Live data from Hacker News

We should have the ability to run any code we want on hardware we own

hugotunius.se

141–150 of 1001 posts

Re: We should have the ability to run any code we want on hardware we own

#141
post #84

We need both options to coexist: 1. Open, hackable hardware for those who want full control and for driving innovation 2. Locked-down, managed devices for vulnerable users who benefit from protection This concept of "I should run any code on hardware I own" is completely wrong as a universal principle. Yes, we absolutely should be able to run any code we want on open hardware we own - that option must exist. But we s…

> The problem isn't that locked-down devices exist - it's that we don't have enough truly open alternatives for those who want them.

The problems is that vendors use "locked down devices" as an excuse to limit competition.

Suppose you have a "locked down" device that can only install apps from official sources, but "official sources" means Apple, Google, Samsung or Amazon. Moreover, you can disable any of these if you want to (requiring a factory reset to re-enable), but Google or Apple can't unilaterally insist that you can't use Amazon, or for that matter F-Droid etc.

Let the owner of the device lock it down as much as they want. Do not let the vendor do this when the owner doesn't want it.

Re: We should have the ability to run any code we want on hardware we own

#142

Earlier quoted context omitted.

Incorrect. Choice 2. Empowered user. The end user is free to CHOOSE to delegate the hardware's approved signing solutions to a third party. Possibly even a third party that is already included in the base firmware such as Microsoft, Apple, OEM, 'Open Source' (sub menu: List of several reputable distros and a choice which might have a big scary message and involved confirmation process to trust the inserted boot media…

>big scary message Open question: Any idea on making it so difficult that grandma isn't even able to follow a phisher’s instructions over the phone but yet nearly trivial for anyone who knows what they’re doing?

Fix the phone system so calls must positively identify themselves.

There is no reason anyone purporting to be from a business or the government should be able to place a call without cryptographically proving their identity.

Re: We should have the ability to run any code we want on hardware we own

#143

Earlier quoted context omitted.

Incorrect. Choice 2. Empowered user. The end user is free to CHOOSE to delegate the hardware's approved signing solutions to a third party. Possibly even a third party that is already included in the base firmware such as Microsoft, Apple, OEM, 'Open Source' (sub menu: List of several reputable distros and a choice which might have a big scary message and involved confirmation process to trust the inserted boot media…

>big scary message Open question: Any idea on making it so difficult that grandma isn't even able to follow a phisher’s instructions over the phone but yet nearly trivial for anyone who knows what they’re doing?

Stop gatekeeping actually useful apps. Nobody should never need to see the message to do anything they actually want to do, otherwise it leads to normalization of deviance.

False positives from PC virus scanners are very rare.

Re: We should have the ability to run any code we want on hardware we own

#144
You already have that ability, afaik there is nothing stopping you or your friends from loading and running whatever software you want except your own technical ability.

If you want the government to force other people to do the work to let you have your cake and eat it too, I can't support that.

Re: We should have the ability to run any code we want on hardware we own

#145
post #84

We need both options to coexist: 1. Open, hackable hardware for those who want full control and for driving innovation 2. Locked-down, managed devices for vulnerable users who benefit from protection This concept of "I should run any code on hardware I own" is completely wrong as a universal principle. Yes, we absolutely should be able to run any code we want on open hardware we own - that option must exist. But we s…

Incorrect. Choice 2. Empowered user. The end user is free to CHOOSE to delegate the hardware's approved signing solutions to a third party. Possibly even a third party that is already included in the base firmware such as Microsoft, Apple, OEM, 'Open Source' (sub menu: List of several reputable distros and a choice which might have a big scary message and involved confirmation process to trust the inserted boot media…

This.

We need a mobile bill of rights for this stuff.

- The devices all of society has standardized upon should not be owned by companies after purchase.

- The devices all of society has standardized upon should not have transactions be taxed by the companies that make them, nor have their activities monitored by the companies that make them. (Gaming consoles are very different than devices we use to do banking and read menus at restaurants.)

- The devices all of society has standardized upon should not enforce rules for downstream software apart from heuristic scanning for viruses/abuse and strong security/permissions sandboxing that the user themselves controls.

- The devices all of society has standardized upon should be strictly regulated by governments all around the world to ensure citizens and businesses cannot be strong-armed.

- The devices all of society has standardized upon should be a burden for the limited few companies that gate keep them.

Re: We should have the ability to run any code we want on hardware we own

#146

It's a matter of ownership vs. licensing. You own the hardware you buy, but you license the software. I agree with the author that as long as you use that software, you should be subject to the constraints of the license. The key is that if you choose not to run that software, your hardware should not be constrained. You own the hardware, it's a tangible thing that is your property. Boils down to a consumer rights is…

The hardware should not be equipped with undefeatable digital locks. Put a physical switch on the hardware (like Chromebooks have-- had?) to allow the owner to opt out of the walled garden. Also worrisome are e-fuses, which allow software to make irrevocable physical changes to your hardware. They shouldn't be allowed to be modified except by the owner. (See Nintendo Switch updates blowing e-fuses to prevent downgrad…

E fuses are needed so people can't downgrade the device to old insecure software to exploit it. Without it or an equivalent like a secure monotonic counter how do you think such attacks be protected?

Re: We should have the ability to run any code we want on hardware we own

#147
post #132

Earlier quoted context omitted.

Incorrect. Choice 2. Empowered user. The end user is free to CHOOSE to delegate the hardware's approved signing solutions to a third party. Possibly even a third party that is already included in the base firmware such as Microsoft, Apple, OEM, 'Open Source' (sub menu: List of several reputable distros and a choice which might have a big scary message and involved confirmation process to trust the inserted boot media…

Keep in mind one of these third parties would almost certainly be Meta (because users want their stuff), and that would almost certainly be a privacy downgrade.

Freedom > Privacy > Security

Never give up your freedom.

If you have to give up your privacy to ensure your freedom, so be it.

If you have to give up your security to ensure your privacy, so be it.

This goes for governments and phones.

Re: We should have the ability to run any code we want on hardware we own

#148

Earlier quoted context omitted.

The issue with this is that inevitably the locked down devices, which will end up being 98%+ of the market, become required for ordinary living, because no-one will develop for the 2%. Open hardware is essentially useless if I need to carry both an open phone and a phone with the parking app, the banking app, messenger app to contact friends, etc.

For security reasons it makes sense for them to be different devices. People and services may not want to allow insecure devices to communicate with them.

Why? It's not like the insecure device doesn't have my identity key on it. If I program it to spam people, I go to jail for spamming.

Re: We should have the ability to run any code we want on hardware we own

#149
post #79
post #55

EU is dropping the ball here. Instead of mandating open hardware they trying to force companies to comply with random stuff, mostly censorship and spying. In theory EU can mandate open bootloaders like EU mandates USB-C charging, but they won't. Open hardware is the enemy of the EU, since that means everyone would be able to bypass the chatcontrol of the day.

Eu has the Digital Markets Act and what google is doing is illegal in Eu. Gatekeepers must allow people to side-load software by regulation. Makes me think that google did this now since trump has been criticizing the DMA, so now they feel empowered by their leader to break the law

Google does still let you sideload though. The publisher has to submit ID but other than that, there are no restrictions.

Re: We should have the ability to run any code we want on hardware we own

#150
post #84

We need both options to coexist: 1. Open, hackable hardware for those who want full control and for driving innovation 2. Locked-down, managed devices for vulnerable users who benefit from protection This concept of "I should run any code on hardware I own" is completely wrong as a universal principle. Yes, we absolutely should be able to run any code we want on open hardware we own - that option must exist. But we s…

> Locked-down, managed devices for vulnerable users who benefit from protection Thats fine! Just make sure it is possible for someone to take the same device and remove the locked down protections. Make it require a difficult/obvious factory reset to enable, if you are concerned about someone being "tricked" into turning off the lockdown. If someone wants baby mode on, all power too them! Thats their choice. Just lik…

> Make it require a difficult/obvious factory reset to enable, if you are concerned about someone being "tricked" into turning off the lockdown.

Is there also a way to make it obvious to the user that a device is running non-OEM software? For example, imagine someone intercepts a new device parcel, flashes spyware on it, then delivers it in similar/the same packaging unbeknownst to the end user. The same could be said for second-hand/used devices.

It's potentially possible the bootrom/uefi/etc bootup process shows some warning for x seconds on each boot that non-OEM software is loaded, but for that to happen you need to be locked out of being able to flash your own bootrom to the device.

Post reply on HN