Live data from Hacker News

Pixel phones are sold with bootloader unlocking disabled

fitzsim.org

231–240 of 359 posts

Re: Pixel phones are sold with bootloader unlocking disabled

#231

Earlier quoted context omitted.

> this is bad because the vendor might Because the vendor can anytime say 'fuck you' and disable/remove the process which allows unlocking the bootloader. Edit: already happened with Pixel 2: https://news.ycombinator.com/item?id=35854552

So anyone who has already unlocked their Pixel 2 is good to go right? Getting the latest Pixel unlocked requires an internet connection, but once done it's done. So the complaint is that in the far future the vendor might not support that on a six year old phone (by that time)? But, it is supported now, so what's the beef? My old Pixel 2 only works now plugged into power and on WIFI because the battery is dead. I can…

supporting something and not spending extra effort to block it are two different things, google only needs to do the second one here

Re: Pixel phones are sold with bootloader unlocking disabled

#232

> connect the device to the Internet before they are allowed to install the operating system they want Phoning home before undertaking such an activity takes away the ownership rights from the customers. They do not actually own these devices even after they have purchased them. The reason is that an important part of their ownership rights, i.e. the freedom to use the software of their choice, has been withheld from…

So google is going through all this effort and some guy in China will just bypass the bootloader lock for $30. There is absolutely no way that the intelligence agencies don't have this same capability, which makes all of this security posturing utterly pointless, other than to prevent regular users from owning their devices.

Pretty sure that if there's a guy in China who is bypassing the bootloader lock for $30, he's just going to connect your device to the internet, and do what you wouldn't. Why wouldn't he?

Re: Pixel phones are sold with bootloader unlocking disabled

#233

How else do you expect they get your device on a surveillance list? Or do people honestly believe that the 0.001% of mobile phone users that unlock their bootloader for custom operating systems are not subject to additional scrutiny by big brother? NSA flagged Linux Journal as an "extremist forum" and flagged readers for extra surveillance - and that was a decade ago.

I think at this point Big Brother has the processing power to scrutinize everyone all the time anyway. It's naive to think that you were in any way off their radar before you unlocked your phone.

Perhaps, but deviating from social norms and ubiquitous technologies multiplies scrutiny. Most efforts made to boost privacy actually often have the opposite effect, but this is a subtle nuance few will understand.

Re: Pixel phones are sold with bootloader unlocking disabled

#234

> connect the device to the Internet before they are allowed to install the operating system they want Phoning home before undertaking such an activity takes away the ownership rights from the customers. They do not actually own these devices even after they have purchased them. The reason is that an important part of their ownership rights, i.e. the freedom to use the software of their choice, has been withheld from…

Isn't the bootloader software, so it's licensed, not sold? Are these "ownership rights" over the bootloader codified in law or a court decision?

Re: Pixel phones are sold with bootloader unlocking disabled

#235
post #74

Earlier quoted context omitted.

Not allowing a bootloader to be unlocked on a company-owned device does sound like a desirable feature, but only for company-owned devices. Applying that setup to all phones assumes that the default phone is a company-owned device and is subject to external control.

It assumes that company owned and managed phones are more common than people who want to unlock the bootloader. I know this isn't ideal, but that's the correct assumption to make.

It assumes that company owned and managed phones are more common that people who are unwilling to connect to the internet to unlock their bootloader. Which is definitely true. Probably by several orders of magnitude. Who cares? You get to unlock your bootloader.

Re: Pixel phones are sold with bootloader unlocking disabled

#236

Earlier quoted context omitted.

A different SKU for enterprise managed devices would cripple IT departments that don't pay the big bucks to e.g. verizon to manage their device provisioning & MDM enrollment.

Has it occurred to you that the feature you're defending allows Google to lock customers into their provisioning/MDM? That this is worse than Verizon controlling provisioning/MDM, because at least Verizon is subject to market competition (ie you can buy the device from other parties), whereas Google doing it means you have no choice whatsoever? You're also grossly exaggerating things. We're not talking about a change…

If this is like DEP on macOS, it is more like a first use redirect until enrollment than a fully-blown MDM.

Re: Pixel phones are sold with bootloader unlocking disabled

#237

Earlier quoted context omitted.

If the servers are running. If the servers deign to give permission to own the device you purchased. If they correctly recognize that this device is owned by the user. After I've purchased the device, the seller has no right to withhold ownership, and the existence of enterprise devices doesn't change that in the slightest.

If the process doesn't work then return it as defective. Transfer of control isn't happening exactly at sale time but a few hours later isn't a big deal. Though of course that depends on it staying unlocked.

What happens in 5 years when Google gets tired of running the server?

Re: Pixel phones are sold with bootloader unlocking disabled

#238

Earlier quoted context omitted.

Not allowing a bootloader to be unlocked on a company-owned device does sound like a desirable feature, but only for company-owned devices. Applying that setup to all phones assumes that the default phone is a company-owned device and is subject to external control.

A different SKU for enterprise managed devices would cripple IT departments that don't pay the big bucks to e.g. verizon to manage their device provisioning & MDM enrollment.

It would be much nicer if it defaulted to allowing unlocking through. You can boot up a DEP enrolled Mac and use it even if your internet connection doesn't work, including disabling SIP and the bootloader. Though your MDM attestation may fail if you then enroll it. That need to explain yourself to the IT department should be enough incentive to an employee to not unlock your work device bootloader.

Re: Pixel phones are sold with bootloader unlocking disabled

#239

Basically this is done to ensure that the phone isn't locked by the carrier, meaning if you buy the device directly from google you can still unlock the device by connecting to the internet. Yeah, it sucks, yeah, you own your device less in a way, but im happy they still let you do it. I sent a support message a while back asking about it on the google store thing - and they said it was unlocked. I installed graphene…

carrier locking is a separate thing from bootloader locking

Re: Pixel phones are sold with bootloader unlocking disabled

#240

"Magic hostname" mentioned in article (afwprovisioning-pa.googleapis.com) makes me believe this may be related to zero-touch enrollment of Android Enterprise/Android for Work ( https://support.google.com/work/android/answer/7514005 ). I'm sure devices sold to regular customers and enterprises are identical and nobody is going to unbox and pre-provision them before shipment, so unboxed phone needs to contact provision…

I wonder how this will work for Google. I can only speak for the Danish market, but when we (both private and public Enterprise) buy devices for business we tend to want the supplier to roll them for us. Apple and many Android manufactures does this. At one point we had a bunch of iPads stolen, likely from someone on the inside since they were delivered and then promptly “lifted” from where they had been delivered by someone who had a key and knew where the cameras were. But since Apple has enrolled them for us, they are essentially dead devices. It’s been some time since I worked for the organisation, but when I was still there we frequently got calls from people who had bought the iPad “legitimately” calling us to get it unlocked.

Google might not care, since it’s not likely to consider the EU it’s primary market for these things, but I think they risk finding out that their being “lazy” is going to bite them in the ass.

Or maybe I don’t understand the bootlicking enough, and what I described above of having a Pixel turn on as “owned by organisation” is entirely possible with it.

Post reply on HN