocked problem-ridden (but personally solvable) Linux environments.

Would it be better if every person who could buy an iPhone was sufficiently technically competent to not install malware on their easily-rootable phone? Yes. But that’s not the world we live in. Maybe I’m succumbing to the “First They Came...” mindset, but until I can’t run Linux on a PC I’ve built with components of my choosing, I don’t really care if my phone is a semi-closed semi-black box. I used to enjoy jailbreaking iOS devices, but eventually decided I’m happy with my phone just being a phone. If I want to tinker, I’ve got a rack full of servers and 3 different workstations I have the freedom to break whenever I want. It’s nice to have a phone that can just do phone things 100% of the time - I haven’t had an iOS system crash (or any bug preventing use) in about 5 years, which was the last time I had a jailbroken phone.

Re: Right to root access

#133

Earlier quoted context omitted.

Let me clarify .. if you have an unlocked device, then software vendors should be able to ensure that their software is non-functional on such a device. Given that, then anything very useful would be rendered non-functional, resulting in the device probably being useless.

Why should a software vendor be allowed to say what I can and can't run on my machine?

Because it’s their software? It is well within your bank’s rights to deny you access to their online banking system for pretty much any (technical) reason they choose; why are you entitled to run their app on what they deem to be an insecure platform? If you don’t like it, either pick a different bank or deal with not having access to their software.

Freedom cuts both ways here; if you want absolute freedom to do whatever you want with your device, why should software vendors not have absolute freedom to choose what platforms their software is permitted to run on?

Obviously none of this applies to FOSS.

Re: Right to root access

#134
post #120

> I believe consumers, as a right, should be able to install software of their choosing to any computing device that is owned outright. While I agree, I think even legislation will not fix this, because what is a computing device, and who decides what is and what is not ? I'm sure apple will argue that nothing they sell should be considered computing devices. While the hacker will consider anything they can trick int…

> I'm sure apple will argue that nothing they sell should be considered computing devices.

“What’s a computer?”

Re: Right to root access

#135
post #120

> I believe consumers, as a right, should be able to install software of their choosing to any computing device that is owned outright. While I agree, I think even legislation will not fix this, because what is a computing device, and who decides what is and what is not ? I'm sure apple will argue that nothing they sell should be considered computing devices. While the hacker will consider anything they can trick int…

> While I agree, I think even legislation will not fix this, because what is a computing device, and who decides what is and what is not ?

If there is legislation, it will contain a definition of what is a computing device and what isn't. It will be imperfect, and the edge cases will be contested in courts. Courts deal with blurry boundaries all the time.

That's how it always is with legal matters, and doesn't mean we have to demand that anything with a firmware must be flashable.

Re: Right to root access

#136
post #47

Earlier quoted context omitted.

Even with access controls, people do things like download chrome from random web sites, then do their banking with the result. If the fake-chrome requested admin access then you'd never be able trust anything on that computer ever again. Even re-installing the OS wouldn't fix it. It would no longer be your computer.

So because it would no longer be our computer, we should buy one that's not ours from the start?

Would you prefer for your technologically illiterate relatives (think grandparents/etc getting their first computing device):

- A computer that is compromised by malware

- A computer that doesn’t permit the user to install malware, and as a consequence, possibly alternative operating systems

Your phrasing implies that “it would no longer be our computer” is equivalent to “one that’s not ours from the start.” As far as I know, Microsoft and Apple aren’t going to ransomware your computer/phone to make a few bucks. You just can’t root an iPhone. Equating the two is arguing in bad faith, at best.

Re: Right to root access

#137

If locking the bootloader and comparing signatures against keys burned into a secure enclave allow Apple to make certain security guarantees that helps them sell products, I'm all for their freedom to do so. Why doesn't OP merely champion competition, instead of encouraging regulation of what software others can write, what hardware others can ship? I too am afraid of general purpose computing going by the wayside, a…

> so I don't know where the pressure for secure enclaves really comes from.

In my experience, security engineers who see them as finally solving the “root of trust” problem. Generally (ime) it’s security engineers/teams that have been pushing for things like ssl/tls, global certificate stores, signed updates of those stores, signed kernels validating those updates. But if you break the kernel (or compromise the bootloader or EFI/BIOS) then it’s all for naught. A secure enclave solves that problem (unless you find a bug in it/its implementation) - your bootloader is validated, which validates your kernel, which validates all the userland components you care about. Security teams rejoice.

Re: Right to root access

#138
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

Thanks, but no. I'm never buying a device with easy root access for a non technical family member ever again. Freedom is great, and I'm using this freedom to buy something with exactly the capabilities I need.

It’s impressive how many people downvote this actually über reasonable opinion…

Re: Right to root access

#139
post #17

> I believe consumers, as a right, should be able to install software of their choosing to any computing device that is owned outright. Manufacturers will then claim that people don't own devices, merely a perpetual license to use it.

That's a slippery slope, because they list devices as sold, not as rented. So they can't claim that. Some still try, especially using copyright on software on the devices as leverage.

More than likely, they’ll instead just start actually renting you the products. See Apple’s 2-year rental program for a (relatively) non-predatory implementation, or NZXT’s for a very predatory implementation.

Re: Right to root access

#140

Contrarian take: you bought the device, that you knew already did not provide that, from a company who has priced in not having to support rooted devices, and who had priced in your future revenue from extras. The company can't complain if you find a way to root it (and they don't), but they're under no obligation to add in this extra feature you're asking for. If you want a mostly-open handheld device, they're for s…

I agree. The gist of the main arguments I see in this thread are that average people should be trusted to choose whether or not they will unlock their device. Yet, a group of (presumably) some of the most technically savvy people on the internet can’t figure out how to buy open products? If you don’t want a locked-down computer, don’t buy a Mac. Clearly, many, many people do, so why should they have that taken away from them because of someone else’s ideals?
Post reply on HN