Live data from Hacker News

We should have the ability to run any code we want on hardware we own

hugotunius.se

151–160 of 1001 posts

Re: We should have the ability to run any code we want on hardware we own

#151
post #84

We need both options to coexist: 1. Open, hackable hardware for those who want full control and for driving innovation 2. Locked-down, managed devices for vulnerable users who benefit from protection This concept of "I should run any code on hardware I own" is completely wrong as a universal principle. Yes, we absolutely should be able to run any code we want on open hardware we own - that option must exist. But we s…

You're wrong.

My hardware. My decision.

Re: We should have the ability to run any code we want on hardware we own

#152

Earlier quoted context omitted.

The hardware should not be equipped with undefeatable digital locks. Put a physical switch on the hardware (like Chromebooks have-- had?) to allow the owner to opt out of the walled garden. Also worrisome are e-fuses, which allow software to make irrevocable physical changes to your hardware. They shouldn't be allowed to be modified except by the owner. (See Nintendo Switch updates blowing e-fuses to prevent downgrad…

E fuses are needed so people can't downgrade the device to old insecure software to exploit it. Without it or an equivalent like a secure monotonic counter how do you think such attacks be protected?

There's a disagreement on who the attacker is. From Nintendo's perspective, the owner of the device is the attacker. From the owners perspective it's Nintendo.

Obviously the parent commenter believes you should be able to exploit your own device and downgrade the OS if you wish.

Re: We should have the ability to run any code we want on hardware we own

#153
post #36

This makes the point that the real battle we should be fighting is not for control of Android/iOS, but the ability to run other operating systems on phones. That would be great, but as the author acknowledges, building those alternatives is basically impossible. Even assuming that building a solid alternative is feasible, though, I don't think their point stands. Generally I'm not keen on legislatively forcing a deve…

The primary problem is that we can't build a phone and run it on a cellular carrier network. This is where legislation is needed. Apple and Google are still a problem, but they are a secondary problem.

But how do we start a movement for these ideas? I feel like there isn’t awareness outside of niche circles and the public may not see the short term benefit. Meanwhile politicians are lobbied by the same corporations and won’t listen.

Re: We should have the ability to run any code we want on hardware we own

#154

Earlier quoted context omitted.

>big scary message Open question: Any idea on making it so difficult that grandma isn't even able to follow a phisher’s instructions over the phone but yet nearly trivial for anyone who knows what they’re doing?

Stop gatekeeping actually useful apps. Nobody should never need to see the message to do anything they actually want to do, otherwise it leads to normalization of deviance. False positives from PC virus scanners are very rare.

What are you on about? The last 10 years of computing the only time windows defender pinged was on false positives.

Re: We should have the ability to run any code we want on hardware we own

#155
post #132

Earlier quoted context omitted.

Keep in mind one of these third parties would almost certainly be Meta (because users want their stuff), and that would almost certainly be a privacy downgrade.

Freedom > Privacy > Security Never give up your freedom. If you have to give up your privacy to ensure your freedom, so be it. If you have to give up your security to ensure your privacy, so be it. This goes for governments and phones.

> This goes for governments and phones.

Apple does not have the ability to throw me in prison or take away my freedoms. Only to not grant me extra freedoms subsidized by their R&D budget.

Re: We should have the ability to run any code we want on hardware we own

#156

I know I'm going to get downvoted to hell for this, but I genuinely think it's OK for a device manufacturer to say: "we are building this device to run this software. If you don't want to run this software, then don't buy this device. There are plenty of other devices out there that will run other software, you can buy one of those if you want to run other software - our devices are designed to only run our software,…

> There are plenty of other devices out there... No there isn't, and one of the main problems.

There are if you are willing to have two devices. One secure phone for banking, phone calls, etc. And a portable linux device for installing whatever you want on. Where installing malware doesn't risk losing all of your money.

Re: We should have the ability to run any code we want on hardware we own

#157

Earlier quoted context omitted.

Freedom > Privacy > Security Never give up your freedom. If you have to give up your privacy to ensure your freedom, so be it. If you have to give up your security to ensure your privacy, so be it. This goes for governments and phones.

> This goes for governments and phones. Apple does not have the ability to throw me in prison or take away my freedoms. Only to not grant me extra freedoms subsidized by their R&D budget.

Apple has removed your freedom from day one.

Their R&D budget is at the expense of a free market that would have delivered the same or better products.

Did you ever see how wild and innovative the Japanese mobile phones were before iPhone monoculture took over?

I want crazy stuff like a smartphone that has the form factor of a Raspberry Pi. Or a smartphone with e-Ink. Crazy new categories of devices.

Sadly, the Apple/Google monopoly has turned smartphones into one of the shittiest, most locked down device categories. It's a death place for innovation.

Re: We should have the ability to run any code we want on hardware we own

#158

Earlier quoted context omitted.

Incorrect. Choice 2. Empowered user. The end user is free to CHOOSE to delegate the hardware's approved signing solutions to a third party. Possibly even a third party that is already included in the base firmware such as Microsoft, Apple, OEM, 'Open Source' (sub menu: List of several reputable distros and a choice which might have a big scary message and involved confirmation process to trust the inserted boot media…

>big scary message Open question: Any idea on making it so difficult that grandma isn't even able to follow a phisher’s instructions over the phone but yet nearly trivial for anyone who knows what they’re doing?

Sure. You ship the device in open mode, and then doing it is easy. The device supports closed mode (i.e. whatever the currently configured package installation sources are, you can no longer add more), and if you put the device in closed mode, getting it back out requires attaching a debugger to the USB port, a big scary message and confirmation on the phone screen itself, and a full device wipe.

Then you put grandma's device in closed mode and explicitly tell her never to do the scary thing that takes it back out again and call you immediately if anyone asks her to. Or, for someone who is not competent to follow that simple instruction (e.g. small children or senile adults), you make the factory reset require a password and then don't give it to them.

Re: We should have the ability to run any code we want on hardware we own

#159
post #36

This makes the point that the real battle we should be fighting is not for control of Android/iOS, but the ability to run other operating systems on phones. That would be great, but as the author acknowledges, building those alternatives is basically impossible. Even assuming that building a solid alternative is feasible, though, I don't think their point stands. Generally I'm not keen on legislatively forcing a deve…

The primary problem is that we can't build a phone and run it on a cellular carrier network. This is where legislation is needed. Apple and Google are still a problem, but they are a secondary problem.

I don't think the cellular network is the problem at all - everything except SMS and PSTN calls works on wifi. The problem is the apps. Netflix only runs on a verified bona fide electrified six car Google- or Apple-approved device; so do most financial apps (EU law requires them to) and basically everything else where the app developers are trying to get money off you (which is most apps). Some apps will refuse to play ads on a non-genuine device and then refuse to function because you aren't watching ads. Play Store does its best to stop you installing its apps on a nongenuine device, but it has to support older devices without TPMs so it's not fully locked down yet. Even YouTube has some level of attestation.

Re: We should have the ability to run any code we want on hardware we own

#160

Earlier quoted context omitted.

> more stress tested and vetted by more people Grandma and grandpa aren't reading the source code and certainly not up at a professional level. This is one of the core misconceptions of the "free/libre" formulation of OSS.

I’m not suggesting grandpa reads code, contributors do. We all know that most commercial code is much shittier than open source. Sure, commercial code usually covers more edge cases and has better UX, but is cobbled together from legacy and random product asks.

> contributors do

More users != more contributors. As software gets more popular, you begin getting 10, 100, 1000, 1,000,000 users for every contributor.

This doesn't just affect non-programmers. We can't even police NPM.

People want it to be true so that it will be a talking point, but it's not true, and we need to find new talking points that align with facts that are evident outside the echo chambers.

Post reply on HN