Live data from Hacker News

Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

androidauthority.com

161–170 of 232 posts

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#161

Earlier quoted context omitted.

This is rubbish. I'm running GrapheneOS and have left my bootloader unlocked, and there's no app that has refused to work. The only caveat is some of them need Google Play services. No, I am not rooted, but my last phone was rooted and there might have been one or two apps out of dozens that wouldn't work with root even with Magisk trying to hide the root status. Using a custom ROM is easily one of the beat choices I…

Do you use a banking app? Last I read depending on the type of check used some apps can still be problematic.

Also many "corporate" things, usually depending on your org's policy. E.g. I can't run OpsGenie (it may actually be the Microsoft SSO step failing, I'm not entirely sure, but the error definitely mentions my device not meeting security policies)

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#162
post #68

Earlier quoted context omitted.

They do, but you can't get the card number from reading the chip. The protocol is a challenge-response one based on a private key stored within the chip. https://en.wikipedia.org/wiki/Chip_Authentication_Program You need to read the entire card number + cvc2 + expiry date with your camera. That's not skimming, that's just taking a photo of the card.

Yeah, and it's easily solvable with a sticker or a dremel to scrape the number off

You can't dremel it out of the chip, though.

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#163
post #143

Earlier quoted context omitted.

In Ontario, Canada, part of the small claims process is a pre-trial conference, with a retired judge moderating. Further, nothing disclosed may be used as part of the trial. Its goal is to help with an amicable settlement. More info: In small claims, lawyers are not forbidden, but they may only speak for their client, and their client must be there, or present remorely, listening and ready to accept offers or deals.…

Did you intend to reply to a different comment?

No! My comments re: Ontario pre-court conference, were meant to highlight a reaspn why this might have been settled before small claims coirt.

I suspect a similar thing happens in the UK, and that forced conference ensures companies must hear reasoning, arguments in full before the case.

In Ontario, it's very informal. You just talk. The retired judge only intercedes if it becomes heated, or runs long.

It helps solve things.

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#164

Earlier quoted context omitted.

This is rubbish. I'm running GrapheneOS and have left my bootloader unlocked, and there's no app that has refused to work. The only caveat is some of them need Google Play services. No, I am not rooted, but my last phone was rooted and there might have been one or two apps out of dozens that wouldn't work with root even with Magisk trying to hide the root status. Using a custom ROM is easily one of the beat choices I…

You should not leave your bootloader unlocked if you care about the security of your device and data. Unfortunately, locking (and unlocking) it wipes user data, so it should be relocked right after installation of GrapheneOS.

I acknowledge that.

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#165
With the increasing difficulty (impossibility) of bootloader unlocking that most manufacturers are building into their Android devices, I wonder whether it's market reasons (the longer the devices are operational, the longer upgrade cycle) or pressure from intelligence agencies due to minimised Google / telemetry data back doors in custom ROMs.

Using the "simplest answer is often the best" approach, it would historically be the profit motivation at 99% probability. Currently, though, feels like surveillance and intelligence gathering is edging to the higher likelihood.

Edited to add: and maybe it's not even intelligence agencies, maybe it's purely profit driven from the personal-data-selling industry.

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#166
post #160
post #61

Earlier quoted context omitted.

EMV chip cards still contain your card number and expiry date. Skimmers would need a way to also learn the CVC2 from the back of the card to use it at most (but not all!) online merchants, but that's feasible using a small camera or a waiter/cashier accomplice doing the skimming. With Google Pay and Apple Pay, and similar mobile wallets, that number is never shared during payments (and in fact not even stored on the…

Any responsible user will learn the CVC, like any other password, and then erase it from the card.

That seems like a lot of extra effort for something that's arguably not your opsec problem, but that of the card payment industry.

In the end, you'll always have to enter it on payment websites anyway.

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#167

Earlier quoted context omitted.

Do you use a banking app? Last I read depending on the type of check used some apps can still be problematic.

So I guess next thing we need is someone sueing the fucking banks that do that. Mine luckily doesn't because I explicitly use an old phone with LineageOS, the banking app, and nothing else on it for online banking. It's arguably way more secure than using your main phone with a bazillion other Apps installed and online at all times.

A lot of this actually seems to have come from recent regulatory pressure for 2FA (which I support in principle, don't get me wrong). I don't even think most of them have given much thought to rooted phones, rather they're just cargo culting Industry Standard Best Practices and turning all the device verification options to max. Luckily, most of them realize they still have customers without a compliant smartphone, or one at all, and offer a fallback, which is almost always SMS...

Though you get those newer "app only" banks. I've never used any since I see that as a major downside, not a selling point, so idk whether they tolerate root. Even with traditional banks, I've come across a few features which can only be accessed via the phone app - in this case likely due to the belief that "web? Everyone just uses apps!" rather than security

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#169
post #134

Earlier quoted context omitted.

There has to be a fallback like SMS and/or automated call.

SMS is magnitudes less secure than the Secure Enclave in my phone. Fallback should never be the weakest link in a security chain. Especially not in something as high stakes as your banking login. I can’t remember how I got my first bank token in my phone. Probably by physically showing up in the bank office with my id.

Agreed. Unfortunately almost every bank here forces me to use this less secure option "for security" due to my rooted phone. Not one has just offered standard TOTP (perhaps because the pull-only nature of it means they can't present the message explicitly telling the user what they're about to authorize. Which is an understandable qualm I guess)

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#170

Earlier quoted context omitted.

This is rubbish. I'm running GrapheneOS and have left my bootloader unlocked, and there's no app that has refused to work. The only caveat is some of them need Google Play services. No, I am not rooted, but my last phone was rooted and there might have been one or two apps out of dozens that wouldn't work with root even with Magisk trying to hide the root status. Using a custom ROM is easily one of the beat choices I…

You should not leave your bootloader unlocked if you care about the security of your device and data. Unfortunately, locking (and unlocking) it wipes user data, so it should be relocked right after installation of GrapheneOS.

Don't most phones only wipe on unlock?

Also can Graphene still update if the bootloader is locked?

Post reply on HN