Live data from Hacker News

Right to root access

medhir.com

161–170 of 428 posts

Re: Right to root access

#161
The problem is larger than that, it's the IT industry's obsession with denying users the ability to evaluate their own risks and take their own responsibility. You do that all the time every day in most other areas of life, but somehow interacting with technology is different. The manufacturer always knows better. Don't want to have a time component to your biometric authentication because you know your risks? Too bad. Google and Apple know better. Password is required to unlock Touch ID.

Re: Right to root access

#162
post #136
post #47

Earlier quoted context omitted.

So because it would no longer be our computer, we should buy one that's not ours from the start?

Would you prefer for your technologically illiterate relatives (think grandparents/etc getting their first computing device): - A computer that is compromised by malware - A computer that doesn’t permit the user to install malware, and as a consequence, possibly alternative operating systems Your phrasing implies that “it would no longer be our computer” is equivalent to “one that’s not ours from the start.” As far a…

> A computer that doesn’t permit the user to install malware

Let me know when that's ever invented. It's certainly not iPhone. The crApp Store is full of scams and ripoffs, costing consumers millions if not billions of dollars.

It's also worth noting how much goodware that users are not permitted to install, due to vendor lockdown and arbitrary restrictions, often motivated purely by the desire to squealch competition. Security, or in this case security theater, always has tradeoffs. Unfortunately, consumers often don't even know what they're missing, because the vendor restricts what they're allowed to see, but we developers know what kind of software that we can't make on locked down platforms.

Vendor lockdown is a tool for authoritarian regimes that enables censorship. For example, these regimes force the vendors to remove VPN apps from their "curated" stores, and since sideloading is forbidden, there are no alternatives for the poor users under these regimes.

Re: Right to root access

#163

Earlier quoted context omitted.

Thanks, but no. I'm never buying a device with easy root access for a non technical family member ever again. Freedom is great, and I'm using this freedom to buy something with exactly the capabilities I need.

It’s impressive how many people downvote this actually über reasonable opinion…

Because it isn't at all reasonable. There is no argument to not allow root access. You don't have to use it, perhaps most users would be safer with a conventional user account, but it is not reasonable to outright deny full system right to the owner of a device since there are so many disadvantages connected to that.

Re: Right to root access

#165
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

This is a very popular HN opinion; but not a very popular real world opinion. The average customer wants a device that works consistently, every day, that is easy to use, with a collection of 3rd party apps who won’t steal their life savings. Windows failed to deliver this; the average customer never downloads an Exe from a newer publisher without terror. The average consumer is literally dozens of times more likely…

If you explain all details about the advantages and disadvantages to them, I am sure they would think differently.

There are much more "hostile" smartphone apps that exfiltrate your data and sell it to the largest bidder than there are compromised executables these days. Also there are more profitable scams than compromising a PC system outside of industrial espionage.

PC in contrast to consoles always were a cost or usage factor. The difficulties of operating a PC isn't significant. It also heavily increases digital competency of the user for computer systems. If you really don't want that, you have other options.

Re: Right to root access

#166
post #42

Earlier quoted context omitted.

And consumers can have that. That doesn't mean I should be unable to unlock my phone and do whatever I want with it.

The problem is not the ability to unlock your phone. The problem is that 90% of people unlocking their phones will either be for piracy (against the company’s interests), or against the customer's own interests (stalkerware, data extraction, sale of stolen devices). There is a reason malware is over 50 times as prevalent on Android.

There would be no piracy on smartphones. That would require desirable applications. Those don't exist because the environment is that shitty.

Re: Right to root access

#167

Earlier quoted context omitted.

This, or even sell "dev units" with the bootloader unlocked so that you explicitly have to accept the risk before purchasing the device. The problem though is that rooting by itself is not that useful when a lot of apps use remote attestation to deny you service if you're rooted. We don't just need root access, we need undetectable root access.

I agree useful rooting should be easier, but it's definitely possible and not super hard to hide rooting. I'm typing this on a rooted phone where all (banking) apps work just fine. All it takes is downloading an app (magisk) and add apps to a list that need to have rooting hidden.

> it's definitely possible and not super hard to hide rooting.

Worth noting that this could change with every update. It's an unstable situation right now, which is undesirable.

For that reason, e.g. the GrapheneOS team isn't employing measures to fake compliance at all. They'd really like to get SafetyNet compliance for their operating system (you need that to get Google Pay/Wallet to work), but funamentally can't get it. Right now, they could just fake it, but that's not guaranteed to work reliably, forever (and doing so would probably threaten their official BasicIntegrity compliance).

Re: Right to root access

#168

Contrarian take: you bought the device, that you knew already did not provide that, from a company who has priced in not having to support rooted devices, and who had priced in your future revenue from extras. The company can't complain if you find a way to root it (and they don't), but they're under no obligation to add in this extra feature you're asking for. If you want a mostly-open handheld device, they're for s…

> you bought the device, that you knew already did not provide that, from a company who has priced in not having to support rooted devices, and who had priced in your future revenue from extras.

This argument falls apart when 99% of the desirable devices do not have this option. It's not even about compromising on optional-but-important features, like having access to your bank - the "1%" devices usually do not even have a secure hardware element that handles full-disk encryption, leaving your most-personal data (that you carry with you everywhere you go, thus exposing it to additional risk) vulnerable.

> If you want a mostly-open handheld device, they're for sale, you should buy one of those.

Yeah, almost none of those are actually compelling. There's the Pixel series and GrapheneOS, but these devices are huuuge (they simply don't fit in my single hand!), and I don't want to give even more money to Google :S

In an ideal world, you should be able to simply root any of your devices on demand, in exchange for wiping the storage clean, losing your warranty, and any expectation of protection/privacy/extra features. Then it's up to you (and/or a third-party OS provider) to take care of that yourself.

The problem with that route is that only a tiny fraction of users are actually interested in that, there's value to lose in accidental rooting (users get angry about lost features), and there's no value to gain.

This is where regulation could come in.

Re: Right to root access

#169
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

Thanks, but no. I'm never buying a device with easy root access for a non technical family member ever again. Freedom is great, and I'm using this freedom to buy something with exactly the capabilities I need.

I take it you mean easily unlockable bootloader, not really out-of-the-box root access which no phone have.

I have taken the opposite stance on that. Never again will they be left with some Samsung bloatware which hardly receives any Android updates when phones such as Nexus, Nokia and Nothing costs the same and has excellent LineageOS support.

Lineage is stable, bloat-free self-updating and requires no maintenance from my side.

Re: Right to root access

#170
post #144

> I believe consumers, as a right, should be able to install software of their choosing to any computing device that is owned outright. That's easy to say, but hard to legislate, and impossible to enforce. There is so much firmware around, small binary blobs burned into micro controllers that can't even be updated. Or that isn't intended to be updated. There are probably even dimmable LED bulbs without IoT features t…

I think a definition would exclude µC, dsps asics, fpga, etc. While most of those have the ability to program themselves, not all programs support such features.

And for external programming you need programming devices who would also need physical interfaces where no standard connector exists.

But a definition for general purpose computing devices wouldn't be harder than to craft legislation that requires my banking app to run on a certified shitty app environment.

Post reply on HN