Earlier quoted context omitted.
Please cite the statistics on the volume of bank account draining before you claim that it happens "at scale".
I mean, the nigerian prince scam is almost a meme these days…
Right to root access
361–370 of 428 posts
Re: Right to root access
#362I'd be concerned with a move away from root access across the board, but that doesn't appear to be happening.
Re: Right to root access
#363> The main exception to this, I believe, would be for critical systems where compromising operation through software modification presents too high a risk. Examples I'm thinking of include: > certain medical devices, such as implants and insulin pumps > subsets of electronic control units for cars These are precisely the opposite of what should be exceptions. If you have a pacemaker implanted in your body, you need t…
Re: Right to root access
#364Re: Right to root access
#365Earlier quoted context omitted.
I contacted the Google through the BBB. Made the statement that lack of ability to install and configure a Kernel level firewall, edit the HOSTS file, and remove unwanted bloat-ware reduces the security of the product. Google agreed their actions do this and said they find the lack of security acceptable. Having a firewall like Little Snitch should be acceptable to know where the phone is communicate, with whom, and…
There are indeed software firewalls on Android that use the VPN functionality to implement something like this so they don't even require root, I believe Glasswire offers one.
Re: Right to root access
#366> The main exception to this, I believe, would be for critical systems where compromising operation through software modification presents too high a risk. Examples I'm thinking of include: > certain medical devices, such as implants and insulin pumps > subsets of electronic control units for cars These are precisely the opposite of what should be exceptions. If you have a pacemaker implanted in your body, you need t…
Disclaimer I don't have a pacemaker: As a biohacker, I think this is a really bad take. I regularly put things [1] in my body of questionable provenance, and then cut them out of myself without anesthesia when they don't suit me anymore, but I like being alive too much to mess with a medical device like a pacemaker. Pacemaker hacking sounds hardcore and like, respect to anyone who does it but I don't think it should…
Also, if someone wants to kill you in your sleep, they... don't need you to even have a pacemaker. And the security of medical devices is notoriously bad, so if you're worried about that sort of thing, be more worried that the status quo doesn't allow you to fix the existing remotely exploitable wireless security vulnerabilities.
Re: Right to root access
#367Earlier quoted context omitted.
It does create an interesting choice, though. For example, certain apps will enforce attestation based on the bootloader status. Even if the user wipes their device and relocks their bootloader with their own keys, this doesn't count as fully secure per the bootloader status. Only Google's keys count. Of course, it is also almost prohibitively difficult to deliver yourself OTA updates after this point. I worry that o…
Right now, although it's possible to use Android with either root or a third party ROM, attestation breaks all sorts of little things. Today this is mostly banking apps, and anything that involves NFC, but this isn't where it's going to end. Attestation requirements are only going to become more prevalent. I predict that in a few years basically all proprietary software for Android will require attestation. So... you…
Re: Right to root access
#368Earlier quoted context omitted.
Disclaimer I don't have a pacemaker: As a biohacker, I think this is a really bad take. I regularly put things [1] in my body of questionable provenance, and then cut them out of myself without anesthesia when they don't suit me anymore, but I like being alive too much to mess with a medical device like a pacemaker. Pacemaker hacking sounds hardcore and like, respect to anyone who does it but I don't think it should…
You pretty obviously don't want to mess with it frivolously . But if there's something wrong with it, and you have to fix it? That seems better than the alternative where you can't. Note that the right to modify it doesn't imply that you're required to in the absence of any reason to. Also, if someone wants to kill you in your sleep, they... don't need you to even have a pacemaker. And the security of medical devices…
That's just it though, in my opinion being able to flash the thing at all would count as a remotely exploitable wireless security vulnerability. The first thing I'd do if mine was flashable is lock it down to make sure it was no longer flashable. Does that make sense? I might not be articulating myself well here.
Re: Right to root access
#369Earlier quoted context omitted.
You pretty obviously don't want to mess with it frivolously . But if there's something wrong with it, and you have to fix it? That seems better than the alternative where you can't. Note that the right to modify it doesn't imply that you're required to in the absence of any reason to. Also, if someone wants to kill you in your sleep, they... don't need you to even have a pacemaker. And the security of medical devices…
> existing remotely exploitable wireless security vulnerabilities That's just it though, in my opinion being able to flash the thing at all would count as a remotely exploitable wireless security vulnerability. The first thing I'd do if mine was flashable is lock it down to make sure it was no longer flashable. Does that make sense? I might not be articulating myself well here.
If it has a mechanism to flash it then they can give you the password for yours so that you can always do it yourself (or have someone do it) in the event that the manufacturer goes out of business before anyone finds the bug.
And if you really want to remove the ability to flash it, you could use your right to flash it to remove that feature, whereas the status quo is that it supports it -- insecurely -- and you aren't allowed to change it.
Re: Right to root access
#370Earlier quoted context omitted.
Unlocking should require a physical modification, like soldering a jumper or flipping an internal switch requiring disassembly. That would filter out basically all scam victims. If a scammer can teach a complete novice how to do micro soldering, they've earned their pay.
The Chromebooks that require removing a single internal screw are a fairly civilized example of this approach (might be a little harder to execute in a phone).