Live data from Hacker News

Right to root access

medhir.com

321–330 of 428 posts

Re: Right to root access

#321
> The main exception to this, I believe, would be for critical systems where compromising operation through software modification presents too high a risk. Examples I'm thinking of include:

    > certain medical devices, such as implants and insulin pumps
    > subsets of electronic control units for cars
These are precisely the opposite of what should be exceptions. If you have a pacemaker implanted in your body, you need the right to replace whatever software is running on it before the manufacturer goes out of business and takes the signing keys with them.

There exists no thing where the owner of the device should not have the right to replace the software it runs, and the more safety-critical the device the more important the right.

Re: Right to root access

#322
Personally, I think everything should be hackable, however...

Limiting the ability to _easily_ modify what's running on a system is more about public cyber-health than the individual's freedom. Viruses + malware much more easily infect systems when they are running outside of a sandbox.

Re: Right to root access

#323
At the very least there should be the right to unlock and use a device after it loses support. A whole ecosystem of software could exist (and does in some cases) to help support or repurpose old devices. If the hardware is still good for something, let it be used! I'm still using my MacBook Pro 2013 and it is fine. I worry I will not be able to do this with Apple's newer laptops. In addition, I want to be able to use my Sonos hardware after Sonos inevitably discontinues support. More realistically I'll eventually have to stop using my Sonos speaker, and realizing this I will never buy another Sonos product.

Re: Right to root access

#324
post #222
post #201

Earlier quoted context omitted.

You are 100% spot-on with the "local" thing here. People living in "bad neighborhoods" have to spend more energy and money on locks, fences, security cameras, self-policing as to not go out alone after dark, etc. Problem is, Internet (and international phone system, to a lesser degree) makes everything so much closer, that scammers from half-way around the globe are "local" for all intents as purposes. Thus, online,…

> Thus, online, every neighborhood is a "bad neighborhood". This is like the exaggerated crime coverage on the local news. I've lived in the so-called "bad internet neighborhood" for 30 years, and I'm fine. It's not so bad.

Just like in a bad neighborhood, there's safety in numbers and keeping a low profile.

Re: Right to root access

#325

> I believe consumers, as a right, should be able to install software of their choosing to any computing device that is owned outright. I agree with this, as well as most (or all) of the other stuff mentioned in that article. However, sometimes it might be reasonable to have a switch inside that you must unscrew it (using a commonly available screwdriver, rather than an obscure one) to switch it (and then later be ab…

I remember how I flashed my Nintendo DS.

In the back of the device there's a sticker over a screwhole. You'll need to poke a screwdriver in there, but inside is not a screw. It's an electrical contact to make the ROM read-write which your screwdriver needs to bridge, and stay bridged while the firmware is flashing (It is harmless if the contact is loss in the process, but I don't know if it would be safe to abort at that point) Pretty hard to convince someone to do that process, yet doable by anyone with a flathead screwdriver.

I guess nowadays it become Samsung's e-fuse where if you flash it blow an e-fuse and the status of the fuse is now detectable with software. Then apps can refuse to service people just because the custom firmware fuse was blown.

Re: Right to root access

#326
post #280

Banking, some government and crypto apps on Android think: no They sometimes actively search for root evidence.

What's even worse is that some won't even let you take a damn screenshot. "Disabled by your administrator." If that doesn't scream the fact that my device is in fact owned by someone else, I don't know what is.

With root + LSPosed + this LSPosed module

https://github.com/LSPosed/DisableFlagSecure

it works in every app again on YOUR phone. I also have root and all my banking apps work currently ... but it's a cat-and-mouse game.

Re: Right to root access

#327
post #9

Earlier quoted context omitted.

There's not nearly enough awareness of this. Even with root access, on modern Android you have to set up a virtual USB connection just to get at the files in the data folders of android apps if you want to, for example, sync the savegames between your mobile emulators and your desktop emulators. It's fucking disgusting. With every new edition they shave off a little more user agency.

What do you mean "a virtual USB connection"? With root access I can see all the files on my Android phone.

A PC can access those folders but even with root and "all files access" android file managers can't on recent versions of Android. Shizuku or apps like it allow file managers to access those folders by pretending to be a PC. Folders like the contents of android/data for each app. Without it you just see empty folders. It's ridiculous.

Re: Right to root access

#328
post #199

Banking, some government and crypto apps on Android think: no They sometimes actively search for root evidence.

I'm actually confused about why banks are so aggressive in denying users the ability to use their apps while rooted. Unlike Google and Apple I can't think of any financial incentives for this, and the security argument is quite obviously nonsense, as I don't think there has been a single person in history who managed to fall for a scam that made them follow the complicated procedure of rooting a smartphone. Neverthel…

I believe the root detection is a form of security-by-obscurity. Bank applications are required to be obfuscated, so you can't simply statically decompile them. The other way to do that is to run the app and set runtime breakpoints, which you can't do on production firmware.

Once the application is decompiled the attacker then can proceed to pentest the bank backend, or find any frontend-only security measures to bypass. One attack I heard in local news is not even a hack at all - they simply make script that use the mobile application API to automatically move money between sock puppet bank accounts. Once a victim get scammed, the money move around quickly. For privacy banks do not provide information about unrelated cross-bank transfers so even cops can't easily trace the multiple hops. That specific bank got in the news for that "weak security"

Re: Right to root access

#329
post #289

Earlier quoted context omitted.

> Exactly how many people have fallen for the scam, out of all computer users Who the fuck knows ? And how is that even remotely a useful question to ask - it's not answerable, those who commit the scam are the only people with the figures, and there's no "register of fuckers who scam other people" where they have to tell you how well they do. > how exactly does device vendor lockdown stop this particular scam Premis…

> Who the fuck knows ? And how is that even remotely a useful question to ask - it's not answerable, those who commit the scam are the only people with the figures, and there's no "register of fuckers who scam other people" where they have to tell you how well they do. Um, why do crime statistics have to come from the perpetrators rather than from the victims? The victims report the crimes, duh. Anyway, you spent a l…

> Um, why do crime statistics have to come from the perpetrators rather than from the victims? The victims report the crimes, duh.

You asked for (quoting) "Exactly how many people have fallen for the scam, out of all computer users". Not every crime is reported, duh.

> Anyway, you spent a lot of words avoiding my question

Nope. I can't answer the question because it's non-answerable. If you believe that nobody has ever fallen for phishing, Nigerian-prince, etc. etc. scams, well, I don't know what colour the sky is on your world, but it's not the same as on mine...

If you further believe that allowing everyone root access to devices that are also linked directly to their bank accounts, social security numbers, driving licenses, etc. etc. Then again, sky colour becomes an issue.

You seem technically savvy. I do not believe you are typical of the average phone user. I think the restrictions in place are a necessary tragedy of the commons, to prevent the destruction of trust in the system as a whole.

As I said, YMMV, and I'm not saying I particularly like the situation, just that I think it's necessary, and opening up everything to everyone is a foolish, idealistic, and hopelessly naive idea.

Re: Right to root access

#330
post #9

Earlier quoted context omitted.

What do you mean "a virtual USB connection"? With root access I can see all the files on my Android phone.

A PC can access those folders but even with root and "all files access" android file managers can't on recent versions of Android. Shizuku or apps like it allow file managers to access those folders by pretending to be a PC. Folders like the contents of android/data for each app. Without it you just see empty folders. It's ridiculous.

Hmm really? That sucks, I guess this is after 14 or so? I'm running 12 or 13.
Post reply on HN