Live data from Hacker News

We should have the ability to run any code we want on hardware we own

hugotunius.se

431–440 of 1001 posts

Re: We should have the ability to run any code we want on hardware we own

#431
post #31

> It should be possible to run Android on an iPhone and manufacturers should be required by law to provide enough technical support and documentation to make the development of new operating systems possible As someone who enjoyed Linux phones like the Nokia N900/950 and would love to see those hacker-spirited devices again, statements like this sound more than naïve to me. I can acknowledge my own interests here (ha…

>“Hardware I own” sounds like you bought a pan and demand the right to cook any food you want. Because I did. How come I can do what I want with my computer, but not my phone? Why are phones so inferior in this area? My phone is more powerful than many of the computers I've had in the past, yet I need to jump through a million hoops to use it as a software development platform. Why?

Your smartwatch is probably more powerful than some of your past computers too. Same with your DSLR camera. Even your smart fridge. These are specialized hardware+software gadgets designed to a particular purpose, which is very different from being a development platform. Same with a phone.

Re: We should have the ability to run any code we want on hardware we own

#432

Earlier quoted context omitted.

All this will do is ensure that if malware does get through the official channels (which it can and regularly does) it will be more widely distributed

Security doesn't need to be 100% effective to add value. The more hoops we make scammers jump through, the fewer people will end up getting scammed. I know angle grinders exist. I still lock up my bike.

Scams have absolutely nothing to do with anything relevant. Scams happen regardless of whether software is installed in the first place. Social engineering is what most scams are based on. Refusing me banking access because I want to use my phone as a computer brings extra security to nobody.

Re: We should have the ability to run any code we want on hardware we own

#433
post #393

Earlier quoted context omitted.

For someone who hasn't spent any time thinking about that matter, could you please elaborate your point?

Imagine using ssh-keygen, but it locks the private key in a vendor-managed secure enclave. You can't copy it, export it, rename it or do anything wth it.

I don't just imagine it, I do it, by using gpg-agent as my ssh-agent and using the private key generated by a Yubikey. Another way is to use tpm2-tools so only your laptop running your own signed boot chain can use the key. It is desirable to lock private key material in a physical thing that is hard to steal.

You can choose not to do this, and that's fine. Hardware attestation is dead because Apple refuses to implement it, so no one can force you to.

Re: We should have the ability to run any code we want on hardware we own

#434
post #430

Much harder to make a secure device that is resistant to getting pwn'd if you can run any code you want. I personally prefer my iPhone to be more secure than to be more open. Buy a more open phone if you want one, but stop trying to use legal means to force the software on my phone to be worse for my use-case just because you want to have your cake and eat it too.

Nobody said that... You can keep your device enslaved to Apple all you want. You don't have to use the administrator permissions on Windows if you don't want them. Some of us do want freedom You've got it completely backwards that having the option to control your hardware means you, as an individual, are impacted by anything at all if you don't want to administrate your own device

How do you enable administrator permissions on your Windows computer?

Re: We should have the ability to run any code we want on hardware we own

#435
post #201

Start with buying the right hardware. Fairphone offers more control over the hardware: https://support.fairphone.com/hc/en-us/articles/104924762388... https://www.fairphone.com/

The OS they ship has Google services on it. They've previously chosen not to give you root access by default because Google wouldn't allow it: https://forum.fairphone.com/t/fairphone-s-approach-to-root-o...

They'll make the same choice again because it's not really a choice. Nobody would buy the device, or could make much use of it, without Google services on it. They'd be out of business

Edit, to be clear: that is not to say I disagree with what they do. They allow you to unlock the bootloader and they even supply an open and degoogled version of the OS! That is more than any other vendor I'm aware of. Every time I need a new phone, I check if the latest Fairphone fits my needs, and even though it's a compromise, I've tried it out in the past for several weeks. It's really worth supporting. But Google's new restriction will almost certainly affect Fairphone users, too

Re: We should have the ability to run any code we want on hardware we own

#436
post #165

> In this context this would mean having the ability and documentation to build or install alternative operating systems on this hardware It doesn't work. Everything from banks to Netflix and others are slowly edging out anything where they can't fully verify the chain of control to an entity they can have a legal or contractual relationship with. To be clear, this is fundamental, not incidental. You can't run your o…

We need legislation mandating that all hardware[a] have at least one fully-functional[b] open source driver for any operating system[c]. And that any device with a microprocessor with writable memory permit custom software to be run on it.

[a] whether that's a single device like a fingerprint scanner, or a device like a phone or tablet

[b] no crippled or low-performance open source driver

[c] any OS, including Windows, Mac, Linux, BSD, or some obscure minor OS as long as such OS is readily available for free or for a reasonable price

Re: We should have the ability to run any code we want on hardware we own

#437
post #317

Earlier quoted context omitted.

Netflix is right in its prime right now, K-Pop Demon Hunters is a smash hit and probably the biggest cultural thing going on right now, it has like 4 songs from it in the top 10. Wednesday is coming back this weekfor the end of season 2. Stranger Things is wrapping up in November,

Any other examples? None of those scream prime to me - however I haven't heard of kpop demon hunters

Maybe it's the marketing? It's on the main home page every time I open it.

Re: We should have the ability to run any code we want on hardware we own

#438
post #165

> In this context this would mean having the ability and documentation to build or install alternative operating systems on this hardware It doesn't work. Everything from banks to Netflix and others are slowly edging out anything where they can't fully verify the chain of control to an entity they can have a legal or contractual relationship with. To be clear, this is fundamental, not incidental. You can't run your o…

Joining all the other comments agreeing completely with this take.

I think it's worth adding that this is fundamental enough to not just be a tech issue. There's a strong legal framework in almost all developed companies for regulating companies where acting in their self interest harms the consumer interest. Without which, lots of things we take for granted (electrical safety certification, usb c, splits between serviceand investment banking).

I think the key thing that's missing at the moment is that the types of restrictions OP is mentioning (DRM, blocking encryption) harm both consumer rights and economic development.

That's an argument that needs to come from people knowledgable about both the indistry, and the technology. Like a lot of the people reading this post.

Re: We should have the ability to run any code we want on hardware we own

#439
post #245
post #165

> In this context this would mean having the ability and documentation to build or install alternative operating systems on this hardware It doesn't work. Everything from banks to Netflix and others are slowly edging out anything where they can't fully verify the chain of control to an entity they can have a legal or contractual relationship with. To be clear, this is fundamental, not incidental. You can't run your o…

You could just not watch Netflix. Most of the content is kind of crap anyway, low effort filler. And the streaming services have trouble even licensing third-party content at all unless they have robust copy protection. That may be stupid because it drives more consumers to privacy but copyright holders are free to negotiate any licensing terms they want.

You could also not bother with any of it and return to a dumb phone. That's not a solution though.

Re: We should have the ability to run any code we want on hardware we own

#440
post #201

Start with buying the right hardware. Fairphone offers more control over the hardware: https://support.fairphone.com/hc/en-us/articles/104924762388... https://www.fairphone.com/

I feel like such initiatives miss one obvious target - the well heeled tech savvy user (who quite often is also privacy minded) and wants the latest. At the price point they are selling a Snapdragon 7 device, I can get a Snapdragon 8 Elite phone from the market quite easily. Now I am happy to pay more because of what they stand for but I don't see them selling a model that features the latest and greatest + the priva…

> Surely the latest hardware and privacy/environmental responsibility are not mutually exclusive.

It pretty much is. The engineering for bringing out a latest-and-greatest device and opening it up is something a small independent outfit can't afford, and the big companies capable of it are not interested in doing it.

Post reply on HN