Live data from Hacker News

Right to root access

medhir.com

231–240 of 428 posts

Re: Right to root access

#231
post #208
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

> There are a ton of products on the market that are vastly more dangerous than computers An irrelevant "whaddabout" argument. It doesn't change that we need security and privacy for our information handling devices, as well as personal control. The real conversation is about how to best balance these.

> It doesn't change that we need security and privacy for our information handling devices, as well as personal control. The real conversation is about how to best balance these.

An irrelevant false dichotomy argument. There's no inherent conflict between security/privacy and personal control. I would argue that a device which has to phone home to the vendor to get approval for everything results in both less privacy and less personal control.

Re: Right to root access

#232
post #199

Banking, some government and crypto apps on Android think: no They sometimes actively search for root evidence.

I'm actually confused about why banks are so aggressive in denying users the ability to use their apps while rooted. Unlike Google and Apple I can't think of any financial incentives for this, and the security argument is quite obviously nonsense, as I don't think there has been a single person in history who managed to fall for a scam that made them follow the complicated procedure of rooting a smartphone. Neverthel…

> to fall for a scam that made them follow the complicated procedure of rooting

If you are unable to imagine how a 3rd party might root a device without the principal being aware of it, then maybe it is a shortcoming of your risk survey, not theirs.

Re: Right to root access

#233
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

Before we put all the blame on vendors, I submit to you, ladies and gentlemen, this: the public finds this tradeoff (privacy for entertainment) completely acceptable. With all the outrage, privacy-centric solutions are out there and relatively easy to find, how come they don't get more traction? Including among the HN crowd?

> privacy-centric solutions are out there and relatively easy to find

Really? Please name them. Over the past 10 or 15 years, I've never seen anything other than the iPhone/Android or Mac/Windows duopoly for sale in any retail store. I've never seen any advertising for other than those duopolies. The HN crowd may be aware of obscure options, but for the vast majority of consumers, they don't exist. And since we as developers make money catering to the vast majority of consumers, we're kind of stuck with the duopoly too, at least as far as our work is concerned.

Re: Right to root access

#234
post #225
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

Only computers let bad people drain bank accounts at scale.

Please cite the statistics on the volume of bank account draining before you claim that it happens "at scale".

Re: Right to root access

#235
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

Before we put all the blame on vendors, I submit to you, ladies and gentlemen, this: the public finds this tradeoff (privacy for entertainment) completely acceptable. With all the outrage, privacy-centric solutions are out there and relatively easy to find, how come they don't get more traction? Including among the HN crowd?

This isn't about privacy. Not directly anyway. This is about your right to have control of your own property.

You make a fair point though; the case does need to be made as to why this is a market failure and not just consumer choice working as expected. Why _do_ consumers tolerate manufacturers retaining ultimate control of consumer's property after the sale? It certainly doesn't seem to be that important to them. Maybe greater awareness of the issue would help somewhat?

Re: Right to root access

#236

Earlier quoted context omitted.

Thanks, but no. I'm never buying a device with easy root access for a non technical family member ever again. Freedom is great, and I'm using this freedom to buy something with exactly the capabilities I need.

So they'll never use a PC or laptop or anything of that ilk again? To use the same logic, they shouldn't be given anything with a visible screw, or are you going to tell me they _wouldn't_ take a screw driver to an appliance because that would be silly for someone who doesn't know what they're doing in there?

If there were a multi-billion dollar industry of scammers always trying to trick them into taking the screws out of things so they could steal from them, then no I probably wouldn't buy them anything with visible screws.

Re: Right to root access

#237
post #25

I detest Google, but I do think they made the right call with Android devices and Chromebooks. You can unlock either as long as you are willing to totally wipe the device first and start over as a new device under a new security context. This removes the risk of this being abused to compromise the data of stolen devices or evil maid attacks unless a user that knows what they are doing has explicitly opted themselves…

The problem with bootloader unlocking on modern Android devices is that they have a hypervisor that you don't get to ever unlock but that will snitch on you and make some apps, like some banking ones, refuse to work because the "integrity" of your device could not be verified. In other words, because these apps can no longer be certain they are able to hide data from you the device owner. Magisk exists, yes, but it's…

It's even worse now with the P9 series.

They require hardware certification for the Pixel Screenshots app... and for anything that uses Gemini Nano (Call recorder summary, weather, pixel screenshots, etc).

Re: Right to root access

#238
> Devices that are locked become e-waste once a manufacturer stops supporting them. This keeps happening like clockwork:

> Spotify’s Car Thing

Contrary to the author's claim, Car Thing is a great example of what can happen with abandoned hardware. The device did not become e-waste when the manufacturer stopped supporting it. There is a lively community of people modifying and updating software and doing really interesting things. I lack one only because I missed the $15 price nadir and they are relatively high priced in the secondary market.

https://www.ebay.com/sch/i.html?_nkw=Spotify+Car+Thing

https://www.reddit.com/r/carthinghax/

Re: Right to root access

#239
post #120

> I believe consumers, as a right, should be able to install software of their choosing to any computing device that is owned outright. While I agree, I think even legislation will not fix this, because what is a computing device, and who decides what is and what is not ? I'm sure apple will argue that nothing they sell should be considered computing devices. While the hacker will consider anything they can trick int…

> I think the only way is to give the right to flash firmware of _ANYTHING_ that has programmable bits

This seems reasonable to me. What's wrong with it?

Re: Right to root access

#240
From a consumer rights and environmental standpoint I agree. But it's important that only the actual owner of the device can do this, and not just the person in possession of the device. You don't want to make stolen devices be anything but paperweights. But so long as I (the owner) select the passphrase for unlocking it I don't see a problem.
Post reply on HN