Live data from Hacker News

Right to root access

medhir.com

201–210 of 428 posts

Re: Right to root access

#201

Earlier quoted context omitted.

A chainsaw does not introduce an opportunity for thousands of remote criminals to steal money from your bank account.

But like a gun or a knife it may give local criminals an opportunity to threaten (or worse) you into giving them money from your wallet.

You are 100% spot-on with the "local" thing here.

People living in "bad neighborhoods" have to spend more energy and money on locks, fences, security cameras, self-policing as to not go out alone after dark, etc.

Problem is, Internet (and international phone system, to a lesser degree) makes everything so much closer, that scammers from half-way around the globe are "local" for all intents as purposes. Thus, online, every neighborhood is a "bad neighborhood".

Re: Right to root access

#202
post #64

Earlier quoted context omitted.

[flagged]

> You’re kidding, right? You seem to have completely forgotten, or put the drunk glasses, on what living in the 2000s was like. Again, citation needed. I made it through the 2000s just fine, thank you. > What a stereotypical HN comment. Cite something that only applied to the 2nd generation of consoles to prove me wrong, even though my point spans almost all console generations. No, I was explaining the historical or…

> Again, citation needed. I made it through the 2000s just fine, thank you.

Playing devil's advocate: banking trojans used to be really common here in Brazil back in the pre-smartphone era of the early 2000s (smartphones already existed, but weren't very commmon; most people who used online banking did it through their home computers). They're the reason why, for a long time, it was hard to use online banking on Linux: banks required (and still require) the use of an invasive "security plugin" on the browser (nowadays, there's also a Linux version of that plugin, which IIRC includes a daemon which runs as the root user), which attempts to somehow block and/or detect these banking trojans.

Re: Right to root access

#204
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

A chainsaw does not introduce an opportunity for thousands of remote criminals to steal money from your bank account.

It does introduce an opportunity to lose a limb, though. I think I'd rather have my bank account hacked.

Re: Right to root access

#205

I used to think this way but then I saw how non-techy people use their devices. Something like this would inevitably be abused and result in wave of malware so massive that it would render the internet too hostile for all but the most careful, knowledgable and paranoid users.

"everyone is too stupid to be trusted with general purpose computers" is a pretty grim position to hold

A grim position that accurately reflects my 36 years of experience involving people and computers.

Re: Right to root access

#206

Earlier quoted context omitted.

I'm willing to stand corrected, but I can't think of a single smartphone on the market from a reputable manufacturer that is sold with root access. If I want a smartphone I have to accept that the manufacturer will have the bootloader locked down, I don't have a choice.

I have zero experience in the android world, but a quick search tells me that Xiaomi Devices, Google Pixel Phones, OnePlus Devices, Redmi Note 4, Samsung Devices and MediaTek Devices at least are rootable, with some rules with various degrees of freedom for the procedure (in particular warranty is voided pretty much all the time when device is rooted).

Google Pixels are the few devices that enable not only to unlock the bootloader but also the ability to flash your own keys and still have secure boot together with full kernel sources availability (which is why Grapheneos only support them as far as I know).

As far as I know Mediatek (and vendors that use those chips) are usually not good with regards to GPL Compliance, which means no Lineageos if kernel sources are not available...

Re: Right to root access

#207

Earlier quoted context omitted.

half of those things have computers in them now

my fuel injected chain saw, has a data port, but luckily, my back woods repair shop showed me the computerless,seasonal re-tune procedure that only requires a stop watch, works a charm As to other devices....phones, we need a whole re write of the privacy and publishing laws, to allow each person to regulate themselves. With an ultra basic "standard" set up for the masses who do want to be entertained, while having b…

You've left out one important player here: it's not just about the manufacturers and the masses yearning for entertainment, but also about the surveillance industry. Phones in particular, but computers in general, are increasingly important for surveilling the population in novel ways that AI opens up. Giving people root access on their tracking equipment would jeopardize its surveillance functions, because people might elect to give themselves privacy.

Re: Right to root access

#208
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

> There are a ton of products on the market that are vastly more dangerous than computers

An irrelevant "whaddabout" argument.

It doesn't change that we need security and privacy for our information handling devices, as well as personal control. The real conversation is about how to best balance these.

Re: Right to root access

#209

Earlier quoted context omitted.

> If you don't want an unlocked bootloader, just don't unlock your bootloader. That kind of logic cuts both ways: "If you don't want a device with a locked boot loader, just don't buy a device with a locked bootloader". Unfortunately, as consumers, we're trapped between a rock and a hard place. On the one hand, I would want 100% freedom to use my device exactly as I see fit and run any software I want, without any fo…

> I am happy my iPhone doesn't allow Meta to say "to use WhatsApp, you must install the MetaStore®, give it root and install it from there". I think the inverse is a much more credible threat, though. "Sorry, you cant sign in to your bank because you are using Linux. Please try again on windows 11 with secure boot turned on" doesn't seem far fetched at all.

> "Sorry, you cant sign in to your bank because you are using Linux."

That's not an hypothetical for us here in Brazil: online banking was Windows-only for quite some time, because there was no Linux version of the invasive "security plugin" banks require for online banking (the current version of that "security plugin" has a Linux version).

Re: Right to root access

#210
post #42

Earlier quoted context omitted.

And consumers can have that. That doesn't mean I should be unable to unlock my phone and do whatever I want with it.

The problem is not the ability to unlock your phone. The problem is that 90% of people unlocking their phones will either be for piracy (against the company’s interests), or against the customer's own interests (stalkerware, data extraction, sale of stolen devices). There is a reason malware is over 50 times as prevalent on Android.

>The problem is that 90% of people unlocking their phones will either be for piracy (against the company’s interests), or against the customer's own interests (stalkerware, data extraction, sale of stolen devices).

The first point is irrelevant once I've bought a thing. Once I own a thing it is mine to do with what I want, and the company's interests ought to be irrelevant. As for your second point, that is mitigated by making the process sufficiently annoying (eg. hiding it in the developer menu).

Post reply on HN