Live data from Hacker News

Samsung Removes Bootloader Unlocking with One UI 8

sammyguru.com

141–150 of 254 posts

Re: Samsung Removes Bootloader Unlocking with One UI 8

#141

Earlier quoted context omitted.

> It is impossible to protect data on rooted phones What makes securing rooted phones different from securing rooted PCs?

I don’t get this too. Laptops are just as portable but don’t have this limitation (yet). This argument that it’s to protect banking and music apps is silly, those products work fine on pcs while maintaining security.

> those products work fine on pcs

In the EU, banking apps no longer do. They require a trusted companion device for 2FA, e.g. a smartphone app or a dedicated chip-and-pin device. This is enforced by the PSD2 directive [1], which has been in effect since 2019.

In contrast to that, you’re always allowed to do banking on an iOS/Android banking app. Banks seem to trust the integrity of the OS enough that they allow the app to be its own second factor.

[1]: https://en.wikipedia.org/wiki/Payment_Services_Directive

Re: Samsung Removes Bootloader Unlocking with One UI 8

#142

It is really a pity, as this means Android OS is closing down. Without supported Consumer Hardware available on the market in sufficient volume, even less end-users will use an alternative OS, which will affect quality and size of the alternative OS-market and fragment the remaining users even more. This will put the future of the entire alternative-OS ecosystem firmly back into the hands of Google. If they start fur…

[deleted]

Re: Samsung Removes Bootloader Unlocking with One UI 8

#143

Earlier quoted context omitted.

> It is impossible to protect data on rooted phones What makes securing rooted phones different from securing rooted PCs?

Magic rock complicated. Grog say Grug too dumb to do magic rock right, so only Grog have secret magic rock key. Grug pay Grog many shiny rock for make magic rock work, or Grog use key and magic rock stop working.

What?

Re: Samsung Removes Bootloader Unlocking with One UI 8

#144
post #58
post #52

Been compiling and running lineageos for nigh on five years now. Attention corporate tyrants: I will never give up.

Seems you may have to start getting good at SMD rework soon.

You can always move to a phone that runs on mainline Linux proper.

Re: Samsung Removes Bootloader Unlocking with One UI 8

#145
post #111

Earlier quoted context omitted.

Phones are portable, and thus more likely to suffer from a physical attack. But that's about it. It is, and always was a flimsy excuse to the strip user of control over his own device. "Secure Boot" isn't actually there to protect the device from an attacker. It's there to "protect" the device from its own user. It's used to "secure" DRM schemes and App Store revenue streams.

>"Secure Boot" isn't actually there to protect the device from an attacker. It's there to "protect" the device from its own user. It's used to "secure" DRM schemes and App Store revenue streams. 1. Basically all the serious DRMs (eg. widevine L1) rely on the content being encrypted all the way to the display itself. The OS, secure boot or not, never sees the content in cleartext, because decryption happens in a secur…

Which is why even "unlocked" bootloader doesn't let the user load his own code into TrustZone.

The name "TrustZone" is rather ironic. It's most commonly used to run DRM code the user should never ever trust.

Re: Samsung Removes Bootloader Unlocking with One UI 8

#146

Pixel stopped providing device trees, kernel history, Samsung has been doing this for a while now. Which are the devices/vendors that still allow / encourage this? Even Graphene OS reported that they're in talks with some vendor... Have there been any updates towards that? The main reason i used to root devices are: * Get longer support/OS updates than what the vendor provided * System level adblock using adaway * Ti…

Here's an updated list of relatively popular phone manufactures and their bootloader unlocking potential. https://github.com/melontini/bootloader-unlock-wall-of-shame...

Was anyone else shocked to see Microsoft in the top tier of their list of unlock-friendly phone manufacturers?

Re: Samsung Removes Bootloader Unlocking with One UI 8

#147
post #99
post #79

As someone who roots single-purpose Android devices, this is one of those things that sucks big-time but makes total sense. The only reason one would unlock a bootloader is to root the system partition. It is impossible to protect data on rooted phones and makes data exfiltration attacks significantly easier to do. This is a huge problem for banking and music apps that absolutely rely on this capability. Samsung is,…

My response would be it doesn't make any sense. There are so many reasons why blocking rooting is a stupid idea. Just some of them: - If you're capable of rooting a device then you're capable of understanding the risks which come with doing so. - The number of users who root their devices will always be so comparitively tiny that the increased risk of data exfil is incredibly small. Also, similarly to above, if you'r…

> The number of users who root their devices will always be so comparitively tiny that the increased risk of data exfil is incredibly small

> the only reason to prevent users from rooting their phones is to protect companies' profits by ensuring users can't fight back against the blatant tracking, data mining, and analytics capture

You contradict yourself, if the number of users which will root their devices is tiny, the lost profits from tracking, data mining, analytics is tiny as well.

Re: Samsung Removes Bootloader Unlocking with One UI 8

#148

Earlier quoted context omitted.

You can use AdGuard to block in-app ads on Android as an FYI

You mean w/ DNS? or an app?

It sets up a VPN and routes your Android traffic through it. But because of battery optimizations etc.. it has been a little flaky for me

Re: Samsung Removes Bootloader Unlocking with One UI 8

#149
post #99

Earlier quoted context omitted.

My response would be it doesn't make any sense. There are so many reasons why blocking rooting is a stupid idea. Just some of them: - If you're capable of rooting a device then you're capable of understanding the risks which come with doing so. - The number of users who root their devices will always be so comparitively tiny that the increased risk of data exfil is incredibly small. Also, similarly to above, if you'r…

> Let's be honest and admit that the only reason to prevent users from rooting their phones is to protect companies' profits by ensuring users can't fight back against the blatant tracking, data mining, and analytics capture which is so valuable to companies. I'm with you on the general sentiment, but how do the companies that block rooting benefit from any of the nefarious activities you mentioned? Those are execute…

First party apps, carrots and sticks from large players like alphabet and meta, pressure from banks, pressure from governments.

Re: Samsung Removes Bootloader Unlocking with One UI 8

#150
post #126

Earlier quoted context omitted.

> no memory tagging support That's not a security feature though... We established that. Fair enough on the other points.

For people out of the loop, parent is referring to TikTag[0], a side-channel speculative execution attack breaking MTE in a probabilistic defense scenario, and the weird cope coming from some people that "MTE was only supposed to be a debugging feature anyway". However, you need some form of code execution beforehand already for this attack, and more importantly it doesn't affect any of the deterministic guarantees o…

> MTE was only supposed to be a debugging feature anyway

It literally was. MTE is a padlock with 16 combinations.

Post reply on HN