Live data from Hacker News

Right to root access

medhir.com

401–410 of 428 posts

Re: Right to root access

#401

Earlier quoted context omitted.

They're definitely not "standard Linux permissions." Yes Android does use many of those (such as standard user IDs, file system permissions, and now SELinux) to implement some of its permissions, but it adds a ton of permissions on top that are not part of Linux.

They are part of what then? Android is built on top of Linux.

They're part of Android. Android is not Linux and Linux is not Android, anymore than a car is a wheel and a wheel is a car. Don't confuse the foundation with the building.

Here's the API reference if you'd like details [1]. They are very much not just standard Linux permissions. Android includes a huge set of APIs on top of Linux

[1] https://developer.android.com/reference/android/Manifest.per...

Re: Right to root access

#402

Earlier quoted context omitted.

I'm using a GNU/Linux phone (Librem 5) as a daily driver, and it has a lot of rough edges. Root access is a no-brainer (it basically runs Debian), but a small company making them can't possibly provide Apple experience.

That's fair. What kind of rough edges did you find? I think I'm OK without any Google services, because I can simply keep another phone just for those and banks/trading platforms.

For me, it's mainly the battery life and the UI lagginess. There are some reviews on the forums: https://forums.puri.sm/t/why-i-stopped-using-my-librem-5-aft..., https://forums.puri.sm/t/librem-5-fatigue/21934.

Re: Right to root access

#403

Earlier quoted context omitted.

Easy doesn't mean without any warning, it just means that the device is unlockable by design and without OEM's approval. It would be reasonable to: - factory reset the device before unlocking it to protect existing data (like Android phones require) - display warnings, for example "if someone's asking you to do this, it's probably a scam" - for the owner to be allowed to permanently disable unlocking, e.g. the common…

> factory reset the device before unlocking it to protect existing data (like Android phones require) I never understood this point. From what threat is it protecting the data from? Surely a thief should not be able to unlock a device without first typing the correct pin/password, and it they can do that they should be able to access the data regardless.

In principle I agree but the edge case I think has to be accounted for is that many people have weak PINs protecting highly sensitive apps (financial, banking) on their phones like that could be backdoored with root access.

There have been times when I really wished that I could OEM unlock my Android device without wiping but overall I think I sleep better knowing that my PIN isn't sufficient to extract all of its data.

Re: Right to root access

#404

Earlier quoted context omitted.

Easy doesn't mean without any warning, it just means that the device is unlockable by design and without OEM's approval. It would be reasonable to: - factory reset the device before unlocking it to protect existing data (like Android phones require) - display warnings, for example "if someone's asking you to do this, it's probably a scam" - for the owner to be allowed to permanently disable unlocking, e.g. the common…

> for the owner to be allowed to permanently disable unlocking, e.g. the commonly cited example of someone setting the device up for their elderly parents This opens a wormhole that warps us back to one of the core issues / battlegrounds in computing: ownership , and specifically, the balance of power and responsibility between the owner and the user, when they're not the same person. Unfortunately, the same means an…

In that scenario I think employers should have the right to make this decision since they own the device and it likely contains sensitive data and credentials belonging to them. But vendors selling devices to retail customers shouldn't be allowed to make that decision unless the customer explicitly asks for help.

I think it's pretty consistent, whoever legally owns the device should be allowed to decide what is and isn't allowed to run on it.

Re: Right to root access

#405

Earlier quoted context omitted.

They are part of what then? Android is built on top of Linux.

They're part of Android. Android is not Linux and Linux is not Android, anymore than a car is a wheel and a wheel is a car. Don't confuse the foundation with the building. Here's the API reference if you'd like details [1]. They are very much not just standard Linux permissions. Android includes a huge set of APIs on top of Linux [1] https://developer.android.com/reference/android/Manifest.per...

KDE and Gnome also implement tons of API on top of Linux ecosystem. Android is Linux system, because it based on Linux.

Re: Right to root access

#406

Earlier quoted context omitted.

> for the owner to be allowed to permanently disable unlocking, e.g. the commonly cited example of someone setting the device up for their elderly parents This opens a wormhole that warps us back to one of the core issues / battlegrounds in computing: ownership , and specifically, the balance of power and responsibility between the owner and the user, when they're not the same person. Unfortunately, the same means an…

In that scenario I think employers should have the right to make this decision since they own the device and it likely contains sensitive data and credentials belonging to them. But vendors selling devices to retail customers shouldn't be allowed to make that decision unless the customer explicitly asks for help. I think it's pretty consistent, whoever legally owns the device should be allowed to decide what is and i…

Yes, my point is that in practice, this gets abused. In particular, the possibility enables vendors to invent business models that rely on denying users ownership, and those happen to outcompete the fair, honest models.

Re: Right to root access

#407

Earlier quoted context omitted.

That's fair. What kind of rough edges did you find? I think I'm OK without any Google services, because I can simply keep another phone just for those and banks/trading platforms.

For me, it's mainly the battery life and the UI lagginess. There are some reviews on the forums: https://forums.puri.sm/t/why-i-stopped-using-my-librem-5-aft... , https://forums.puri.sm/t/librem-5-fatigue/21934 .

Thanks! Looks like some of the concerns are legit. I guess I'll carry two phones if I buy this one. The web browsing experience is the most concerning one -- if that's bad then I might as well use a dumb phone.

Re: Right to root access

#408

Earlier quoted context omitted.

For me, it's mainly the battery life and the UI lagginess. There are some reviews on the forums: https://forums.puri.sm/t/why-i-stopped-using-my-librem-5-aft... , https://forums.puri.sm/t/librem-5-fatigue/21934 .

Thanks! Looks like some of the concerns are legit. I guess I'll carry two phones if I buy this one. The web browsing experience is the most concerning one -- if that's bad then I might as well use a dumb phone.

The web browsing is quite manageable, especially with NoScript. Sent from the phone.

Re: Right to root access

#409
post #399

Earlier quoted context omitted.

I suspect DRM will eventually be self defeating. For example, I prefer to torrent content just so that I can get stuff to play using my media player of choice (and the instant seeks) without any hassle. Most normal people probably aren't even aware this is an option. But with cryptocurrencies normalizing it's only a matter of time before a paid piracy service emerges that is both cheaper, simpler and better than Netf…

I'm a senior person who looks after content protection and anti-piracy at a major streaming company. The idealism of those who want to see the demise of DRM doesn't actually hold up in the face of reality. Even when we remove restrictions and give global access to content, for free, pirates don't give up. One of the reasons is that many pirate sites get ad revenue, piracy is a business for many folk and they get the…

I'm sure you are aware that there are groups (scenes) which break your DRM as a hobby, they sacrifice device keys for 4K HDR content. And they do it for just the reputation.

More money than ever flows into piracy these days.

Even with complete monolithic control (which is an unlikely objective) over the entire chain from distribution to display there will be a way to obtain good quality output from a hijacked LCD controller if nothing else. There is no win condition for you.

Re: Right to root access

#410
post #398
post #364

Earlier quoted context omitted.

Much harder to install a key logger or other such shenanigans.

Install a key logger, when they already have someone on the end of the line willing to install and run whatever software they request? Why? I think the marginal security value of denying root on the computer when you have already wangled root on the human is small.

Prior to modern AI, one could be done at scale, now I suppose both can which may change my calculus on this one. I hadn't thought about that until your comment. Thanks!
Post reply on HN