Live data from Hacker News

Samsung Removes Bootloader Unlocking with One UI 8

sammyguru.com

181–190 of 254 posts

Re: Samsung Removes Bootloader Unlocking with One UI 8

#181
post #139

Earlier quoted context omitted.

Believe it or not I did consider going the full Apple route. The problem is, Apple doesn't offer anything in the 8 inch zone. I need a tablet that fits into my pant pockets. And on top of that, there's no way to migrate the data from a bunch of these apps from the Google walled garden to the Apple walled garden, not to mention purchased licenses.

Is an iPad Mini too big? That’s an 8.3” display.

Interesting, thanks. The price tag is heavy on them though, the Samsung Galaxy Active Tab 5 is at less than 400€, the iPad Mini about 800€.

Re: Samsung Removes Bootloader Unlocking with One UI 8

#182
Damn, I got a samsung instead of an asus phone because I could unlock it. Now what:s left? Really annoyed at all those companies who refuse to let me own my own phone.

And before anyone asks me if I really need to unlock my phone... It's the principle of it, if I bought it, I own it and I should be able to run what I want on it. I will not buy a phone from a company that denies me that right.

That said, I do use root for a few things:

- AFWall+ (previously I used netguard but can't run multiple VPN on android so I couldn't have that running together with tailscale)

- Neo-backup. Some messaging apps believe that keeping chat history is not important. Or they believe that it's fine that the only way to transfer chat history is to upload it to Google cloud without encrypting it. I hate losing my chat history and I do not want it uploaded somewhere without encrypting it so I need a backup solution. Enters neobackup

- Sometimes, it is useful to be able to spoof one's GPS without the app being the wiser from a privacy perspective.

- A very stupid banking app I have prevent screenshots but then doesn't allow me to download a proof of transfer. So I use root to remove the restriction against screenshots

Re: Samsung Removes Bootloader Unlocking with One UI 8

#183
post #79

As someone who roots single-purpose Android devices, this is one of those things that sucks big-time but makes total sense. The only reason one would unlock a bootloader is to root the system partition. It is impossible to protect data on rooted phones and makes data exfiltration attacks significantly easier to do. This is a huge problem for banking and music apps that absolutely rely on this capability. Samsung is,…

    This is a huge problem for banking and music apps that absolutely rely on this capability
Yeah, I immediately cleared application data and uninstalled it, once I discovered my bank, of all organizations, was relying on Android to silo a token that grants access to my bank account with nothing else but a 4-digit PIN.

I had submitted a vulnerability report, because the option to require a password could be turned off without a password, and their response was that it works as expected, because they only require a PIN and providing a password is optional. That isn't to say that I have the option to make my account require passwords, it's that providing a password isn't needed, but I have the option of providing one anyway.

With only the PIN requirement, and four attempts before a lockout, a security vulnerability in the OS immediately becomes a 1 in 250 chance they'll have full access to may bank account, if I have a truly random PIN, or a 1 in 5 chance, if I have one of the four most common PINs and it always tries those. All that without having to wait to capture me logging in.

Also, Google explicitly states that the phones storage should not be used for sensitive data.

Re: Samsung Removes Bootloader Unlocking with One UI 8

#184
post #79

As someone who roots single-purpose Android devices, this is one of those things that sucks big-time but makes total sense. The only reason one would unlock a bootloader is to root the system partition. It is impossible to protect data on rooted phones and makes data exfiltration attacks significantly easier to do. This is a huge problem for banking and music apps that absolutely rely on this capability. Samsung is,…

> It is impossible to protect data on rooted phones What makes securing rooted phones different from securing rooted PCs?

To clarify, that line was implying something that makes a big impact:

    It is impossible to protect [the owner from accessing] data on rooted phones
It matters a lot to distributors why like to trick copyright holders into thinking that DRM is effect, which could only be the case if it works 100% of the time on 100% of the users, which it generally doesn't.

Re: Samsung Removes Bootloader Unlocking with One UI 8

#185
post #179
post #99

Earlier quoted context omitted.

My response would be it doesn't make any sense. There are so many reasons why blocking rooting is a stupid idea. Just some of them: - If you're capable of rooting a device then you're capable of understanding the risks which come with doing so. - The number of users who root their devices will always be so comparitively tiny that the increased risk of data exfil is incredibly small. Also, similarly to above, if you'r…

The main reason IMO to block rooting is to stop resellers selling phones with preinstalled malware. If the phone has two Amazon/Aliexpress sellers, you're going to pick the cheaper one right? With who-knows-what alterations? It's a really prevalent problem and most people are not going to notice the "insecure" warning at bootup.

Phones can and do have a warning that they were rooted on boot. So this is not an excuse. But don't worry, I'm sure there are several marketing teams at work on new excuses why your computers should be controlled by benevolent corporations and not you.

Re: Samsung Removes Bootloader Unlocking with One UI 8

#186

Earlier quoted context omitted.

> It is impossible to protect data on rooted phones What makes securing rooted phones different from securing rooted PCs?

To clarify, that line was implying something that makes a big impact: It is impossible to protect [the owner from accessing] data on rooted phones It matters a lot to distributors why like to trick copyright holders into thinking that DRM is effect, which could only be the case if it works 100% of the time on 100% of the users, which it generally doesn't.

In other words, security against the user.

Re: Samsung Removes Bootloader Unlocking with One UI 8

#187

Earlier quoted context omitted.

The bad guys e.g. the police detaining you during a protest and temporarily seizing your property, or the border police "scanning" your phone.

If your phone was in hands of police you better sell it anyway because they could install a physical GPS tracker, etc. So locked bootloader doesn't change much. Also if you live in a truly democratic country you don't even need to set the PIN code - your rights are protected by the law.

It would be relatively difficult to add a physical GPS tracker to a modern phone. Also, it's unnecessary, the government just needs to take a note of the IMSI and/or IMEI and then use the cell tower records to track you (rather accurately I should add).

The problem is not the tracking inherent in the design of mobile telephony networks, which you can circumvent by using burner phones. The problem is for example abuse of tools such as cellebrite to gain warrantless access to your phone at various opportunities.

This is also why proper baseband isolation is important. Baseband firmware is unaudited and likely to have government backdoors.

If the government wants to surveil me, they'll have to put in some actual effort instead of just taking opportunities.

Re: Samsung Removes Bootloader Unlocking with One UI 8

#188

Earlier quoted context omitted.

I mean for the Microsoft Android phones it kinda makes sense, since they're not exactly shipping Android by choice. They'd much rather you use the Windows Phones which this says ARE locked down.

Wasn’t windows phone discontinued like 10 years ago?

Yes.

Re: Samsung Removes Bootloader Unlocking with One UI 8

#189
post #21

Earlier quoted context omitted.

I've got a Samsung dryer and when it had a fault with the door sensor they got it fixed pretty quickly. I had better service from them than Bosch or Miele - I replaced a Bosch dryer when I was totally fed up of trying to organise Bosch to fix it and being told it was at least a 6 week wait - Samsung half the price, and surprised us that it is a better dryer (faster, easier to use etc). I don't love their phones, thou…

It’s amazing how nothing goes wrong with my 20+ year old Maytags, Whirlpools, or Estates by Whirlpool (their budget subbrand). No logic board failures, drain pump failures. Acquired from yard sales and then subject to duty cycles of 5-10 loads a day. Somewhat relevant, I have 3 relatives/colleagues still sporting iPhone 8’s/8 Pluses. The only issue is that some newer apps are slow. Told them to grab iPhone SE 3rd gen…

> It’s amazing how nothing goes wrong with my 20+ year old Maytags, Whirlpools, or Estates by Whirlpool (their budget subbrand). No logic board failures, drain pump failures.

whirlpool tumble driers are notorious in the UK for catching fire

https://inews.co.uk/news/business/peterborough-fire-hotpoint...

> At a parliamentary hearing in July, the US appliance company told MPs the numbers were higher than feared, after 1.7 million products were modified following the scandal.

> Whirlpool said that its machines could be linked to 750 fires in the last 11 years, or one every five days.

the grenfell disaster was also started by a whirlpool fridge

and their factory in peterborough also caught fire

Re: Samsung Removes Bootloader Unlocking with One UI 8

#190
post #178

Earlier quoted context omitted.

The problem with banking isn't rooting itself as an attack vector, but the insecurity and laxk of reliability guarantees of rooted phones so that banks rightfully don't want any liability when something goes wrong with their apps.

which is idiotic as you can have things like locked through adb root that only grants you root if you use adb to connect and you need to approve the request to connect on the phone first. This has nothing to do with guarantees but is just a security theater to sound like they are doing something

My argument isn't as much about the tech as it is about managing risk on the bank's side.

Imagine claims like "the XYZ bank app mangled my input and now my money is gone". I'm certain that people have sued for less. How can the bank argue in court that this wasn't their fault? What if the plaintiff demonstrates some actual glaring app misbehavior in court, but the root cause is in a broken third party Android build?

Post reply on HN