Live data from Hacker News

S.Korea fines Google $177M for blocking Android customisation

reuters.com

21–30 of 99 posts

Re: S.Korea fines Google $177M for blocking Android customisation

#21
post #20

Earlier quoted context omitted.

There will still need to be the option for a locked boot loader though. If I’m Snowden, knowing my boot loader could be unlocked and a key logger side loaded isn’t reassuring.

Ironically, Google's own Pixel devices are basically the only ones on the market that allow locking the bootloader with your own key [0]. They even follow the recommended bootflow [1], displaying a warning screen with the hash of the installed ROM when you boot the phone. [0]: https://android.googlesource.com/platform/external/avb/+/mas... [1]: https://android.googlesource.com/platform/external/avb/+/mas...

Why is this ironic?

Re: S.Korea fines Google $177M for blocking Android customisation

#22
post #8

Earlier quoted context omitted.

There will still need to be the option for a locked boot loader though. If I’m Snowden, knowing my boot loader could be unlocked and a key logger side loaded isn’t reassuring.

I'm not aware of any manufacturer who allows bootloader unlocking without also displaying a warning screen every time the phone boots up. Example: https://www.thecustomdroid.com/wp-content/uploads/2019/06/Ho...

My current phone (Xiaomi POCO F2 Pro) only displays a faint lock/unlock icon above the logo while booting. Easy to miss.

But that's not really important, because unlocking the bootloader factory resets the device on every Android phone that I know of. AFAIK it's not possible to unlock a bootloader without the owner's knowledge.

Re: S.Korea fines Google $177M for blocking Android customisation

#23

Earlier quoted context omitted.

There will still need to be the option for a locked boot loader though. If I’m Snowden, knowing my boot loader could be unlocked and a key logger side loaded isn’t reassuring.

If such snowden like person wants to use such a device, wouldn't he be able to change to lineage os or whatever knowing full well he is now the master of the device or is there malware that persists still ?

Someone could flash a hacked version of lineage when you're not looking.

Re: S.Korea fines Google $177M for blocking Android customisation

#24
post #21
post #20

Earlier quoted context omitted.

Ironically, Google's own Pixel devices are basically the only ones on the market that allow locking the bootloader with your own key [0]. They even follow the recommended bootflow [1], displaying a warning screen with the hash of the installed ROM when you boot the phone. [0]: https://android.googlesource.com/platform/external/avb/+/mas... [1]: https://android.googlesource.com/platform/external/avb/+/mas...

Why is this ironic?

Probably because it effectively means that Google’s own devices are the simplest to “deGoogle.”

Re: S.Korea fines Google $177M for blocking Android customisation

#25

Earlier quoted context omitted.

There will still need to be the option for a locked boot loader though. If I’m Snowden, knowing my boot loader could be unlocked and a key logger side loaded isn’t reassuring.

No, locked bootloader's are the stuff of nightmares. Much rather be able to scratch all memory on the device and reinstall. Perhaps what I mean is "locked bootloaders at POS". Selling them locked should be illegal, but locking them yourself with your own key should be trivial.

How about splitting the difference like locking the bootloader at point of sale with guaranteed period for updates? After the period has lapsed, allow users to unlock the bootloader to extend with custom software upgrades or, a subscription base to continue with original POS policy.

This weirdly intersects for the Right to Repair movement, or for consumers whom would rather be conservative on new device purchases and software licenses.

Re: S.Korea fines Google $177M for blocking Android customisation

#27
post #11
post #3

I hate when a law or legal decision is aimed 45 degrees off like this. Letting manufacturers bundle their fucked-up version of Android is a bad thing. What we need is mandatory unlockable bootloaders so the users can load whatever they want on their devices.

What we need is control on the bootloader, with the ability to unlock, load our own keys, and relock. We also need to clean-up the mess with all those "partitions" (some of them with critical informations e.g. calibration, IMEI, etc) so that only one partition would have all those static information (reasonably protected against overwrite, e.g. colocated with bootloader and device-tree). We should be able to re-parti…

While this all sounds great, I don't imagine legal regulation on how a device is partitioned would go as well as you think...

Re: S.Korea fines Google $177M for blocking Android customisation

#28
post #3

I hate when a law or legal decision is aimed 45 degrees off like this. Letting manufacturers bundle their fucked-up version of Android is a bad thing. What we need is mandatory unlockable bootloaders so the users can load whatever they want on their devices.

> unlockable bootloaders so the users can load whatever they want Here you go: https://puri.sm/products/librem-5 .

We shouldn't have to sacrifice performance, quality, and reasonable price points in order to have the basic things we've had in the desktop world for decades.

Re: S.Korea fines Google $177M for blocking Android customisation

#29
post #25

Earlier quoted context omitted.

No, locked bootloader's are the stuff of nightmares. Much rather be able to scratch all memory on the device and reinstall. Perhaps what I mean is "locked bootloaders at POS". Selling them locked should be illegal, but locking them yourself with your own key should be trivial.

How about splitting the difference like locking the bootloader at point of sale with guaranteed period for updates? After the period has lapsed, allow users to unlock the bootloader to extend with custom software upgrades or, a subscription base to continue with original POS policy. This weirdly intersects for the Right to Repair movement, or for consumers whom would rather be conservative on new device purchases and…

Reminds me of the idea I've been thinking about - kind of unrelated - but once a device is officially no longer supported by a company - particularly consoles and online games - they should make the source code available so people can continue from there on their own.

Re: S.Korea fines Google $177M for blocking Android customisation

#30
post #2

I recently installed LineageOS on my phone, replacing the stock MIUI. I would probably return this phone if I had no other option than to use MIUI. I much prefer the "pure" Android experience. For many essential and security critical apps to work, like bank apps or the McDonald's app you need to hide the fact you're using a modified system, because of SafetyNet. This hiding/bypass works for now, because it tricks Goo…

>or the McDonald's app Excuse me? McDonald's app considers itself security critical now?

Anything that deals with your financial information usually has security.
Post reply on HN