Earlier quoted context omitted.
That's easily solved. Just scope the law to any device that can run code, and have the criteria for control be "the user must never have less control over code execution as the manufacturer does after the sale". So, for example, if someone buys a phone from Apple they will get full control of the entire device (SEP/TEE included) because Apple has the ability to exercise post-sale code execution control to that level…
Does that apply to those biometric readers issued to me by the government? If not, why not? Can I have a root on my car to disable ISA? Why not, if not? Do you see the problem?
Right to root access
311–320 of 428 posts
Re: Right to root access
#312Earlier quoted context omitted.
Please cite the statistics on the volume of bank account draining before you claim that it happens "at scale".
I mean, the nigerian prince scam is almost a meme these days…
Re: Right to root access
#313Earlier quoted context omitted.
> If protection of the casual user was an argument, there would be an easy option to unlock your system, be that phones or desktop computers. Making it easy to unlock could make it easy(er) for scammers to get it unlocked: > I received the same type of call a little later in the day. They were very adamant they were calling from the Bell data centre, on a terrible line and I made them call back three more times while…
Unlocking should require a physical modification, like soldering a jumper or flipping an internal switch requiring disassembly. That would filter out basically all scam victims. If a scammer can teach a complete novice how to do micro soldering, they've earned their pay.
Re: Right to root access
#314I detest Google, but I do think they made the right call with Android devices and Chromebooks. You can unlock either as long as you are willing to totally wipe the device first and start over as a new device under a new security context. This removes the risk of this being abused to compromise the data of stolen devices or evil maid attacks unless a user that knows what they are doing has explicitly opted themselves…
It does create an interesting choice, though. For example, certain apps will enforce attestation based on the bootloader status. Even if the user wipes their device and relocks their bootloader with their own keys, this doesn't count as fully secure per the bootloader status. Only Google's keys count. Of course, it is also almost prohibitively difficult to deliver yourself OTA updates after this point. I worry that o…
Attestation requirements are only going to become more prevalent. I predict that in a few years basically all proprietary software for Android will require attestation.
So... you may still be able to unlock the device and make it yours, but you'll also be locked out of the ever expanding and ever-more-isolated walled garden.
If you can live off of GrapheneOS and F-Droid, that's great, but for a lot of users this won't be a real choice, because you increasingly need proprietary software for access to real things in the physical world (i.e. I needed to install a special app for event tickets recently).
Re: Right to root access
#315Earlier quoted context omitted.
Damage caused by the customer isn't covered by any warranty anyway, and realistically, how many people would tinker with root access as long as the device worked as intended? I'd be really surprised if the number was more than 1 in 100. And if 1 in 20 brick the device in the process, that's 1 in 2000. According to [1] the average warranty claims rate for consumer electronics is 1 in 100. I doubt the difference in sup…
> Damage caused by the customer isn't covered by any warranty anyway Exactly. We charged the guy for what he did. We gave him 'sa' access to the database and he tried to burn us. I think you may be assuming people act rationally? They do not. Most will but you will always get 'that guy' especially at scale. People will lie about what they have done. Or not even realize what they did goofed things up. In my example th…
It does seem like there ought to be a reasonable split between personal software and business stuff. I mean you guys had a big contract, it is some negotiated thing between two peers, it could be reasonable to negotiate root in some subsystems, not in others. In the end you can’t really trust anything a system tells you if somebody has full root of it. It seems like you guys keeping control of the logging would be a reasonable give for them, if they expect support. (But why would you guys have planned around a downright adversarial customer? That guy is weird).
Also, doesn’t this seem like… basically some kind of fraud? I wonder if your annoying user expected to be able to add the savings whatever he got back from the support contract to his “value to the company” somehow.
For personal customers who are just buying smartphones, we don’t really have giant support contracts to screw around with.
Re: Right to root access
#316There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…
That's because there are people behind every product, and the people behind computers tend to be the paternalistic, nanny-state type. Just read through the histrionics in any HN thread about leaf blowers, they want every landscaper locked up and their tools of the trade taken away. Someone once suggested they should be forced to use rakes. Imagine if some landscaper insisted what laptop you should use.
As you wouldn't expect to find many in-the-Army buzz-cut guys roaming the Google campus as you would at a gun company, you wouldn't expect some blue-haired face-pierced sales engineer selling you table saws.
It's a cultural thing, nothing more.
Re: Right to root access
#317Earlier quoted context omitted.
> This isn't about privacy. Not directly anyway. Agree fully. Don’t know why you’re being downvoted. I accept the risk or tradeoff of Apple or MS spying on me. It’s not that, but the right to repair, to tinker, to hack. Those things have brought us so much interesting wonderful things. My entire generation (millennial) has superior tech literacy to both those that came before and after (no shade to the older gen - so…
Market failures do happen, so I'm not claiming consumer choice is the perfect solution in every case. But consumers aren't stupid either; if this _were_ a mainstream concern the market _would_ self-correct. But it hasn't self-corrected on this issue, because most consumers don't really care that much. So I think you have to carefully consider why that is before you start thinking you know what they want better than t…
The underlying premise here is that the alternative is available for consumers to choose, i.e. that you can buy something which is otherwise equivalent to an iPhone but supports third party app stores or installing a third party OS. But that isn't the case.
What you get instead is e.g. Fairphone, which has the specs of a $200 phone but costs $800 and if you actually have root your bank app might break etc. And still many people buy it. So all you can conclude from this is that the price the mass market places on freedom is less than $600 plus some non-trivial usability issues, not that they value it at zero and don't care about it at all.
On top of this, it's a threshold issue. If the median phone was rooted, people would develop apps that need root. When the percentage is some low single digit if not a fraction of a percent, they don't, and then taking the trade offs of a phone that can be rooted isn't buying you what it should because you need a critical mass in order to achieve the expected benefits, but you need the benefits in order to achieve the critical mass. This is the sort of situation where a mandate can get you over the hump.
> There are costs to any regulation, and lots of possible unintended consequences.
A good way to handle this is through anti-trust, because then you can do things like exempt any company with less than e.g. 5% market share. That means not Apple or Google or Samsung, but if there is any major problem with the rule then the market can work around it by having 20+ independent companies each provide whatever it is that people actually want. Meanwhile that level of competition might very well solve the original problem on its own, because now a couple of them start selling unlocked devices without any countervailing trade offs and that's enough to make the others do it.
Re: Right to root access
#318Earlier quoted context omitted.
> Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom. "Freedom" is also a terrible argument for this. What does it even mean? Freedom from what? Freedom to do what? It's such a meaningless word you're going to lose half your audience just by bringing it up.
"Freedom - the condition of being free; the power to act or speak or think without externally imposed restraints" When the context is "digital devices", it becomes pretty clear what it means. You should be free to use it however you want, without externally imposed restraints. Locking down the device so much so users cannot run applications they've written themselves without the approval of the company who made it, i…
Yea, this is a nice thought if you don't live in society. However, it falls apart pretty rapidly once you realize "your freedom to stops at my freedom from". So it's a non-starter.
Re: Right to root access
#319Earlier quoted context omitted.
The problem with bootloader unlocking on modern Android devices is that they have a hypervisor that you don't get to ever unlock but that will snitch on you and make some apps, like some banking ones, refuse to work because the "integrity" of your device could not be verified. In other words, because these apps can no longer be certain they are able to hide data from you the device owner. Magisk exists, yes, but it's…
It's even worse now with the P9 series. They require hardware certification for the Pixel Screenshots app... and for anything that uses Gemini Nano (Call recorder summary, weather, pixel screenshots, etc).
Re: Right to root access
#320Earlier quoted context omitted.
"Freedom - the condition of being free; the power to act or speak or think without externally imposed restraints" When the context is "digital devices", it becomes pretty clear what it means. You should be free to use it however you want, without externally imposed restraints. Locking down the device so much so users cannot run applications they've written themselves without the approval of the company who made it, i…
> "Freedom - the condition of being free; the power to act or speak or think without externally imposed restraints" Yea, this is a nice thought if you don't live in society. However, it falls apart pretty rapidly once you realize "your freedom to stops at my freedom from". So it's a non-starter.
Well, democracies are societies, and you have much freedom in (most of) those. Not sure where you live, but if possible, you can always try to vacation in one to experience it yourself :)
> "your freedom to stops at my freedom from"
I don't understand what this means, nor how it relates to having root access on your digital devices. Could you possibly explain this again? I want to understand.