I have talked about this before. The issue goes further in my opinion and starts to effect property rights themselves. In particular locked down hardware starts to effect the owners right of exclusion. The right of exclusion loosely is the right include or exclude something from/usesing some property. When the hardware is locked down the owner can know longer solely make those decisions. Instead in the instance of li…
Right to root access
351–360 of 428 posts
Re: Right to root access
#352Earlier quoted context omitted.
Easy doesn't mean without any warning, it just means that the device is unlockable by design and without OEM's approval. It would be reasonable to: - factory reset the device before unlocking it to protect existing data (like Android phones require) - display warnings, for example "if someone's asking you to do this, it's probably a scam" - for the owner to be allowed to permanently disable unlocking, e.g. the common…
> for the owner to be allowed to permanently disable unlocking, e.g. the commonly cited example of someone setting the device up for their elderly parents This opens a wormhole that warps us back to one of the core issues / battlegrounds in computing: ownership , and specifically, the balance of power and responsibility between the owner and the user, when they're not the same person. Unfortunately, the same means an…
And while we're at it, let's not allow apps to refuse to run because of rooting.
Re: Right to root access
#353Earlier quoted context omitted.
This is the first time I heard about it. Has anyone looked into their claims? Would love to buy an affordable Linux pad or a mini PC.
FWIW, I have no idea if this is any good. My point is, I found this after maybe 3 minutes searching. If we were to spend 30 minutes, we would definitely find something reasonable.
That's quite an assumption.
Re: Right to root access
#354I detest Google, but I do think they made the right call with Android devices and Chromebooks. You can unlock either as long as you are willing to totally wipe the device first and start over as a new device under a new security context. This removes the risk of this being abused to compromise the data of stolen devices or evil maid attacks unless a user that knows what they are doing has explicitly opted themselves…
The problem with bootloader unlocking on modern Android devices is that they have a hypervisor that you don't get to ever unlock but that will snitch on you and make some apps, like some banking ones, refuse to work because the "integrity" of your device could not be verified. In other words, because these apps can no longer be certain they are able to hide data from you the device owner. Magisk exists, yes, but it's…
And there are some real strong reasons why you benefit from this sort of ability, such as preventing folks from cheating in competitive games. I can't say that all uses seem to have good reasons to use it, but that seems like more of a vote with your wallet sort of situation. Perhaps the play store should also have stricter requirements on acceptable use of attestation and ensure they are upheld.
Re: Right to root access
#355Earlier quoted context omitted.
A PC can access those folders but even with root and "all files access" android file managers can't on recent versions of Android. Shizuku or apps like it allow file managers to access those folders by pretending to be a PC. Folders like the contents of android/data for each app. Without it you just see empty folders. It's ridiculous.
Hmm really? That sucks, I guess this is after 14 or so? I'm running 12 or 13.
Re: Right to root access
#356Re: Right to root access
#357Earlier quoted context omitted.
> Um, why do crime statistics have to come from the perpetrators rather than from the victims? The victims report the crimes, duh. You asked for (quoting) "Exactly how many people have fallen for the scam, out of all computer users". Not every crime is reported, duh. > Anyway, you spent a lot of words avoiding my question Nope. I can't answer the question because it's non-answerable. If you believe that nobody has ev…
> You asked for (quoting) "Exactly how many people have fallen for the scam, out of all computer users". Not every crime is reported, duh. Not every crime is reported, but it's indisputable that a lot of crimes are reported. So give me a statistic, any reported statistic. > If you believe that nobody has ever fallen for phishing, Nigerian-prince, etc. etc. scams, well, I don't know what colour the sky is on your worl…
As I said, I don't care about the current OS situation, I think it's actually pretty well reasoned out. I'm not spending my time tracking down statistics for you to "prove" some point to some other person on the internet.
I don't care enough to argue. Have a nice life.
Re: Right to root access
#358Earlier quoted context omitted.
was that when they said “instead of uploading the images to our servers to do the CSAM scan, we’ll do a quick once over in the privacy of your own phone to see if we can allow-list your photo” ? And then the whole world suddenly went apeshit, so Apple basically shrugged, said “fine, we’ll do it just like everyone else and put your photos in the relatively unprotected server domain to do the scan”. Sucks to be you. Un…
A server is someone else's device. Your phone is your own device. So no, doing the scan on your own device and making your device your potential adversary is not better than doing it on the server. You can always choose not to use the server.
Apple only ever scanned images being uploaded to the server. They were only ever going to scan images (even if it was done on the local device) if they were uploaded to the server.
On the one hand you have:
- do the scan in private, get a pass (I'm assuming we all get a pass), and no-one outside of your phone ever even looks at your images.
On the other hand, you:
- do the scan on upload. Some random bloke in support gets tasked with looking at 1 in every 10,000 images (or whatever) to make sure the algorithm is working, and your photo of little Bobby doing somersaults in the back garden is now being studied by Jim.
If you never uploaded it, it was never scanned, in either case.
So yes, you've lost privacy because faux outrage on the internet raised enough eyebrows. Way to go.
Re: Right to root access
#359Earlier quoted context omitted.
The problem with bootloader unlocking on modern Android devices is that they have a hypervisor that you don't get to ever unlock but that will snitch on you and make some apps, like some banking ones, refuse to work because the "integrity" of your device could not be verified. In other words, because these apps can no longer be certain they are able to hide data from you the device owner. Magisk exists, yes, but it's…
If software doesn't want to run on your hardware because it can't make sure you're not tampering with it, why is it wrong for doing so? You're not necessarily entitled to the ability to run the software right? I understand the implications this has on ones ability to create custom operating systems is troubling (eg this could destroy desktop Linux), but at the end of the day I guess it is just a choice the developer…
It's not the software, it's that the hardware itself, that I bought to own, still serves someone else in a way that's detrimental to my interests, and that can't be overridden because those stupid encryption keys used to sign attestation reports are burned into the silicon and only accessible to that TrustZone hypervisor that can't be unlocked.
> And there are some real strong reasons why you benefit from this sort of ability, such as preventing folks from cheating in competitive games.
Maybe playing such games on general-purpose devices is a bad idea to begin with. You know, consoles are already locked down pretty tight. But then there are PCs that have no hardware roots of trust at all yet you can play anything on them and sometimes even compete with console players. So go figure.
Re: Right to root access
#360Earlier quoted context omitted.
> You asked for (quoting) "Exactly how many people have fallen for the scam, out of all computer users". Not every crime is reported, duh. Not every crime is reported, but it's indisputable that a lot of crimes are reported. So give me a statistic, any reported statistic. > If you believe that nobody has ever fallen for phishing, Nigerian-prince, etc. etc. scams, well, I don't know what colour the sky is on your worl…
[sigh] fine. You believe whatever you want. As I said, I don't care about the current OS situation, I think it's actually pretty well reasoned out. I'm not spending my time tracking down statistics for you to "prove" some point to some other person on the internet. I don't care enough to argue. Have a nice life.
A simple Google search would do: "Nigerian prince’ email scams still rake in over $700,000 a year" https://www.cnbc.com/2019/04/18/nigerian-prince-scams-still-...
$700k a year as an excuse to lock down over a billion smartphones? Not to mention that once again, this is an email scam, and thus vendor lockdown is irrelevant and doesn't prevent it.
It appears that you're the one believing whatever you want to believe, despite the empirical facts. The problem is that proponents of vendor lockdown always make gross exaggerations to defend it, pure fearmongering.