Live data from Hacker News

We should have the ability to run any code we want on hardware we own

hugotunius.se

171–180 of 1001 posts

Re: We should have the ability to run any code we want on hardware we own

#171

Earlier quoted context omitted.

Sure. You ship the device in open mode, and then doing it is easy. The device supports closed mode (i.e. whatever the currently configured package installation sources are, you can no longer add more), and if you put the device in closed mode, getting it back out requires attaching a debugger to the USB port, a big scary message and confirmation on the phone screen itself, and a full device wipe. Then you put grandma…

Very nice! I’m sure I’m missing a problem with the following approach: shipping in _closed_ mode with a sticker on the front notifying the person they should do a factory reset immediately to make sure they can do everything they want to do. During the reset, include a scary message for those who opt in to get to open mode. Everyone simply goes by defaults so it would only be technical people presumably who would eve…

The problem with that is the owner has to choose which package sources they want to allow before the device is in closed mode, because after that adding more requires the scary reset, and the vendor of course has the perverse incentive to ship the device in closed mode with only their own store enabled, which has to be prohibited because it's anti-competitive.

Re: We should have the ability to run any code we want on hardware we own

#172

Earlier quoted context omitted.

Incorrect. Choice 2. Empowered user. The end user is free to CHOOSE to delegate the hardware's approved signing solutions to a third party. Possibly even a third party that is already included in the base firmware such as Microsoft, Apple, OEM, 'Open Source' (sub menu: List of several reputable distros and a choice which might have a big scary message and involved confirmation process to trust the inserted boot media…

Consider the possibility of an evil maid type attack before a device is setup for the first time, e.g. running near identical iOS or macOS but with spyware preloaded, or even just adware.

We already have that today. And locked down systems don't prevent it, because you can always exploit some part of the supply chain. A determined actor will always find a path.

Re: We should have the ability to run any code we want on hardware we own

#173
It has never been easier to realize your own open source hardware platform. Those dedicated to freedom can chose to offer alternatives. The challenge is we don't live in a post job society and people need to make money to survive. Until that changes, practical professionals will gravitate towards non-ideal systems that optimize for short term value over freedom.

Re: We should have the ability to run any code we want on hardware we own

#174
post #79
post #55

EU is dropping the ball here. Instead of mandating open hardware they trying to force companies to comply with random stuff, mostly censorship and spying. In theory EU can mandate open bootloaders like EU mandates USB-C charging, but they won't. Open hardware is the enemy of the EU, since that means everyone would be able to bypass the chatcontrol of the day.

Eu has the Digital Markets Act and what google is doing is illegal in Eu. Gatekeepers must allow people to side-load software by regulation. Makes me think that google did this now since trump has been criticizing the DMA, so now they feel empowered by their leader to break the law

Side loading is absolutely not equal open bootloader!

Re: We should have the ability to run any code we want on hardware we own

#175
post #151
post #84

We need both options to coexist: 1. Open, hackable hardware for those who want full control and for driving innovation 2. Locked-down, managed devices for vulnerable users who benefit from protection This concept of "I should run any code on hardware I own" is completely wrong as a universal principle. Yes, we absolutely should be able to run any code we want on open hardware we own - that option must exist. But we s…

You're wrong. My hardware. My decision.

I don't think it will convince you in any way, but the whole point is/will be that it's not your hardware, you're paying for a perpetual license to use a terminal bound to someone else's service.

Re: We should have the ability to run any code we want on hardware we own

#176

Earlier quoted context omitted.

> There are plenty of other devices out there... No there isn't, and one of the main problems.

There are if you are willing to have two devices. One secure phone for banking, phone calls, etc. And a portable linux device for installing whatever you want on. Where installing malware doesn't risk losing all of your money.

> secure phone for banking

Secure from the owner doesn't equal security in general.

I know of no reasonable, modern Linux devices besides the Starlite tablet and potentially the Furiphone. And boy, have I looked and looked. But the second has not been around long enough to be reviewed by a reputable entity.

Re: We should have the ability to run any code we want on hardware we own

#177
post #84

We need both options to coexist: 1. Open, hackable hardware for those who want full control and for driving innovation 2. Locked-down, managed devices for vulnerable users who benefit from protection This concept of "I should run any code on hardware I own" is completely wrong as a universal principle. Yes, we absolutely should be able to run any code we want on open hardware we own - that option must exist. But we s…

Incorrect. Choice 2. Empowered user. The end user is free to CHOOSE to delegate the hardware's approved signing solutions to a third party. Possibly even a third party that is already included in the base firmware such as Microsoft, Apple, OEM, 'Open Source' (sub menu: List of several reputable distros and a choice which might have a big scary message and involved confirmation process to trust the inserted boot media…

I like the way Chromebooks do things, initially locking down the hardware but allowing you to do whatever if you intentionally know what you're doing (after wiping the device for security reasons). It's a pity that there's all the Google tracking in them that's near impossible to delete (unless you remove Chrome OS).

Re: We should have the ability to run any code we want on hardware we own

#178
The only way this happens is if people & organizations vote with their $$.

My immediate follow-up to people who take this position: Are you using Framework laptops, pinephone or other OSS devices already? If not, then it's just empty air -- vote with your $$.

Re: We should have the ability to run any code we want on hardware we own

#179
> When Google restricts your ability to install certain applications they aren’t constraining what you can do with the hardware you own, they are constraining what you can do using the software they provide with said hardware.

No. Incorrect. Because the argument that we should be focusing on software is a distraction. They use restricting the OS as an argument to restrict the Hardware. Their is pressure put on on hardware devs to toe this line.

You can see this with secure enclaves. If they didn't care about what software was running on their hardware, they wouldn't be designing hardware to restrict the kind of OS you can run on the hardware. Secure Boot/UEFI is going in that direction and Mobile devices are already there to some extent.

This whole argument is a distraction designed to lure people away from the real problem. That all technology (Hardware and Software) is being designed to restrict freedoms. If you are focus on this distraction, you are missing the point.

Re: We should have the ability to run any code we want on hardware we own

#180

This makes the point that the real battle we should be fighting is not for control of Android/iOS, but the ability to run other operating systems on phones. That would be great, but as the author acknowledges, building those alternatives is basically impossible. Even assuming that building a solid alternative is feasible, though, I don't think their point stands. Generally I'm not keen on legislatively forcing a deve…

> Google and Apple have more power than most nations.

To push further, Google and Apple have basically as much power as the US.

The UK going after Apple, only to get rebutted by the US is the most simple instance of it. International treaties pushed by the US strongly protecting it's top corporations is the more standard behavior.

Any entity fighting the duopoly is effectively getting into a fight with the US.

Post reply on HN