Live data from Hacker News

Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

androidauthority.com

171–180 of 232 posts

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#171
post #160
post #61

Earlier quoted context omitted.

EMV chip cards still contain your card number and expiry date. Skimmers would need a way to also learn the CVC2 from the back of the card to use it at most (but not all!) online merchants, but that's feasible using a small camera or a waiter/cashier accomplice doing the skimming. With Google Pay and Apple Pay, and similar mobile wallets, that number is never shared during payments (and in fact not even stored on the…

Any responsible user will learn the CVC, like any other password, and then erase it from the card.

I can certainly remember mine from repeated use, but I can't say I've ever heard of someone erasing it

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#172

Okay - so which devices are left that are easily rootable? I will be in the market for new one soon. It's good if EU after mandating usb-c also mandates unlockable bootloaders for whomever wants it.

I'm in love with fairphones

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#173
post #65

Earlier quoted context omitted.

CalxyOS is the other one, with less problematic developer history.

Up until your comma the comment suited me just fine, but then... let's not get personal about developers' health issues. It isn't helpful, and there has already been an HN discussion on the topic that you've unfortunately exhumed. There has been great progress at solving problems that had come up during a sad time for GrapheneOS and CalyxOS.

I understand that position, but one can also not simply ignore the situation. It'd be okay if the project had removed the maintainer, but they did not, instead he just sabotaged the Mozilla location service discussion while purporting to speak in the name of the Graphene foundation. There is a responsibility to warn users about that risk factor.

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#174
post #134

Earlier quoted context omitted.

There has to be a fallback like SMS and/or automated call.

SMS is magnitudes less secure than the Secure Enclave in my phone. Fallback should never be the weakest link in a security chain. Especially not in something as high stakes as your banking login. I can’t remember how I got my first bank token in my phone. Probably by physically showing up in the bank office with my id.

> SMS is magnitudes less secure than the Secure Enclave in my phone.

The secure enclave on a rooted phone that no longer has execution integrity?

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#175
post #134

Earlier quoted context omitted.

There has to be a fallback like SMS and/or automated call.

SMS is magnitudes less secure than the Secure Enclave in my phone. Fallback should never be the weakest link in a security chain. Especially not in something as high stakes as your banking login. I can’t remember how I got my first bank token in my phone. Probably by physically showing up in the bank office with my id.

SMS 2FA is not great, but still seems to be more secure than a rooted phone.

If your SMS OTP leaks to the attacker, they still need to know the first factor (password, biometrics) to gain access.

Meanwhile, if your rooted phone is controlled by an attacker ... that's it, the attacker has everything.

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#176

[flagged]

I'm on a 5 years old phone with Android 14. The OEM stopped the update on Android 11 but the Custom ROM community is going strong. Not only do I now have the latest software that works smoother, but also better camera with GCam, no ads systemwide, better privacy controls through Warden and other similar apps. I just avoided e-waste.

> Not only do I now have the latest software that works smoother, but also better camera with GCam, no ads systemwide, better privacy controls through Warden and other similar apps.

Sounds like a lot of that functionality could be achieved by just buying an iPhone instead. The 6s received updates through 7 major versions.

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#177

Earlier quoted context omitted.

So I guess next thing we need is someone sueing the fucking banks that do that. Mine luckily doesn't because I explicitly use an old phone with LineageOS, the banking app, and nothing else on it for online banking. It's arguably way more secure than using your main phone with a bazillion other Apps installed and online at all times.

How would that stick? You can just sign into the bank via your web browser in the case of a nonfunctional app. The apps just give you added security assurances beyond using the web. "The app can't function in a low security environment, but complainant is free to use the web client in such event." case dismissed (obviously an oversimplification, but the point stands)

The app is for 2fa.

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#178
post #116

Earlier quoted context omitted.

This is definitely not the case everywhere. Where I live the app is 100% needed because it’s the „second factor“ in the login process.

Curious, can you name this institution that only allows the app to be used as the second factor without fallbacks?

In Germany: all of them.

Well, some offer a hardware device for like 25€ that can do the same thing, but then if you have an account with multiple banks, you need multiple of these devices.

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#179
post #160

Earlier quoted context omitted.

Any responsible user will learn the CVC, like any other password, and then erase it from the card.

I can certainly remember mine from repeated use, but I can't say I've ever heard of someone erasing it

I have done it since many years ago

Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools

#180

Earlier quoted context omitted.

Bank apps, Netflix, and Disney+ also won't work. There are spoofing measures though I've been burned by unlocking and rooting too often to try again, at least not while my devices are still under warranty.

My solution * use bank website for the one bank that requires it, otherwise I got a new bank account without silly fake security. * thepiratebay has everything Netflix and Disney does and it works anywhere

I always use websites when possible instead of installing yet more spyware disguised as a useful app. My bank, however, has the TOTP built in the app. You can't make a transaction without the phone app connected to the internet.
Post reply on HN