Live data from Hacker News

Samsung Removes Bootloader Unlocking with One UI 8

sammyguru.com

121–130 of 254 posts

Re: Samsung Removes Bootloader Unlocking with One UI 8

#121

Earlier quoted context omitted.

> It is impossible to protect data on rooted phones What makes securing rooted phones different from securing rooted PCs?

Nothing. They just perceive the users as more stupid and incapable of handling their personal property properly.

The scariest part is, they might actually be.

Re: Samsung Removes Bootloader Unlocking with One UI 8

#122
post #63

Earlier quoted context omitted.

> > Adding cpu instructions is something that you can't physically do > You can physically do it with a microcode update. Do these ARM CPUs even have microcode? Unlike on x86 CPUs where there are some very complex instructions which have to be microcoded, on ARM all instructions are simple enough that their decoding into micro-operations can be completely hard-coded in the decoder logic.

Yes, it's too risky to make CPUs without microcode. Being able to fix bugs, or at least disable things so you don't have a complete paperweight is still important even for ARM.

Disabling things can be done through "chicken bits" on configuration registers, no microcode necessary.

Do you know of any ARM cores used on smarphones which actually have updatable microcode? I've never heard of any. All errata fixes I've seen are of the "set this bit in a specific register" kind.

Re: Samsung Removes Bootloader Unlocking with One UI 8

#123
Normally, I'd go and say "vote with your wallet" - but sadly, in the tablet sphere, it's either ultra low spec Alibaba junk or it's Samsung. No Fairphone, no Pixel, nothing.

Seriously Samsung, go and screw yourselves.

The reason I insist on rooting in the first place is because unlike iOS which has a true full backup that you can trigger from your Mac (and restore afterwards), Android decidedly does not, and a bunch of apps don't do any kind of cloud sync.

Re: Samsung Removes Bootloader Unlocking with One UI 8

#124
post #54

Xiaomi apparently have also stopped unlocking their bootloaders, so the "workaround" was to go to an official store and ask them perform a downgrade, and before the staff can relock the bootloader, grab the phone and run: https://x.com/kobe_koto/status/1949154478298456531 Absolutely hilarious.

This is amazing. Imagine getting the cops called on you for this and having to explain why the phone company was against you stealing your own phone

Re: Samsung Removes Bootloader Unlocking with One UI 8

#125
post #23

The writing's been on the wall for custom ROMs in general for a while, so I've been starting to think about a mobile phone vendor I could actually have a decent business relationship with. I.e. use their stock ROM and be fairly happy with it. Any opinions? Samsung was a candidate for their somewhat unified ecosystem. Maybe even apple.

Samsung carries a lot of advertising crap, tracking, etc. Pretty much every phones is going to be worse than Pixel in that respect, since you get Google's tracking + whatever pile of crap the vendor added (which in the end they all seem to do). So it's basically: Pixel with GrapheneOS > iPhone >> Google Pixel with PixelOS I wouldn't recommend anything else. Theoretically Fairphone + e/OS may have been an option, but…

I've owned a few pixels but for whatever reason in my case the hardware had a habit of randomly dying just outside of the warranty period. But maybe I can revisit.

Re: Samsung Removes Bootloader Unlocking with One UI 8

#126
post #69

Earlier quoted context omitted.

No secure element, no memory tagging support, no proper cellular baseband isolation, no verified boot, taking months to ship security updates .. the list is long. From a security/privacy perspective the fairphone is on the worse side of options unfortunately.

> no memory tagging support That's not a security feature though... We established that. Fair enough on the other points.

For people out of the loop, parent is referring to TikTag[0], a side-channel speculative execution attack breaking MTE in a probabilistic defense scenario, and the weird cope coming from some people that "MTE was only supposed to be a debugging feature anyway".

However, you need some form of code execution beforehand already for this attack, and more importantly it doesn't affect any of the deterministic guarantees of MTE. And those are the main appeal to GrapheneOS in the first place, preventing things like use-after-free by tagging the memory such that it simply can't be accessed anymore. So it's very much a security feature.

[0] https://news.ycombinator.com/item?id=40715018

Re: Samsung Removes Bootloader Unlocking with One UI 8

#127
post #6

Earlier quoted context omitted.

They should be economically incentivized to pick up their trash.

Is any other product forced to do such a thing? Considering a phone lasts for years and is very small, it produces very little garbage over time compared to disposable product people use. Think how big a garbage can is compared to a phone.

I dump a whole bin of paper every two weeks; most of it is recyclable.

Phones are electrowaste. Recyclability of electronics is... not good.

Re: Samsung Removes Bootloader Unlocking with One UI 8

#128
post #79

As someone who roots single-purpose Android devices, this is one of those things that sucks big-time but makes total sense. The only reason one would unlock a bootloader is to root the system partition. It is impossible to protect data on rooted phones and makes data exfiltration attacks significantly easier to do. This is a huge problem for banking and music apps that absolutely rely on this capability. Samsung is,…

> It is impossible to protect data on rooted phones What makes securing rooted phones different from securing rooted PCs?

Magic rock complicated. Grog say Grug too dumb to do magic rock right, so only Grog have secret magic rock key.

Grug pay Grog many shiny rock for make magic rock work, or Grog use key and magic rock stop working.

Re: Samsung Removes Bootloader Unlocking with One UI 8

#129

Pixel stopped providing device trees, kernel history, Samsung has been doing this for a while now. Which are the devices/vendors that still allow / encourage this? Even Graphene OS reported that they're in talks with some vendor... Have there been any updates towards that? The main reason i used to root devices are: * Get longer support/OS updates than what the vendor provided * System level adblock using adaway * Ti…

You can use AdGuard to block in-app ads on Android as an FYI

You mean w/ DNS? or an app?

Re: Samsung Removes Bootloader Unlocking with One UI 8

#130
post #58
post #52

Been compiling and running lineageos for nigh on five years now. Attention corporate tyrants: I will never give up.

Seems you may have to start getting good at SMD rework soon.

Either freedom or zip. I'd sooner bang rocks together than use a phone I can't compile the OS for. The number of required binary blobs is a foul enough insult already.
Post reply on HN