Live data from Hacker News

Right to root access

medhir.com

281–290 of 428 posts

Re: Right to root access

#281
post #126

Earlier quoted context omitted.

Android is built on top of Linux. Android the OS has a lot of permissions layers between an app and the bare metal.

Still, those permissions are standard Linux permissions. So the argument that Linux is less secure than Android is a little hard to understand. A little more specificity might help.

They're definitely not "standard Linux permissions." Yes Android does use many of those (such as standard user IDs, file system permissions, and now SELinux) to implement some of its permissions, but it adds a ton of permissions on top that are not part of Linux.

Re: Right to root access

#282
post #208

Earlier quoted context omitted.

> There are a ton of products on the market that are vastly more dangerous than computers An irrelevant "whaddabout" argument. It doesn't change that we need security and privacy for our information handling devices, as well as personal control. The real conversation is about how to best balance these.

> The real conversation is about how to best balance these. How do you even formulate these values so that they're in conflict in the first place?

I guess people are unaware of the various malicious rootkits that have cropped up?

If you're serious about this stuff binary thinking is a mistake. It's not a question of whether rooting is possible or impossible. It's a question of under what circumstances it can be done, and under whose control.

Also, "conflict" is the wrong word here. It's a question of competing concerns not conflicting ones.

We probably want root access to be under the end-user's control, but in such a way that minimizes the ability of malicious parties to exploit it.

e.g., one way would be to allow anyone to easily install any root they want, but to disallow software from, say, the Apple app store from running on such "rooted" devices. While that gives end-users control and would mostly prevent malicious actors from getting things they want, it's probably not what most user's would want. They probably want to run all their regular software along side the root software.

Another way would be to allowing people to easily install software as root, and allow software from popular app stores to run on it. That gives users max control, but is pretty easy for malicious actors to exploit too. People aren't going to be too happy with this when some coupon clipping app starts emptying people's bank accounts.

These are just examples to give the idea of the range of possibilities. The real answer needs to be a lot more nuanced than this. The point is, pretending there aren't issues doesn't get us anywhere. You might as well have no opinion on this.

Re: Right to root access

#283

Earlier quoted context omitted.

This isn't about privacy. Not directly anyway. This is about your right to have control of your own property. You make a fair point though; the case does need to be made as to why this is a market failure and not just consumer choice working as expected. Why _do_ consumers tolerate manufacturers retaining ultimate control of consumer's property after the sale? It certainly doesn't seem to be that important to them. M…

> Why _do_ consumers tolerate manufacturers retaining ultimate control of consumer's property after the sale? Just my opinion from many conversations with normies about this: It's because most of them don't know (the marketing material from these companies certainly doesn't advertise it), and the ones who do know don't care because they wouldn't be able to (technical knowledge) or want to root/unlock and utilize the…

> the ones who do know don't care because they wouldn't be able to (technical knowledge) or want to root/unlock and utilize the capabilities

This is a good point. Some of that is perhaps self-perpetuating: Why root if there's nothing you can do with root? And why develop stuff you can do with root if there's nobody who can use it? If there weren't so much active suppression of software freedom by manufacturers maybe the situation would change and the benefits of consumers having full control of their devices would be more apparent.

Re: Right to root access

#284
post #208
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

> There are a ton of products on the market that are vastly more dangerous than computers An irrelevant "whaddabout" argument. It doesn't change that we need security and privacy for our information handling devices, as well as personal control. The real conversation is about how to best balance these.

Bringing up whataboutism is even less relevant. Comparisons aren't suddenly bad because of an overused buzzword

Re: Right to root access

#285
post #276
post #267

Earlier quoted context omitted.

> lockdown aren't that Vendor lockdown is that. Defenders of vendor lockdown argue that computer users need to be protected paternalistically from themselves. For some reason we accept that for computers, but nobody would accept refrigerators and ovens that only allow you to eat healthy foods, nobody would accept homebuilders controlling the doors of your house and having to approve anyone who comes in, etc. Why do c…

Wow, ok, if you think this is on par with the lockdowns that the commenters support for guns (which I've previously proxied as ~ existing restrictions), then I'm not sure what to say > Why do computers get this special treatment of vendor lockdown, but not any other product? Of course they don't, plenty of other products are treated much more seriously by "us" (supporting lockdowns that limit your own use without sup…

You appear to be conflating two different things: legal mandates and vendor lockdown.

There are legal mandates regarding the sale and use of certain products. For example, you have to be a minimum age to buy cigarettes and alcohol, stores in some localities can only sell alcohol during certain hours, bars have to close at a certain time, you can't drive drunk, you must wear a seatbelt, you can't exceed the speed limit, etc.

But there are no vendor lockdowns in this regard. A cigarette will allow anyone to smoke it, a container of alcohol will allow anyone to drink it, you car still works if you're drunk and don't put on your seatbelt, etc. If your car made you take a breathalyzer test whenever you wanted to drive, or it didn't allow you to exceed the speed limit, that would be vendor lockdown.

I discussed the issue in another comment: "The equivalent would be if you could only use specific brands of replacement chains, blades, tires, or bullets that are approved by the manufacturer, for which the manufacturer gets a cut of the sales of those replacements." https://news.ycombinator.com/item?id=42684134

Re: Right to root access

#286
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

Actually, chainsaws, table saws, cars, motorcycles, and even guns all have safety mechanisms installed by the manufacturers and tampering with them voids the warranty.

Tampering with safety mechanisms on your car voids the warranty on the safety mechanism, not on your whole car. Otherwise using third party mechanics would be impossible.

Re: Right to root access

#287
post #282

Earlier quoted context omitted.

> The real conversation is about how to best balance these. How do you even formulate these values so that they're in conflict in the first place?

I guess people are unaware of the various malicious rootkits that have cropped up? If you're serious about this stuff binary thinking is a mistake. It's not a question of whether rooting is possible or impossible. It's a question of under what circumstances it can be done, and under whose control. Also, "conflict" is the wrong word here. It's a question of competing concerns not conflicting ones. We probably want roo…

I just don't have this paternalistic instinct to try and protect people from rootkits. Even if I did, this is certainly the wrong way to do so—you need to hold companies accountable for the flaws in their software (for which we have basically no legislation at the moment) or they have no incentive to make the regulations meaningfully protective. Otherwise you just end up with shipping hardware that's still insecure, but checks the right regulatory checkboxes, and still restricts people from using the hardware they bought, and still no way to remediate when something inevitably does slip past the regulatory controls.

Re: Right to root access

#288
post #160

Earlier quoted context omitted.

If protection of the casual user was an argument, there would be an easy option to unlock your system, be that phones or desktop computers. But on many systems these options do not exist because the vendor likes people dependent on them. This is why devices like chromebooks or all mobile phones are more or less e-waste in the making. In my opinion it is a waste to use any development capacity for these systems apart…

> If protection of the casual user was an argument, there would be an easy option to unlock your system, be that phones or desktop computers. Making it easy to unlock could make it easy(er) for scammers to get it unlocked: > I received the same type of call a little later in the day. They were very adamant they were calling from the Bell data centre, on a terrible line and I made them call back three more times while…

Easy doesn't mean without any warning, it just means that the device is unlockable by design and without OEM's approval.

It would be reasonable to:

- factory reset the device before unlocking it to protect existing data (like Android phones require)

- display warnings, for example "if someone's asking you to do this, it's probably a scam"

- for the owner to be allowed to permanently disable unlocking, e.g. the commonly cited example of someone setting the device up for their elderly parents

Re: Right to root access

#289
post #269

Earlier quoted context omitted.

A meme is not a statistic. Exactly how many people have fallen for the scam, out of all computer users. And how exactly does device vendor lockdown stop this particular scam?

> Exactly how many people have fallen for the scam, out of all computer users Who the fuck knows ? And how is that even remotely a useful question to ask - it's not answerable, those who commit the scam are the only people with the figures, and there's no "register of fuckers who scam other people" where they have to tell you how well they do. > how exactly does device vendor lockdown stop this particular scam Premis…

> Who the fuck knows ? And how is that even remotely a useful question to ask - it's not answerable, those who commit the scam are the only people with the figures, and there's no "register of fuckers who scam other people" where they have to tell you how well they do.

Um, why do crime statistics have to come from the perpetrators rather than from the victims? The victims report the crimes, duh.

Anyway, you spent a lot of words avoiding my question, which is how exactly does vendor lockdown stop the Nigerian prince scam? You're arguing that vendor lockdown is supposed to protect consumers, but you can't seem to explain how or how often.

Post reply on HN