Live data from Hacker News

Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

thenextweb.com

231–236 of 236 posts

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#231
post #152

Earlier quoted context omitted.

Oh, surprise Google fan boys/employees downvoting a critical post about the company without leaving a comment. How typical. This is getting boring on HN.

https://news.ycombinator.com/newsguidelines.html

Not related to parent post but I think those guidelines urgently need to be updated with rules about abuse of the flagging mechanism.

I have had multiple HN posts flagged by people who wanted to reduce its visibility.

(One happened on this very page)

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#232

Earlier quoted context omitted.

How complex it is to test all known issues against all current kernels? A weekly report with some easy to understand graphs would probably convince more people to work on these bugs.

Time and cost, same as it would be to do it across all kernel versions, not just current ones. Theoretically could be done pretty simply via a CI/CD pipeline if someone wrote solid test cases for the issues found by the fuzzier.

Thats my point! Make this part of the kernel regression and also run it on the old kernels.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#233

Earlier quoted context omitted.

> How can you hold it and at the same time advocate against their choice to use a system that doesn't have the ability to install apps from untrustworthy sources? The availability of such systems is obviously an increase in available choice, not a decrease. Saying "doesn't have the ability to install apps from other sources" is the same as saying "doesn't give you the choice to install apps from other sources" -- it'…

I'm sorry, but you have completely missed the point. I generally try not to respond in ways that can be construed as rude, but there was only one point, it was core to my comment, and your comment indicates that you did not understand it. > You could choose not to even if your ability to choose was not restricted. Choosing not to install apps that aren't approved by Apple is not the same thing as choosing to use a de…

> How can someone (perhaps yourself?) be in favor of expanding choice and also opposed to to the existence of this choice?

The issue isn't that an iPhone on which you can't install apps not approved by Apple exists, it's that an iPhone (i.e. Apple hardware running iOS) on which you can install apps not approved by Apple doesn't exist, so that choice is missing from the market. In order for it to be a choice it is necessary for both alternatives to be available.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#234
post #146

Earlier quoted context omitted.

I don't think it's an underestimated view, it's quite common. I just don't think it would be compromised very much if there was an optional escape hatch. Buying a hypothetical Apple device and never flicking on the sideloading switch would still give you that. Whereas the person who generally prefers the security engineering, design choices and/or integration of iOS but wants some exceptions is now told "If you care…

> Buying a hypothetical Apple device and never flicking on the sideloading switch would still give you that. Until someone (my abusive spouse? someone with a narrowly scoped zero-day and physical access to my phone?) abuses the existence of this functionality in ways that compromise my security. > Whereas the person who generally prefers the security engineering, design choices and/or integration of iOS but wants som…

> I agree with you here. It would be great if Apple offered two classes of iPhone, one where such a switch was present and one where unsigned code was prevented from executing by hardware.

You don't even need two classes of phone, just a setting to allow unsigned code which requires a factory reset to change.

Nobody can compromise the data on your phone with unsigned code if switching to unsigned code requires erasing the phone, and you're going to notice immediately if your phone has been wiped, which is no worse for you than someone with physical access smashing it with a hammer and replacing it with another phone.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#235
post #146

Earlier quoted context omitted.

I don't think it's an underestimated view, it's quite common. I just don't think it would be compromised very much if there was an optional escape hatch. Buying a hypothetical Apple device and never flicking on the sideloading switch would still give you that. Whereas the person who generally prefers the security engineering, design choices and/or integration of iOS but wants some exceptions is now told "If you care…

> Buying a hypothetical Apple device and never flicking on the sideloading switch would still give you that. Until someone (my abusive spouse? someone with a narrowly scoped zero-day and physical access to my phone?) abuses the existence of this functionality in ways that compromise my security. > Whereas the person who generally prefers the security engineering, design choices and/or integration of iOS but wants som…

Could be very visible. E.g. on some Androids (and I think Chromebooks too), unlocking the boot loader adds a large exclamation mark or other warning to the boot screen.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#236

Earlier quoted context omitted.

I'm sorry, but you have completely missed the point. I generally try not to respond in ways that can be construed as rude, but there was only one point, it was core to my comment, and your comment indicates that you did not understand it. > You could choose not to even if your ability to choose was not restricted. Choosing not to install apps that aren't approved by Apple is not the same thing as choosing to use a de…

> How can someone (perhaps yourself?) be in favor of expanding choice and also opposed to to the existence of this choice? The issue isn't that an iPhone on which you can't install apps not approved by Apple exists, it's that an iPhone (i.e. Apple hardware running iOS) on which you can install apps not approved by Apple doesn't exist, so that choice is missing from the market. In order for it to be a choice it is nec…

> In order for it to be a choice it is necessary for both alternatives to be available.

Fair, and ideally both options would exist. But an Android phone is a close approximation of an unlocked iPhone, while there is no other close approximation of a locked iPhone. Pushing the security stance of iPhone to align more closely with Android is a homogenization of the landscape and a reduction in the diversity of options.

Post reply on HN