Live data from Hacker News

Right to root access

medhir.com

21–30 of 428 posts

Re: Right to root access

#21

I used to think this way but then I saw how non-techy people use their devices. Something like this would inevitably be abused and result in wave of malware so massive that it would render the internet too hostile for all but the most careful, knowledgable and paranoid users.

"everyone is too stupid to be trusted with general purpose computers" is a pretty grim position to hold

You left out the vital clause. "... if they have total unfettered control". Also, not everyone. Obviously.

It's a position I came to rather regretfully and sadly.

Re: Right to root access

#22
post #6

Earlier quoted context omitted.

This is an extremely weak argument, and I'd like to stop seeing it perpetuated. If you don't want an unlocked bootloader, just don't unlock your bootloader. Why should we remove the ability to unlock the bootloader entirely just because some people don't want to use it?

> If you don't want an unlocked bootloader, just don't unlock your bootloader. That kind of logic cuts both ways: "If you don't want a device with a locked boot loader, just don't buy a device with a locked bootloader". Unfortunately, as consumers, we're trapped between a rock and a hard place. On the one hand, I would want 100% freedom to use my device exactly as I see fit and run any software I want, without any fo…

I would also be happy with those restrictions on a traditional PC-class computing device (laptop or desktop). Would I personally buy one? Probably not, but I'd feel a whole hell of a lot better if my non-techie wife or mother or brother were using one and they were no more susceptible to some kind of exploit on their PC device than they were on their phone

That's the whole thing--there should be choice

Re: Right to root access

#23
post #20

I used to think this way but then I saw how non-techy people use their devices. Something like this would inevitably be abused and result in wave of malware so massive that it would render the internet too hostile for all but the most careful, knowledgable and paranoid users.

As the author mentions, desktop computers have always been (mostly) unlocked. This comment is just over the top scaremongering.

Even with access controls, people do things like download chrome from random web sites, then do their banking with the result. If the fake-chrome requested admin access then you'd never be able trust anything on that computer ever again. Even re-installing the OS wouldn't fix it.

It would no longer be your computer.

Re: Right to root access

#24
post #4

> Root access refers to the highest level of privileges a user can be granted to a computer system. This is no longer true. You might have root access on your smartphone, but you still don't have access to the TEE (on ARM this is implemented using the "TrustZone" "feature"). Also, AVF is coming to Android, and protected VMs won't work with unlocked bootloader.. so expect the situation to deteriorate further once manu…

Yeah I mean theres not even any way to really know what your communicating with without taking the thing apart and following the traces + an ocilliscope. If it was worth obfuscating to a determined company it would be hell to figure out.

You could just be a sandbox root which is pointed at a guest user in a higher namespace.

Re: Right to root access

#25
I detest Google, but I do think they made the right call with Android devices and Chromebooks. You can unlock either as long as you are willing to totally wipe the device first and start over as a new device under a new security context.

This removes the risk of this being abused to compromise the data of stolen devices or evil maid attacks unless a user that knows what they are doing has explicitly opted themselves into that risk.

Re: Right to root access

#26
post #20

I used to think this way but then I saw how non-techy people use their devices. Something like this would inevitably be abused and result in wave of malware so massive that it would render the internet too hostile for all but the most careful, knowledgable and paranoid users.

As the author mentions, desktop computers have always been (mostly) unlocked. This comment is just over the top scaremongering.

Yep, and if you connected a Windows95 machine to the internet it would be compromised within 15 minutes.

Re: Right to root access

#27

I used to think this way but then I saw how non-techy people use their devices. Something like this would inevitably be abused and result in wave of malware so massive that it would render the internet too hostile for all but the most careful, knowledgable and paranoid users.

Stupidest take I've seen today.

There are already myriad unlockable devices.

What a bizarre fantasy you have constructed.

Re: Right to root access

#28
post #3
post #2

Author seems to want 'hardware-level locks' regulated, i.e., allow the government to get into your encrypted devices.

That is absolutely not what the author is saying here, just that users should have the ability to install their own software on their own hardware, and that locked bootloaders and the like should not be allowed.

Yes, that is exactly what the author is saying, wanting government regulation. For one, the government won't simply say "keep the device open for the end user" (or a "smart" government wouldn't), but even if they did, you've now opened that device to any attacker, law enforcement included.

Re: Right to root access

#29
If locking the bootloader and comparing signatures against keys burned into a secure enclave allow Apple to make certain security guarantees that helps them sell products, I'm all for their freedom to do so.

Why doesn't OP merely champion competition, instead of encouraging regulation of what software others can write, what hardware others can ship?

I too am afraid of general purpose computing going by the wayside, and I have the Precursor phone and Raptor Talos PowerPC machines on my wishlist, just as soon as I wrap my head around secure boot chains in general before having to implement one myself. But niche hardware is expensive to produce, so we're likely left with what AMD, Intel and Apple provides us.

I guess one quirk that IMO is fair to criticize is that it's not necessarily consumers who are demanding to be locked out of their administrator privileges (the average computer user is of course not aware of the distinction of signed vs unsigned binaries), so I don't know where the pressure for secure enclaves really comes from. Is it the data centers buying thousands of chips that don't want to be pwned? government customers who refuse to buy a single die if they can't verify the bootloader? Or just patriotic engineers sensitive to a cybersecurity regime that demands we keep our guard up against enemies, foreign and domestic?

Re: Right to root access

#30

not sure if your in the US, but we can't even get net neutrality. Unfortuantely the likelyhood of this is a hell freezing over situation. I would start with, laws should be logical and informed and go from there... the number of prerequisite changes required to come mildly close to this is unreal. Including but not limited too: copyright law, insurance law, patents, contract law, federal vs state law, an agency compe…

California is typically pro consumer, tenant, employee.

If it could be passed in California it would trickle down elsewhere.

e.g. California emissions mandates leading to less emissions in the entire country because it makes more sense at scale to build 1 SKU.

Post reply on HN