Live data from Hacker News

Right to root access

medhir.com

361–370 of 428 posts

Re: Right to root access

#361
post #234

Earlier quoted context omitted.

Please cite the statistics on the volume of bank account draining before you claim that it happens "at scale".

I mean, the nigerian prince scam is almost a meme these days…

This scam is much older than the Internet or even computers. It was called a Spanish Prisoner scam in the 19th century but I would be surprised if it wasn't happening in the ancient world via cuneiform tablets.

Re: Right to root access

#362
I don't really agree with this. There's no shortage of computing platforms in a variety of form factors (including tablets) for which root access is possible. When you buy an iPad, you do so knowing what you're getting and what you're not getting. It's a truly optional purchase, because no one really needs an iPad.

I'd be concerned with a move away from root access across the board, but that doesn't appear to be happening.

Re: Right to root access

#363

> The main exception to this, I believe, would be for critical systems where compromising operation through software modification presents too high a risk. Examples I'm thinking of include: > certain medical devices, such as implants and insulin pumps > subsets of electronic control units for cars These are precisely the opposite of what should be exceptions. If you have a pacemaker implanted in your body, you need t…

Disclaimer I don't have a pacemaker: As a biohacker, I think this is a really bad take. I regularly put things [1] in my body of questionable provenance, and then cut them out of myself without anesthesia when they don't suit me anymore, but I like being alive too much to mess with a medical device like a pacemaker. Pacemaker hacking sounds hardcore and like, respect to anyone who does it but I don't think it should be easy to flash one of those things because I'd really prefer nobody do that to me in my sleep.

[1]. https://dangerousthings.com/

Re: Right to root access

#365
post #293

Earlier quoted context omitted.

I contacted the Google through the BBB. Made the statement that lack of ability to install and configure a Kernel level firewall, edit the HOSTS file, and remove unwanted bloat-ware reduces the security of the product. Google agreed their actions do this and said they find the lack of security acceptable. Having a firewall like Little Snitch should be acceptable to know where the phone is communicate, with whom, and…

There are indeed software firewalls on Android that use the VPN functionality to implement something like this so they don't even require root, I believe Glasswire offers one.

If I have to choose between a firewall and a VPN, I'm choosing the VPN. I should not be forced to make sacrifices like this, nor should anyone else.

Re: Right to root access

#366

> The main exception to this, I believe, would be for critical systems where compromising operation through software modification presents too high a risk. Examples I'm thinking of include: > certain medical devices, such as implants and insulin pumps > subsets of electronic control units for cars These are precisely the opposite of what should be exceptions. If you have a pacemaker implanted in your body, you need t…

Disclaimer I don't have a pacemaker: As a biohacker, I think this is a really bad take. I regularly put things [1] in my body of questionable provenance, and then cut them out of myself without anesthesia when they don't suit me anymore, but I like being alive too much to mess with a medical device like a pacemaker. Pacemaker hacking sounds hardcore and like, respect to anyone who does it but I don't think it should…

You pretty obviously don't want to mess with it frivolously. But if there's something wrong with it, and you have to fix it? That seems better than the alternative where you can't. Note that the right to modify it doesn't imply that you're required to in the absence of any reason to.

Also, if someone wants to kill you in your sleep, they... don't need you to even have a pacemaker. And the security of medical devices is notoriously bad, so if you're worried about that sort of thing, be more worried that the status quo doesn't allow you to fix the existing remotely exploitable wireless security vulnerabilities.

Re: Right to root access

#367

Earlier quoted context omitted.

It does create an interesting choice, though. For example, certain apps will enforce attestation based on the bootloader status. Even if the user wipes their device and relocks their bootloader with their own keys, this doesn't count as fully secure per the bootloader status. Only Google's keys count. Of course, it is also almost prohibitively difficult to deliver yourself OTA updates after this point. I worry that o…

Right now, although it's possible to use Android with either root or a third party ROM, attestation breaks all sorts of little things. Today this is mostly banking apps, and anything that involves NFC, but this isn't where it's going to end. Attestation requirements are only going to become more prevalent. I predict that in a few years basically all proprietary software for Android will require attestation. So... you…

I wonder what the ticket vendor would have said if you told them that you don't own a smartphone.

Re: Right to root access

#368

Earlier quoted context omitted.

Disclaimer I don't have a pacemaker: As a biohacker, I think this is a really bad take. I regularly put things [1] in my body of questionable provenance, and then cut them out of myself without anesthesia when they don't suit me anymore, but I like being alive too much to mess with a medical device like a pacemaker. Pacemaker hacking sounds hardcore and like, respect to anyone who does it but I don't think it should…

You pretty obviously don't want to mess with it frivolously . But if there's something wrong with it, and you have to fix it? That seems better than the alternative where you can't. Note that the right to modify it doesn't imply that you're required to in the absence of any reason to. Also, if someone wants to kill you in your sleep, they... don't need you to even have a pacemaker. And the security of medical devices…

> existing remotely exploitable wireless security vulnerabilities

That's just it though, in my opinion being able to flash the thing at all would count as a remotely exploitable wireless security vulnerability. The first thing I'd do if mine was flashable is lock it down to make sure it was no longer flashable. Does that make sense? I might not be articulating myself well here.

Re: Right to root access

#369

Earlier quoted context omitted.

You pretty obviously don't want to mess with it frivolously . But if there's something wrong with it, and you have to fix it? That seems better than the alternative where you can't. Note that the right to modify it doesn't imply that you're required to in the absence of any reason to. Also, if someone wants to kill you in your sleep, they... don't need you to even have a pacemaker. And the security of medical devices…

> existing remotely exploitable wireless security vulnerabilities That's just it though, in my opinion being able to flash the thing at all would count as a remotely exploitable wireless security vulnerability. The first thing I'd do if mine was flashable is lock it down to make sure it was no longer flashable. Does that make sense? I might not be articulating myself well here.

Removing the ability to flash it seems like a bad idea. Suppose they find a bug and release an official patch. You want it so you don't die, right? The alternative to flashing the one that's in you is that you need chest surgery again to replace it.

If it has a mechanism to flash it then they can give you the password for yours so that you can always do it yourself (or have someone do it) in the event that the manufacturer goes out of business before anyone finds the bug.

And if you really want to remove the ability to flash it, you could use your right to flash it to remove that feature, whereas the status quo is that it supports it -- insecurely -- and you aren't allowed to change it.

Re: Right to root access

#370
post #308

Earlier quoted context omitted.

Unlocking should require a physical modification, like soldering a jumper or flipping an internal switch requiring disassembly. That would filter out basically all scam victims. If a scammer can teach a complete novice how to do micro soldering, they've earned their pay.

The Chromebooks that require removing a single internal screw are a fairly civilized example of this approach (might be a little harder to execute in a phone).

Maybe requiring a PC connection dev options enabled and ADB, high enough barrier?
Post reply on HN