Live data from Hacker News

What happened to running what you wanted on your own machine?

hackaday.com

151–160 of 315 posts

Re: What happened to running what you wanted on your own machine?

#151

Earlier quoted context omitted.

> I don’t think you have an inalienable right to run code of your choice > more importantly crack down on those who would pirate their, software. If you represent the interests of corporations then try leading with that next time. > Escape hatches are great, but each also represents a security weakness waiting to be exploited. Besides being a broad statement that lacks citations and no doubt relies on contrived examp…

> If you represent the interests of corporations then try leading with that next time. I don't. I'm just saying Google and whichever boogeyman you'd care to slot into position 2 share the same interests. Far more than you or me and Google anyway. > Besides being a broad statement that lacks citations and no doubt relies on contrived examples where this was implemented poorly To a laymen user, any software that is run…

> To a laymen user, any software that is running without code signing has a much much much higher chance of being something that has gone wrong rather than Joe Public found a cool image editing app that doesn't want to be distributed via the Play store.

Don't give me these "political" answers. That's just another broadly-agreeable statement that's completely unrelated to the one I asked you to substantiate:

> Escape hatches are great, but each also represents a security weakness waiting to be exploited.

There are 3 problems here:

0. If Google genuinely cared about Android security to this degree, they wouldn't be giving threat actors 4 months to run wild with 0-days before publishing them:

https://news.ycombinator.com/item?id=45158523

https://xcancel.com/GrapheneOS/status/1964754118653952027

1. Crossing the escape hatch != security breach

Mobile security relies on sandboxing, not on Google's approvals. Even the most malicious app approved by Google shouldn't be able to steal information, access information from other apps without authorization, or execute actions on user's behalf.

Whenever this core principle is broken due to inevitable security vulnerabilities, it should be treated as such and promptly patched. Instead these shortcomings are used as convenient excuses to advance these political goals.

2. An escape hatch can be anything:

- "allow installation from unknown sources" like we've always had

- secret settings menu + PIN/password + require a switch to be flipped in the recovery menu during boot + require an ADB command to executed + warnings at every step.

- ADB commands + switch in recovery menu + time delay + require a full device reset with all data being lost

First one is somewhat vulnerable to social engineering though I've personally never encountered a device where someone was tricked into doing this, so it must be more resistant than downloading malware on Windows.

Second is close to impervious to social engineering. Grandma isn't going to be accessing the recovery menu or running ADB commands any time soon.

Third one, while far too restrictive in my opinion would still be better than nothing, it would be impenetrable to social engineering, and safeguard any existing data on the device even in case of a serious concurrent vulnerability in the Android sandbox.

Are all of these completely unacceptable?

On the balance of probabilities, "Joe Public" isn't being tricked into doing anything, he is trying to install ReVanced to get ad-free Youtube.

Re: What happened to running what you wanted on your own machine?

#152
post #140

Earlier quoted context omitted.

Passkeys are another brick in this wall. The authors of the spec built in client software identification and attestation, which means authenticating parties can require you to only use certain, closed-source passkey clients. It's not hard to imagine a future where only blessed Passkey clients, such as Microsoft's, Apple's, and Google's implementations, are allowed by most services.

Heh, I'm working on a blog post about this very topic. Passkeys are ... weird. There's a lot of potential for gatekeeping, where websites can indeed require you to use device-bound passkeys through device attestation, and where becoming a vendor requires interacting with the fido alliance.... I would say "I'm sure the mean well", but given that parties like Yubico benefit from not getting more competitors, the cynic…

> I would say "I'm sure they mean well",

Yeah, I wouldn't say that. It's clear from their public comments[1,2,3] that the spec authors don't believe the private key actually belongs to the user to do what they want with. They see services restricting what users may do with their own logins as a feature of Passkeys. It's really a shame it went in this direction. Replacing passwords with an easy-to-use keypair auth system would be a massive security improvement. But the Passkey ecosystem is poisoned at this point. Unless they remove the client ID & attestation anti-features, it should be considered a proprietary big tech protocol.

[1] Threatening an open-source passkey client with server-side bans because they don't implement passkey storage on the client device in the way the spec authors prefer. https://github.com/keepassxreboot/keepassxc/issues/10406

[2] Maintaining a list of "non-compliant" clients, including the above open-source one, presumably for use in server-side bans. https://passkeys.dev/docs/reference/known-issues/

[3] While writing an article about this on my website, I actually emailed the two involved spec authors on the above issue, politely asking how their interpretation of the Passkey spec could possibly be compatible with open source software. Neither replied.

Re: What happened to running what you wanted on your own machine?

#153

Earlier quoted context omitted.

He didn't assault anyone. He said a bunch of things. They've all been collected here: https://stallman-report.org/ What I love about that report is that the author created it with the intention of making Stallman look bad. And if you look at the author's summaries, he looks bad. However, the author also made us the favour of collecting all the statements in one single place. And if you look at the things that Stallma…

And there's a reply to that: https://geoff.greer.fm/2019/09/30/in-defense-of-richard-stal... via https://news.ycombinator.com/item?id=21113414

Yeah yeah but the reason why I link to that, is that if someone is interested they can with minimal effort find by themselves all the information to understand it was just a smear job.

Like, someone says "C assaulted B". And Stallman says "If A forces B to offer herself to C, C didn't assault B". Which is obivously correct. It could only be incorrect if you were redefining words to serve your purposes.

Re: What happened to running what you wanted on your own machine?

#154

It's important to understand that we could genuinely lose general purpose computing. I don't think it's in serious danger at the moment, but we've been in the midst of a slide in that direction for the last 10-15 years. Part of it is mobile phones, part of it is TPM, part of it is market forces. The latest turn is strictly political. We've really foolishly built the technology necessary for authoritarianism just a fe…

Oh wow... The idea of losing general purpose computing is a terrifying thought I've never considered before.

It’s already happening.

Many big institutions lean heavily on mobile apps and other gated computing.

I live in BC Canada and by far the easiest way to authenticate a login to provincial sources involves using the BC ID App as a second factor, even when logging in via desktop. Many banks now also use their app as a second factor, rather than a generic OTP option that can run on any hardware.

There were also issues like running Netflix DRM in browser on Linux for a while.

General purpose computers won’t go away, but they will continue to be gated from more and more services until you are more or less required to have a phone or locked down ecosystem device.

Re: What happened to running what you wanted on your own machine?

#156

Earlier quoted context omitted.

> I don't see how remote hardware attestation avoids being spoofed Hardware cryptoprocessor. Keys are held in a tamper resistant secure element. You're not gonna get at those keys without pouring some serious resources into the task. The keys are owned by the corporation and used to establish a root of trust from boot. If you change anything at all to suit your interests, verification fails, your machine is identifie…

History tells us there will always be a “low cost” vendor with exploitable hardware, or if production becomes more tightly controlled, inevitable cost cutting and declining standards will provide a way in. Not that we shouldn’t oppose locked down hardware, but locking things down creates pressure and motivation for the people who like things to be unlocked.

[deleted]

Re: What happened to running what you wanted on your own machine?

#157
post #15
post #2

The one word answer to this? Linux.

The article is largely about phones, where the barrier to install a truly open Linux system are high and getting higher.

I do run GNU/Linux on my smartphone. No Android or iOS.

Re: What happened to running what you wanted on your own machine?

#158
post #122

Earlier quoted context omitted.

Death by a thousand cuts. TPM, secure attestation, age verification, DRM, and probably more things I'm forgetting right now.

Passkeys are another brick in this wall. The authors of the spec built in client software identification and attestation, which means authenticating parties can require you to only use certain, closed-source passkey clients. It's not hard to imagine a future where only blessed Passkey clients, such as Microsoft's, Apple's, and Google's implementations, are allowed by most services.

Yeah I hate this, installed a new CPU and none of my passkeys work. The browser asks my phone and they don't trust each other and not a damn clue how to fix it.

Re: What happened to running what you wanted on your own machine?

#159

Earlier quoted context omitted.

Doing evil things under the guise of good intentions (with reasons that appear valid on the surface) has always been the playbook. All you're doing is excusing it - let's not. If this was genuinely about security and UX then they would continue to provide viable "escape hatches", but it isn't and so they don't. That's what's being criticized .

I disagree, I don’t think I’m excusing it at all and your argument hinges on the restriction of software running on hardware to be evil. I wouldn’t describe it that way. I think it’s frustrating certainly but I don’t think you have an inalienable right to run code of your choice. I would characterize it more as Google is responding to the needs of the vast majority of its users, most of whom do not care to run unsign…

> Escape hatches are great, but each also represents a security weakness waiting to be exploited.

Having money and using them without supervision is a safety risk. You can unknowingly buy food that isn't good for your health. And good food is what you actually need. So transfer your money to me and I will benevolently manage your diet for you. No other motives but your safety and wellbeing, I swear.

By the way, can you really trust the supermatkets? They sell alcohol and alcohol is bad for you.

Re: What happened to running what you wanted on your own machine?

#160

Earlier quoted context omitted.

EU CRA (enforced Dec 2027) prohibits shipment of non-certified binaries for "critical" software, including firmware and hypervisors. Operating systems like Linux are categorized as "important" software, https://www.whitecase.com/insight-alert/cyber-resilience-act...

I might be wrong but I don't think that open source software are subject to the CRA. If you look at article (18) here [0] it seems to explicitly exclude free software that you download from the internet. [0] https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng

That depends on the definition of "commercial activity". Some groups have influenced the legislation to exclude specific activity. Some supply chain roles, including developers who contribute patches, are excluded. Others can seek guidance on interpreting the legal text.

  - software that are not monetised by their manufacturers should not be considered to be a commercial activity. 
  - supply of products with digital elements qualifying as free and open-source software components intended for integration by other manufacturers into their own products with digital elements should be considered to be making available on the market only if the component is monetised by its original manufacturer. 
  - development of products with digital elements qualifying as free and open-source software by not-for-profit organisations should not be considered to be a commercial activity provided that the organisation is set up in such a way that ensures that all earnings after costs are used to achieve not-for-profit objectives. 
  - does not apply to natural or legal persons who contribute with source code to products with digital elements qualifying as free and open-source software that are not under their responsibility.
Post reply on HN