Live data from Hacker News

Right to root access

medhir.com

391–400 of 428 posts

Re: Right to root access

#391
post #280

Earlier quoted context omitted.

What's even worse is that some won't even let you take a damn screenshot. "Disabled by your administrator." If that doesn't scream the fact that my device is in fact owned by someone else, I don't know what is.

With root + LSPosed + this LSPosed module https://github.com/LSPosed/DisableFlagSecure it works in every app again on YOUR phone. I also have root and all my banking apps work currently ... but it's a cat-and-mouse game.

[deleted]

Re: Right to root access

#392
post #280

Earlier quoted context omitted.

What's even worse is that some won't even let you take a damn screenshot. "Disabled by your administrator." If that doesn't scream the fact that my device is in fact owned by someone else, I don't know what is.

With root + LSPosed + this LSPosed module https://github.com/LSPosed/DisableFlagSecure it works in every app again on YOUR phone. I also have root and all my banking apps work currently ... but it's a cat-and-mouse game.

[deleted]

Re: Right to root access

#393

Earlier quoted context omitted.

"everyone is too stupid to be trusted with general purpose computers" is a pretty grim position to hold

A grim position that accurately reflects my 36 years of experience involving people and computers.

Is it about computers only, or should the people be protected from themselves in every aspect of life?

Re: Right to root access

#394

Earlier quoted context omitted.

The vendor can install a Trojan horse on every phone, then activate it silently when his customers does something suspicious. It also very useful feature for law enforcement agencies and foreign spies.

You have to trust the vendor. You have no choice. You cannot personally tell whether it is trustworthy or not.

[deleted]

Re: Right to root access

#395

Earlier quoted context omitted.

The problem with bootloader unlocking on modern Android devices is that they have a hypervisor that you don't get to ever unlock but that will snitch on you and make some apps, like some banking ones, refuse to work because the "integrity" of your device could not be verified. In other words, because these apps can no longer be certain they are able to hide data from you the device owner. Magisk exists, yes, but it's…

If software doesn't want to run on your hardware because it can't make sure you're not tampering with it, why is it wrong for doing so? You're not necessarily entitled to the ability to run the software right? I understand the implications this has on ones ability to create custom operating systems is troubling (eg this could destroy desktop Linux), but at the end of the day I guess it is just a choice the developer…

> If software doesn't want to run on your hardware because it can't make sure you're not tampering with it, why is it wrong for doing so?

It's an invasion of my privacy.

Re: Right to root access

#396

Earlier quoted context omitted.

> Damage caused by the customer isn't covered by any warranty anyway Exactly. We charged the guy for what he did. We gave him 'sa' access to the database and he tried to burn us. I think you may be assuming people act rationally? They do not. Most will but you will always get 'that guy' especially at scale. People will lie about what they have done. Or not even realize what they did goofed things up. In my example th…

That seem extremely frustrating. It does seem like there ought to be a reasonable split between personal software and business stuff. I mean you guys had a big contract, it is some negotiated thing between two peers, it could be reasonable to negotiate root in some subsystems, not in others. In the end you can’t really trust anything a system tells you if somebody has full root of it. It seems like you guys keeping c…

It was frustrating. As it was me who got to speed weeks figuring out what this guy did. My group figured out the root cause though was the software was not doing what he wanted. So we made up a new group to sell that custom service to others. Everyone eventually came out ahead there. Because someone in his management chain realized that we had a good breach of contract case. Weird is nice for what he was doing. He was being a jerk because the stuff was forced on him. It broke his small empire of spreadsheets he was holding the company hostage with. Our 'mistake' was assuming our customers were rational. Many are. But you always have a handful that seem to just be in a bad place in life and they like to take it out on others.

For IoT devices/cell/etc it could be 'bad' to give out the root password from a company PoV. As there are so many out there with the exact same password on several thousand devices (poor security but you can image a thousand devices in a few hours). So once given out it is written down into some wiki and everyone has it now (welcome to the botnet). So if you get one change whatever you were given and assume everyone else has it. Or maybe the 'secret sauce app' is under some random user account. But give out root and that special secret account is bypassed. Then it is off to china somewhere to be ripped apart and resold under a new brand name and half the cost.

Then on top of that lets say you are a nice company giving the thing out. That means you will need some sort of training for your support guys. Documentation on how to do it. And so on. Those things cost money for a EoL product you no longer make anything on.

Like I said there is a list of things as to why not to do it. There is also an interesting list of why to do it. But the upside is low for the company to allow it. I wish more companies would do it. But it is rare.

If people want companies to do this, the company has to be incentivized to want to spend any time/money on it. If people can make this an upside to companies doing this and not 'shame' and 'you broke the law' the companies will help.

Re: Right to root access

#397

Earlier quoted context omitted.

A grim position that accurately reflects my 36 years of experience involving people and computers.

Is it about computers only, or should the people be protected from themselves in every aspect of life?

"should the people be protected from themselves"

There's a line from Blazing Saddles that comes to mind...

Re: Right to root access

#398
post #364
post #312

Earlier quoted context omitted.

Interesting example. How does denying root to the user mitigate this attack?

Much harder to install a key logger or other such shenanigans.

Install a key logger, when they already have someone on the end of the line willing to install and run whatever software they request? Why?

I think the marginal security value of denying root on the computer when you have already wangled root on the human is small.

Re: Right to root access

#399

The reason why this will never happen is simply due to things like DRM. We right now have ENCRYPTED signal going from our computer to our displays, not just computers, but phones too SIMPLY to prevent people from dumping raw data. All of that extra processing done just so you're allowed to for ex: watch netflix with a resolution higher than 720p. Then comically there's Chinese capture cards that you plug your GPU int…

I suspect DRM will eventually be self defeating. For example, I prefer to torrent content just so that I can get stuff to play using my media player of choice (and the instant seeks) without any hassle. Most normal people probably aren't even aware this is an option. But with cryptocurrencies normalizing it's only a matter of time before a paid piracy service emerges that is both cheaper, simpler and better than Netf…

I'm a senior person who looks after content protection and anti-piracy at a major streaming company.

The idealism of those who want to see the demise of DRM doesn't actually hold up in the face of reality. Even when we remove restrictions and give global access to content, for free, pirates don't give up. One of the reasons is that many pirate sites get ad revenue, piracy is a business for many folk and they get the benefit of not paying for the most expensive part. They also don't have legal/regulatory compliance, taxes and will often operate their infrastructure using stolen credit cards or accounts (we can see this).

Then you have people who are selling legitimately and trying to provide the best service for customers, but who have to pay for the content, competing with people who don't have any such responsibilities. So, customers take the cheap deal.

Some folk are also under the assumption that streaming services are money grabbing. Except when you actually look, most streaming services are running at a loss, or barely profitable.

I'm just working to protect our company and reduce losses, ultimately I am not preventing people getting access to fresh food or water. I am protecting premium goods from being illegitimately exploited and protecting the jobs of my colleagues when we're already under significant cost pressures.

One reason I post about these things on the internet is in the hope that one day we might have a constructive dialogue about how to balance freedoms AND enable commerce. But at the moment we have extremism, libertarian ideals against company lawyers.

Re: Right to root access

#400

Earlier quoted context omitted.

FWIW, I have no idea if this is any good. My point is, I found this after maybe 3 minutes searching. If we were to spend 30 minutes, we would definitely find something reasonable.

I'm using a GNU/Linux phone (Librem 5) as a daily driver, and it has a lot of rough edges. Root access is a no-brainer (it basically runs Debian), but a small company making them can't possibly provide Apple experience.

That's fair. What kind of rough edges did you find? I think I'm OK without any Google services, because I can simply keep another phone just for those and banks/trading platforms.
Post reply on HN