Live data from Hacker News

Pixel phones are sold with bootloader unlocking disabled

fitzsim.org

101–110 of 359 posts

Re: Pixel phones are sold with bootloader unlocking disabled

#101
ELI5 - everything about a phone only works when the carrier allows it to connect to the network.

So, the way this is done is to, well, connect to the network and allow the phone to be unlocked - which according to the article is what happened?

So the real complaint is that the Pixel can't be loaded with a customized Android OS (or Linux, etc.) without being connected to the internet first and this is bad because the vendor might put bloatware, spyware, etc. on the phone, which, once you install your OS will be gone anyway?

OK, well then other than the underlying hardware needing to still be recognized on the carrier's network, which pretty much means you still have to be connected. The point is you aren't going to be stealthy using the carrier network on a phone, so at the EOD you have a pretty expensive device you can really only use on WIFI using your own VPN without the Vendor's software.

So what's the advantage over a small tablet based on OTS SOC hardware that you have full control over? IOW why buy the phone in the first place?

Re: Pixel phones are sold with bootloader unlocking disabled

#103
post #81

Earlier quoted context omitted.

Ha. Your example is rather specific seeming to me, as I actually work on one of the big 5 Canadian banking iOS apps here in Toronto. For obvious reasons; we don’t ship to alternate stores - even if such a thing as iOS sideloading existed; we wouldn’t support it, and we of course do not support anything but the Play Store on Android. It’s obviously partly a support cost issue - there would be less than 1% of our milli…

> I think for a while we even had some sort of check that would detect a jailbroken iPhone or rooted Android device and attempted to refuse to run on them. Your uncertainty about this suggests it's not something you decided, but please let anyone involved in making decisions like that know that's a dick move. It's the user's device, not the bank's.

Oh, I certainly have absolutely no control over those types of decisions. I'm a soldier, not a general, I just do what I'm told, tbh.

Re: Pixel phones are sold with bootloader unlocking disabled

#104
post #74

Earlier quoted context omitted.

Not allowing a bootloader to be unlocked on a company-owned device does sound like a desirable feature, but only for company-owned devices. Applying that setup to all phones assumes that the default phone is a company-owned device and is subject to external control.

It assumes that company owned and managed phones are more common than people who want to unlock the bootloader. I know this isn't ideal, but that's the correct assumption to make.

That’s a stupid false dichotomy caused by a poor onboarding workflow. “Well we either make it easier for businesses or deny the right to literally every customer to own their device. It’s okay because most people won’t notice.”

Re: Pixel phones are sold with bootloader unlocking disabled

#105

Earlier quoted context omitted.

> So I’m guessing with this you’d use an alternative store like F-Droid instead of the Play Store? Not necessarily, but that's the best way to do it. Between apps from F-Droid and a browser, you don't need any apps from the play store. Your bank doesn't have an app on F-Droid you might say? Well that's what the browser is for.

Erm, why would you ever want an app for your bank on your mobile phone ? So that when you get mugged, it can turn into a kidnapping? I use some bank apps because they're quicker than the websites. But I do this with a cheap Nexus 7 tablet that stays at home with a label saying "full take" stuck to the top to remind me to not trust it with any sensitive information. Segregating apps onto different devices is the way t…

Doesn't this risk also apply to, like; carrying cash or even a debit card too close to an ATM? :/

I just don't see this as enough of a risk to be concerned about it, maybe it depends on where you live.

Re: Pixel phones are sold with bootloader unlocking disabled

#106

Earlier quoted context omitted.

If the servers are running. If the servers deign to give permission to own the device you purchased. If they correctly recognize that this device is owned by the user. After I've purchased the device, the seller has no right to withhold ownership, and the existence of enterprise devices doesn't change that in the slightest.

If the process doesn't work then return it as defective. Transfer of control isn't happening exactly at sale time but a few hours later isn't a big deal. Though of course that depends on it staying unlocked.

This is incorrect. Have you considered that the delay between getting the device and getting it connected could be well outside of the return window or people could be purchasing them in countries without such consumer rights?

Smartphones aren’t only for the developed world.

Re: Pixel phones are sold with bootloader unlocking disabled

#107

Earlier quoted context omitted.

Ha. Your example is rather specific seeming to me, as I actually work on one of the big 5 Canadian banking iOS apps here in Toronto. For obvious reasons; we don’t ship to alternate stores - even if such a thing as iOS sideloading existed; we wouldn’t support it, and we of course do not support anything but the Play Store on Android. It’s obviously partly a support cost issue - there would be less than 1% of our milli…

> rooted Android device (I'm sure I'm missing the obvious here) but why are you happy to have customers log in using a browser on a device they fully control, yet not do the same using your app on a device they fully control?

The obvious answer is that they're not happy about it, but that browsers don't give them the access necessary to detect whether the device running said browser is rooted (let alone do anything about it), so they can't pretend they know better about my own device's security than I do.

Re: Pixel phones are sold with bootloader unlocking disabled

#108
Disgusting. Google has taken the fraud of Android to a new level. The great "open-source" OS that was supposed to free us all from vendor and telco tyranny has spectacularly failed to do so, and to cripple fully-owned hardware in this manner just adds further insult.

Say what you want about "socialist" countries in Europe, but I don't think this kind of bullshit would stand in France. Based on laws they've passed over the last decade or two, Europeans seem to protect consumers; while the U.S. government abets corporations in ripping them off.

Google apologists busily downvoting...

Re: Pixel phones are sold with bootloader unlocking disabled

#109
post #27

Earlier quoted context omitted.

The two reasons are invalid for Pixel phones: 1. Pixel phones display an "unlocked bootloader" warning (which can't be disabled) during boot. In case it is re-locked with an additional signing key installed (Pixel-s are literally the only phones which you can do this currently in the market), a similar screen with the SHA256 hash of the public key is displayed. 2. Unlocking does not void warranty. The only reason Goo…

> 1. Pixel phones display an "unlocked bootloader" warning (which can't be disabled) Yet. Other manufacturers have the same warning and have had them disabled. (I did it to one of my older moto phones a few years back) > 2. Unlocking does not void warranty. Not by itself, but having a signal in place that it was unlocked lets the manufacturer look for common problems caused by doing things like flashing the wrong dev…

> Maybe this situation has changed for the Tensor/Samsung pixels but the point is screwing up your device due to flashing incorrect images shouldn't be something the manufacturer needs to foot the bill on.

Then maybe the manufacturers should be more forthcoming with making said tools available to the public, such that they don't have to foot the bill for said mistakes to be corrected.

Re: Pixel phones are sold with bootloader unlocking disabled

#110

Earlier quoted context omitted.

As usual, security is used as an excuse to lock down more than is necessary. To prevent the supply chain attack you mention, the boot lock just has to be tamper evident, such as showing a "Bootloader unlocked" message during boot. As is already the case in some phones. Additionally, a way to reset to a factory-verified state could undo such an attack. Warranty could also easily be achieved by flipping a non-reversibl…

Pixel's are locked down a very tiny bit , and I don't think this is some kind of dystopian over-reach with security as an excuse. For all the security listed in this thread the whole "I must connect to the internet once" problem is a very fair tradeoff from the user's perspective.

And what happens when that server on the Internet stops authorizing bootloader unlocks, or disappears entirely?
Post reply on HN