Live data from Hacker News

We should have the ability to run any code we want on hardware we own

hugotunius.se

131–140 of 1001 posts

Re: We should have the ability to run any code we want on hardware we own

#131
post #84

We need both options to coexist: 1. Open, hackable hardware for those who want full control and for driving innovation 2. Locked-down, managed devices for vulnerable users who benefit from protection This concept of "I should run any code on hardware I own" is completely wrong as a universal principle. Yes, we absolutely should be able to run any code we want on open hardware we own - that option must exist. But we s…

The issue with this is that inevitably the locked down devices, which will end up being 98%+ of the market, become required for ordinary living, because no-one will develop for the 2%. Open hardware is essentially useless if I need to carry both an open phone and a phone with the parking app, the banking app, messenger app to contact friends, etc.

For security reasons it makes sense for them to be different devices. People and services may not want to allow insecure devices to communicate with them.

Re: We should have the ability to run any code we want on hardware we own

#132
post #84

We need both options to coexist: 1. Open, hackable hardware for those who want full control and for driving innovation 2. Locked-down, managed devices for vulnerable users who benefit from protection This concept of "I should run any code on hardware I own" is completely wrong as a universal principle. Yes, we absolutely should be able to run any code we want on open hardware we own - that option must exist. But we s…

Incorrect. Choice 2. Empowered user. The end user is free to CHOOSE to delegate the hardware's approved signing solutions to a third party. Possibly even a third party that is already included in the base firmware such as Microsoft, Apple, OEM, 'Open Source' (sub menu: List of several reputable distros and a choice which might have a big scary message and involved confirmation process to trust the inserted boot media…

Keep in mind one of these third parties would almost certainly be Meta (because users want their stuff), and that would almost certainly be a privacy downgrade.

Re: We should have the ability to run any code we want on hardware we own

#133
post #107

Much harder to make a secure device that is resistant to getting pwn'd if you can run any code you want. I personally prefer my iPhone to be more secure than to be more open. Buy a more open phone if you want one, but stop trying to use legal means to force the software on my phone to be worse for my use-case just because you want to have your cake and eat it too.

Once you decide to trade your liberty for security, it becomes the norm and then no one has liberty.

Apple is a company, not a government. I haven't traded my liberty for anything. Again, you can buy a different phone – that is where liberty comes into this equation.

If the USG decides to pass a law saying you can only buy iPhones, then we will have more to talk about w.r.t. liberty.

Nothing actually prevents you from modifying your iPhone however you see fit, btw. If you are incapable of breaking Apple's security without bricking the phone, that's a "you" problem.

Re: We should have the ability to run any code we want on hardware we own

#134
post #86
post #31

> It should be possible to run Android on an iPhone and manufacturers should be required by law to provide enough technical support and documentation to make the development of new operating systems possible As someone who enjoyed Linux phones like the Nokia N900/950 and would love to see those hacker-spirited devices again, statements like this sound more than naïve to me. I can acknowledge my own interests here (ha…

Not to mention, it's an authoritarian attitude, talking about forcing companies to support arbitrary software stacks

[deleted]

Re: We should have the ability to run any code we want on hardware we own

#135
post #84

We need both options to coexist: 1. Open, hackable hardware for those who want full control and for driving innovation 2. Locked-down, managed devices for vulnerable users who benefit from protection This concept of "I should run any code on hardware I own" is completely wrong as a universal principle. Yes, we absolutely should be able to run any code we want on open hardware we own - that option must exist. But we s…

Incorrect. Choice 2. Empowered user. The end user is free to CHOOSE to delegate the hardware's approved signing solutions to a third party. Possibly even a third party that is already included in the base firmware such as Microsoft, Apple, OEM, 'Open Source' (sub menu: List of several reputable distros and a choice which might have a big scary message and involved confirmation process to trust the inserted boot media…

>big scary message

Open question:

Any idea on making it so difficult that grandma isn't even able to follow a phisher’s instructions over the phone but yet nearly trivial for anyone who knows what they’re doing?

Re: We should have the ability to run any code we want on hardware we own

#136
post #84

We need both options to coexist: 1. Open, hackable hardware for those who want full control and for driving innovation 2. Locked-down, managed devices for vulnerable users who benefit from protection This concept of "I should run any code on hardware I own" is completely wrong as a universal principle. Yes, we absolutely should be able to run any code we want on open hardware we own - that option must exist. But we s…

Incorrect. Choice 2. Empowered user. The end user is free to CHOOSE to delegate the hardware's approved signing solutions to a third party. Possibly even a third party that is already included in the base firmware such as Microsoft, Apple, OEM, 'Open Source' (sub menu: List of several reputable distros and a choice which might have a big scary message and involved confirmation process to trust the inserted boot media…

Consider the possibility of an evil maid type attack before a device is setup for the first time, e.g. running near identical iOS or macOS but with spyware preloaded, or even just adware.

Re: We should have the ability to run any code we want on hardware we own

#137
post #84

We need both options to coexist: 1. Open, hackable hardware for those who want full control and for driving innovation 2. Locked-down, managed devices for vulnerable users who benefit from protection This concept of "I should run any code on hardware I own" is completely wrong as a universal principle. Yes, we absolutely should be able to run any code we want on open hardware we own - that option must exist. But we s…

On Steam Deck, you never even have to set a 'sudo' password. You can have a safe managed experience and still allow a device to be open. Option 2 is ridiculous because it will just be exploited by companies and governments that want to control what you do or what content you see.

Re: We should have the ability to run any code we want on hardware we own

#139
post #36

Earlier quoted context omitted.

The primary problem is that we can't build a phone and run it on a cellular carrier network. This is where legislation is needed. Apple and Google are still a problem, but they are a secondary problem.

You kind of can? The carrier network has no way to verify that your cellular modem is a real modem made by a real modem company, and not 3 SDRs in a trench coat standing on the top of each other. The sheer technical difficulty is what makes this kind of thing impractical. The network does validate that a SIM card is a real SIM card, but you can put a "real SIM card" in anything.

IMEI whitelisting is common in the US at least... I think this shuts down the trench coat idea.

Re: We should have the ability to run any code we want on hardware we own

#140
post #36

Earlier quoted context omitted.

The primary problem is that we can't build a phone and run it on a cellular carrier network. This is where legislation is needed. Apple and Google are still a problem, but they are a secondary problem.

You kind of can? The carrier network has no way to verify that your cellular modem is a real modem made by a real modem company, and not 3 SDRs in a trench coat standing on the top of each other. The sheer technical difficulty is what makes this kind of thing impractical. The network does validate that a SIM card is a real SIM card, but you can put a "real SIM card" in anything.

Yeah pretty much. I don't disagree on principal that people should be able to install a custom OS on their device. But in practical terms it doesn't really matter all that much because hardware is so complex and moves so fast that no hobbyist has even close to the time and resources to develop a custom OS for the latest phones.

The M1 Macbook Air is 5 years old now, has an active development, lots of community funding and attention, yet is still missing basic functionality like external monitors and video decoding. Because it's just a mammoth task to support modern hardware. Unless you have a whole paid team on it you've got no hope.

Post reply on HN