Live data from Hacker News

Pixel phones are sold with bootloader unlocking disabled

fitzsim.org

271–280 of 359 posts

Re: Pixel phones are sold with bootloader unlocking disabled

#272

Disgusting. Google has taken the fraud of Android to a new level. The great "open-source" OS that was supposed to free us all from vendor and telco tyranny has spectacularly failed to do so, and to cripple fully-owned hardware in this manner just adds further insult. Say what you want about "socialist" countries in Europe, but I don't think this kind of bullshit would stand in France. Based on laws they've passed ove…

> I don't think this kind of bullshit would stand in France

France allows carrier locking, just like every other European country.

Re: Pixel phones are sold with bootloader unlocking disabled

#273

Earlier quoted context omitted.

So you don't own it when you buy it. At best Google still owns it and they graciously allow you permission to change the bootloader after you submit to their terms of service. Also, better hope their servers are online and reachable, and that you have functional internet.

This is honestly the most overblown issue I've ever seen on HN. How many people are buying a brand new in box pixel to install a custom OS on and do not have an internet connection anywhere, not even a free public wifi? I'd be shocked if this impacts even a single person. At this point it's being angry for the sake of it.

I can totally imagine a situation in which, in the future, someone buys a new old stock pixel phone and can't replace the OS because the bootloader can't be unlocked because the servers don't exist anymore.

A few years ago I bought a Nokia N900 which was at the time a 10 year old phone. I did this to use it as a daily driver.

Without community support the phone would have been useless. But, more importantly, if the phone required an internet connection to some server in order to let you replace the stock OS then it would have been a brick because Nokia's servers were long gone by then.

That being said, all things considered, the most important argument here is not of the practicality but the principle.

You handed over money for a piece of hardware but you can't make full use of the hardware until you let the phone talk to the manufacturer once. Thats completely insane irrespective of how small of a perceived issue you think it is.

Re: Pixel phones are sold with bootloader unlocking disabled

#274
post #114

> connect the device to the Internet before they are allowed to install the operating system they want Phoning home before undertaking such an activity takes away the ownership rights from the customers. They do not actually own these devices even after they have purchased them. The reason is that an important part of their ownership rights, i.e. the freedom to use the software of their choice, has been withheld from…

> Phoning home before undertaking such an activity takes away the ownership rights from the customers. They do not actually own these devices even after they have purchased them. Is this just philosophically speaking or were there some actual rights granted by law being violated?

I am unaware of any current law that would require devices which can run software to be able to run arbitrary software.

That being said, Google's Pixel phones have widely been known for their ability to unlock the bootloader and install an Android software of the user's choice. It was one of their selling points for a long time.

If this ability is turned into a "possibility" that can be taken away at any time and if it has not been properly communicated to the customers, then it might qualify as false advertising.

Re: Pixel phones are sold with bootloader unlocking disabled

#275
post #195

Earlier quoted context omitted.

The PinePhone can boot from an SD even if the eMMC install isn't working, so it kinda fits the description. You can either run an OS from the SD or boot an image to fix/reinstall on the eMMC.

Maybe not a great example. The PinePhone relies on software to manage its battery charging parameters. Thermal limits are controlled entirely in software and sent to the PMIC by the kernel, if this isn't done correctly or at all it's not just possible to have a brick, but a flaming brick. Another post on the matter: https://xnux.eu/log/#017

While this is absolutely true, and it should never have been implemented this way, I have been following the topic very closely and have not come across a single report of a flaming PinePhone in over three years. With five-digit numbers of PinePhone's out there in the hands of people who don't know what they are doing, this IMHO thus is fortunately mostly a theoretical issue.

BTW: PINE64 did better on the PinePhone Pro, and (since it's also going to be Rockchip (RK3566) based in all likelihood) is unlikely to replicate the mistake on the PinePhone 2.

Re: Pixel phones are sold with bootloader unlocking disabled

#276
post #74

Earlier quoted context omitted.

Not allowing a bootloader to be unlocked on a company-owned device does sound like a desirable feature, but only for company-owned devices. Applying that setup to all phones assumes that the default phone is a company-owned device and is subject to external control.

It assumes that company owned and managed phones are more common than people who want to unlock the bootloader. I know this isn't ideal, but that's the correct assumption to make.

I don't know about managed, but for high-end I think it's been true for many years that the bulk of them are bought by companies.

Re: Pixel phones are sold with bootloader unlocking disabled

#277
post #48

> connect the device to the Internet before they are allowed to install the operating system they want Phoning home before undertaking such an activity takes away the ownership rights from the customers. They do not actually own these devices even after they have purchased them. The reason is that an important part of their ownership rights, i.e. the freedom to use the software of their choice, has been withheld from…

Xiaomi does the same (or at least did until my latest phone change i.e. around 3 years ago). You must unlock the bootloader before being able to install a custom recovery image such as TWRP, which itself is used to install custom ROMs. This unlock involves: creating a user account in the Xiaomi services website, logging into that account from your phone's system, then having the phone logged in for at least 7 days ,…

> then having the phone logged in for at least 7 days

I unlocked the bootloader with the unlock tool less than 12 hours after purchasing my Xiaomi Mi 8. How come everybody has to wait that long?

Re: Pixel phones are sold with bootloader unlocking disabled

#278
post #48

> connect the device to the Internet before they are allowed to install the operating system they want Phoning home before undertaking such an activity takes away the ownership rights from the customers. They do not actually own these devices even after they have purchased them. The reason is that an important part of their ownership rights, i.e. the freedom to use the software of their choice, has been withheld from…

Xiaomi does the same (or at least did until my latest phone change i.e. around 3 years ago). You must unlock the bootloader before being able to install a custom recovery image such as TWRP, which itself is used to install custom ROMs. This unlock involves: creating a user account in the Xiaomi services website, logging into that account from your phone's system, then having the phone logged in for at least 7 days ,…

I once had to follow a similar process to get the key to sign apps to install on my nokia symbian phone.

Re: Pixel phones are sold with bootloader unlocking disabled

#279

Earlier quoted context omitted.

So google is going through all this effort and some guy in China will just bypass the bootloader lock for $30. There is absolutely no way that the intelligence agencies don't have this same capability, which makes all of this security posturing utterly pointless, other than to prevent regular users from owning their devices.

> some guy in China will just bypass the bootloader lock for $30. I've seen this kind of thing before but I have no idea how this works. Is it an insider employee at google or a mobile provider that is doing this on the side? Is it a 0-day exploit? Is it something that anyone can do but someone is productizing it for $30?

I think that it is something anyone can do, provided that they know how. I would assume that it is as simple as putting the phone into some kind of low-level programming mode, perhaps EDL or similar, and overwriting a few bytes of data.

These low-level modes likely use proprietary protocols that are only known to the vendors who manufacture the SoC used in the phone, for example Qualcomm. As many of those devices are manufactured in China, it is likely that someone who worked there leaked some tools for performing these low-level programming activities. And then they figured out how to use these tools for unlocking the bootloaders.

Post reply on HN