Live data from Hacker News

We should have the ability to run any code we want on hardware we own

hugotunius.se

161–170 of 1001 posts

Re: We should have the ability to run any code we want on hardware we own

#161
post #86
post #31

> It should be possible to run Android on an iPhone and manufacturers should be required by law to provide enough technical support and documentation to make the development of new operating systems possible As someone who enjoyed Linux phones like the Nokia N900/950 and would love to see those hacker-spirited devices again, statements like this sound more than naïve to me. I can acknowledge my own interests here (ha…

Not to mention, it's an authoritarian attitude, talking about forcing companies to support arbitrary software stacks

Is it authoritarian to stop other people from being authoritarians?

Re: We should have the ability to run any code we want on hardware we own

#162
post #142

Earlier quoted context omitted.

>big scary message Open question: Any idea on making it so difficult that grandma isn't even able to follow a phisher’s instructions over the phone but yet nearly trivial for anyone who knows what they’re doing?

Fix the phone system so calls must positively identify themselves. There is no reason anyone purporting to be from a business or the government should be able to place a call without cryptographically proving their identity.

I like that! I’m sure it would take a little bit of time for folks to stop trusting calls from personal numbers where highly-capable social engineers do their best work, but eventually I expect nearly all of us would learn the lesson.

And presumably we could set up notifications so our elderly relatives’ phones would alert us to calls from unverified numbers not in their contact list lasting longer than a minute or two.

Re: We should have the ability to run any code we want on hardware we own

#163

Earlier quoted context omitted.

> I can acknowledge my own interests here (having control over how exactly the device I own runs), but I can also see the interests of phone manufacturers — protecting revenue streams, managing liability and regulatory risks, optimizing hardware–software integration, and so on. I don't see how my own interests here outweigh collective interests here. However the interests you mention aren't collective at all but very…

Its only the manufacturers interests because they dont want people to brick their phone on accident. Really theyre only a secondary party of interest, the real interested party is grandma/anyone who can fall victim to malware. Apples decision to ban sideloading is a huge part of how they became the most popular phone maker in the us

> because they dont want people to brick their phone on accident

Or worse, blow them up.

Re: We should have the ability to run any code we want on hardware we own

#164

Earlier quoted context omitted.

>big scary message Open question: Any idea on making it so difficult that grandma isn't even able to follow a phisher’s instructions over the phone but yet nearly trivial for anyone who knows what they’re doing?

Stop gatekeeping actually useful apps. Nobody should never need to see the message to do anything they actually want to do, otherwise it leads to normalization of deviance. False positives from PC virus scanners are very rare.

Interesting, mind elaborating a bit/clarifying the first couple of sentences there? A point I’d like to understand

Re: We should have the ability to run any code we want on hardware we own

#165
> In this context this would mean having the ability and documentation to build or install alternative operating systems on this hardware

It doesn't work. Everything from banks to Netflix and others are slowly edging out anything where they can't fully verify the chain of control to an entity they can have a legal or contractual relationship with. To be clear, this is fundamental, not incidental. You can't run your own operating system because it's not in Netflix's financial interest for you to do so. Or your banks, or your government. They all benefit from you not having control, so you can't.

This is why it's so important to defend the real principles here not just the technical artefacts of them. Netflix shouldn't be able to insist on a particular type of DRM for me to receive their service. Governments shouldn't be able to prevent me from end to end encrypting things. I should be able to opt into all this if I want more security, but it can't be mandatory. However all of these things are not technical, they are principles and rights that we have to argue for.

Re: We should have the ability to run any code we want on hardware we own

#166

Earlier quoted context omitted.

>big scary message Open question: Any idea on making it so difficult that grandma isn't even able to follow a phisher’s instructions over the phone but yet nearly trivial for anyone who knows what they’re doing?

Sure. You ship the device in open mode, and then doing it is easy. The device supports closed mode (i.e. whatever the currently configured package installation sources are, you can no longer add more), and if you put the device in closed mode, getting it back out requires attaching a debugger to the USB port, a big scary message and confirmation on the phone screen itself, and a full device wipe. Then you put grandma…

Very nice!

I’m sure I’m missing a problem with the following approach: shipping in _closed_ mode with a sticker on the front notifying the person they should do a factory reset immediately to make sure they can do everything they want to do. During the reset, include a scary message for those who opt in to get to open mode.

Everyone simply goes by defaults so it would only be technical people presumably who would even get into the open mode in the first place. And then require the debugger to leave closed mode like you said.

Edit: this comment worries about solo/asocial/“orphaned” members of our society

Re: We should have the ability to run any code we want on hardware we own

#167

Much harder to make a secure device that is resistant to getting pwn'd if you can run any code you want. I personally prefer my iPhone to be more secure than to be more open. Buy a more open phone if you want one, but stop trying to use legal means to force the software on my phone to be worse for my use-case just because you want to have your cake and eat it too.

Closed devices are secure, yes. Apps can use pinned https certs. Apple signs the binary. This ensures that when your personal data is exfiltrated, it will go undetected by malicious third parties such as yourself.

Re: We should have the ability to run any code we want on hardware we own

#168

Earlier quoted context omitted.

> more stress tested and vetted by more people Grandma and grandpa aren't reading the source code and certainly not up at a professional level. This is one of the core misconceptions of the "free/libre" formulation of OSS.

I’m not suggesting grandpa reads code, contributors do. We all know that most commercial code is much shittier than open source. Sure, commercial code usually covers more edge cases and has better UX, but is cobbled together from legacy and random product asks.

> We all know that most commercial code is much shittier than open source

Citation needed. Seriously.

Re: We should have the ability to run any code we want on hardware we own

#169

Earlier quoted context omitted.

For security reasons it makes sense for them to be different devices. People and services may not want to allow insecure devices to communicate with them.

Why? It's not like the insecure device doesn't have my identity key on it. If I program it to spam people, I go to jail for spamming.

It would be easier to spoof such identities and some services may not want to deal with the overhead of using the legal system. Spammers today already can be taken to court, but in practice people don't do that.

Re: We should have the ability to run any code we want on hardware we own

#170

Earlier quoted context omitted.

For security reasons it makes sense for them to be different devices. People and services may not want to allow insecure devices to communicate with them.

Why? It's not like the insecure device doesn't have my identity key on it. If I program it to spam people, I go to jail for spamming.

If only you went to jail for spamming.
Post reply on HN