Live data from Hacker News

Right to root access

medhir.com

261–270 of 428 posts

Re: Right to root access

#261
post #256
post #250

Earlier quoted context omitted.

> think it's bizarre that we treat computers as the most dangerous products in the world We do not? You don't even need a license to buy /operate a computer unlike with some other examples on your list

By "we" I meant online commenters debating the issue of tech company device lockdown. I didn't mean "the law". To the contrary, the submitted article author was proposing that we pass laws giving greater individual consumer rights over their devices. But the big tech companies have been viciously fighting against consumer rights, such as the right to repair.

This is also strange as the commenters don't propose the measures that would correspond to viewing computers as more dangerous than guns (lockdown aren't that), but unlike with the law, I don't have a good simple illustration of that.

Re: Right to root access

#262
post #220

I'm not entirely aligned with this article, though I think the principle is correct. I do think that it should never be illegal to tamper with a device that you own in any way that you find acceptable. But I do not feel that manufacturers have any obligation to make this easy or possible. It should be completely legal to hack your devices and to distribute tools and instructions for hacking devices without limitation…

But the question here is if it should be illegal for manufacturers to make the modify a product. The difference is between a locked down boot loader and one that is just a standard boot loader.

Right -- and that I don't agree with. My concern is laws that make it illegal to modify products you own or to offer advice or tools to people who wish to modify products they own. Similarly, arrangements like leases and limited licenses that convey some aspects of "ownership" but not complete ownership should also be severely restricted.

In general if there are no legal recourses to go after people who modify their devices, then it makes it more appealing for manufacturers to allow a supported opt-out method because that reduces the incentives to compromise their products with out-of-band methods.

So I'd prefer to take an indirect route of empowering customers rather than requiring manufacturers to do additional work to free up their products.

Re: Right to root access

#263
post #233

Earlier quoted context omitted.

> privacy-centric solutions are out there and relatively easy to find Really? Please name them. Over the past 10 or 15 years, I've never seen anything other than the iPhone/Android or Mac/Windows duopoly for sale in any retail store. I've never seen any advertising for other than those duopolies. The HN crowd may be aware of obscure options, but for the vast majority of consumers, they don't exist. And since we as de…

And as for "why are not selling this in every retail store?", the answer is the same - because if they were, no one would buy them. I found the situation curious, while everyone complains about it, only very few people are trying to do anything about it. Perhaps the breaking point was not reached yet, and something big has to happen to change people's perspective.

> And as for "why are not selling this in every retail store?", the answer is the same - because if they were, no one would buy them.

That's purely hypothetical. How could any prove or disprove the assertion?

The general point, though, is that consumer awareness is essential for sales. People won't buy things that they don't know about. As an indie developer myself, I'm painfully aware of this. It doesn't matter how great one's product is if nobody knows about it. Advertising is very expensive, so it requires vast capital outlays in order to get your products into the minds of consumers and onto the shelves of stores. The big established brands have a massive advantage, making it difficult for competitors to break into the market. Apple itself leveraged its existing brand, with Mac and iPod, in order to promote iPhone. And Apple's primary competitor is Google, who also was already an established brand via search and Chrome.

Remember that back in the day, Microsoft almost destroyed the entire desktop OS market. They almost killed Apple too. Only the Department of Justice put some kind of break on it, and Microsoft let Apple live in order to provide antitrust cover. If MS had for example simply withdrawn its apps from Mac—Office, Internet Explorer (remember that Internet Explorer was originally the default web browser on Mac OS X before Safari!)—Apple likely would have died.

Re: Right to root access

#264

Earlier quoted context omitted.

Perhaps it imposes some restrictions, like using TPMs, but I don't think it excludes what the author is suggesting, which is the ability to run as root. Case in point: every popular desktop PC let's you run as root, and also watch DRM content. They aren't totally mutually exclusive.

You can't play 4K Netflix on Linux, period. Because of DRM. Before you say "this is just a Netflix issue" - you can't play 4K Prime Video on Linux either. Nor 4K Disney+. And many other services. Piracy is the only way to watch most 4K streaming content on Linux. You may have the most capable and up-to-date hardware on the market, you still can't.

Yeah, that realization is what killed my attempt at replacing my Nvidia Shield TV with my home-built SteamOS box. I got everything "working" in the most technical sense, but I was limited to 720p on Hulu, and that ended up driving us crazy. I know that the box is capable of streaming 4K video just fine, because I was able to stream my 4K Blu-ray rips from my Jellyfin server just fine, so this limitation is purely artificial.

I did do some experimentation with VMs and emulation and whatnot, but I never got anything that worked consistently enough to use full-time, so I bit the bullet and plugged my Nvidia Shield TV back in.

Re: Right to root access

#265

Earlier quoted context omitted.

This, or even sell "dev units" with the bootloader unlocked so that you explicitly have to accept the risk before purchasing the device. The problem though is that rooting by itself is not that useful when a lot of apps use remote attestation to deny you service if you're rooted. We don't just need root access, we need undetectable root access.

I agree useful rooting should be easier, but it's definitely possible and not super hard to hide rooting. I'm typing this on a rooted phone where all (banking) apps work just fine. All it takes is downloading an app (magisk) and add apps to a list that need to have rooting hidden.

Magisk only works because Google still supports devices that don't support hardware attestation. Very soon you won't be able to fool Play Integrity without hacking the TEE

Re: Right to root access

#266
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

Before we put all the blame on vendors, I submit to you, ladies and gentlemen, this: the public finds this tradeoff (privacy for entertainment) completely acceptable. With all the outrage, privacy-centric solutions are out there and relatively easy to find, how come they don't get more traction? Including among the HN crowd?

I have no data to back this up. So what follows is purely my personal opinion.

I think the reason people don't care, is because they don't know. The average person either doesn't know or barely knows That anything deeper than what they see in the user interface is happening on their system.

We humans are very much an out of sight out of mind type of creature. If we can't see it, it's hard for us to imagine that it exists.

Re: Right to root access

#267
post #261
post #256

Earlier quoted context omitted.

By "we" I meant online commenters debating the issue of tech company device lockdown. I didn't mean "the law". To the contrary, the submitted article author was proposing that we pass laws giving greater individual consumer rights over their devices. But the big tech companies have been viciously fighting against consumer rights, such as the right to repair.

This is also strange as the commenters don't propose the measures that would correspond to viewing computers as more dangerous than guns (lockdown aren't that), but unlike with the law, I don't have a good simple illustration of that.

> lockdown aren't that

Vendor lockdown is that. Defenders of vendor lockdown argue that computer users need to be protected paternalistically from themselves.

For some reason we accept that for computers, but nobody would accept refrigerators and ovens that only allow you to eat healthy foods, nobody would accept homebuilders controlling the doors of your house and having to approve anyone who comes in, etc. Why do computers get this special treatment of vendor lockdown, but not any other product?

Re: Right to root access

#268

Earlier quoted context omitted.

I believe GP is referring to things like privacy-centric de-Googled Android phones, which definitely are an option. I would not classify those as "least bad" or even bad. GP is correct about Apple products; even among the HN crowd they are likely the most popular devices. I think this is because most readers aren't trying to die on the hill of openness. They're more concerned with software and ubiquity, two areas whe…

Actually, I was disagreeing with the GP specifically about Apple products. I'm an Apple user, but very much because they're the "least bad" option. De-Googled Android phones still have awful audio latency (I'm a musician who makes a music app on the side), very limited messaging and notification features, and integrate poorly with desktop OSes. For how I use my devices, open or no, Android simply isn't a viable optio…

> Apple's products being well-integrated and well-designed doesn't require them to be locked down the way they are.

That's definitely true, and it's what has made me favor Google over Apple for decades now. Google's deal has been free software for the price of your user data, but I've accepted that deal because Google has never practiced predatory lock-in. Apple makes claims to value your privacy (I wouldn't know) while making predatory lock-in fundamental to everything they do. Denying access to your own device is part of this.

The irony is that I loathe the data economy. I think it has gone far beyond what Google ever envisioned (for years it seemed they had yet to discover a way to make money at all). The privacy aspect matters, but I also hate the way it makes companies and their products behave; the way it feels like every click results in an attempt to directly advertise to you. And it's all clumsy and broken. How often are ads even correctly targeted? I feel about conglomerated user data the way I feel about meme coins: it's all built on speculation, hopes, and dreams, and has less to do with people actually buying your product. I can't wait for the bubble to burst and/or for a global ban on the sale and purchase of user data.

Re: Right to root access

#269
post #234

Earlier quoted context omitted.

Please cite the statistics on the volume of bank account draining before you claim that it happens "at scale".

I mean, the nigerian prince scam is almost a meme these days…

A meme is not a statistic. Exactly how many people have fallen for the scam, out of all computer users.

And how exactly does device vendor lockdown stop this particular scam?

Re: Right to root access

#270
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

Before we put all the blame on vendors, I submit to you, ladies and gentlemen, this: the public finds this tradeoff (privacy for entertainment) completely acceptable. With all the outrage, privacy-centric solutions are out there and relatively easy to find, how come they don't get more traction? Including among the HN crowd?

There is nothing inherent to the benefits that these companies tout that require them to lock us out of our own devices.

What you are describing is not a tradeoff but a magnificent bribe. They bribe us with measly benefits in order to accept the deal that is incredibly favourable for them.

See: https://reallifemag.com/the-magnificent-bribe/

Post reply on HN