Live data from Hacker News

Right to root access

medhir.com

331–340 of 428 posts

Re: Right to root access

#331
OP here. Really glad to see others engaging with this topic, I wrote up this post because I felt like there wasn't anything out there that was advocating for unlocked hardware as part of the discussion on "right to repair".

As someone that works in security, I fully understand the need for sane defaults that protect the average user. I even advocate in the article that we should keep these defaults in place for the most part.

What I tend to not understand is the argument that there should be no option for more enterprising users to access their hardware at the lowest levels because we need to protect the average consumer. It may be a footgun for some, but that's sort of the point. I expect to be able to modify something I own, whether it's to my detriment or not.

My argument isn't that root access should be the default, but at the very least it should be an option. I just don't think it's right that we've normalized corporations blocking the ability to load / inspect software, which often is marketed as a safety or privacy thing, but is arguably more a business decision meant to protect profit margins.

Re: Right to root access

#332
A libertarian and consumer friendly right-to-repair (RTR) / right-to-own (RTO) governance model could be something like Orthodox Union or UL but for consumer devices

The Right-to-Repair union RTR-U could be a simple authority with access to the keys to unlock the device if the vendor breaches certain commitments. Various levels of commitment could be offered similar to copy-left. The basic / lowest level would be "can unlock if the company dies". Higher commitments could be

will unlock if ...

company starts telemetry

company changes licensing

company stops providing timely firmware updates.

This way consumers are guaranteed a certain quality of service and access on their devices. Then vendors get a stamp of approval (like OU or UL) with the level of certification like RTR-open, RTR-private , RTR-long-terms-support etc.

This governance operates within private enterprise while consumers are offered the option to buy into vendors who commit to right-to-repair and right-to-own.

Re: Right to root access

#333
post #289

Earlier quoted context omitted.

> Who the fuck knows ? And how is that even remotely a useful question to ask - it's not answerable, those who commit the scam are the only people with the figures, and there's no "register of fuckers who scam other people" where they have to tell you how well they do. Um, why do crime statistics have to come from the perpetrators rather than from the victims? The victims report the crimes, duh. Anyway, you spent a l…

> Um, why do crime statistics have to come from the perpetrators rather than from the victims? The victims report the crimes, duh. You asked for (quoting) "Exactly how many people have fallen for the scam, out of all computer users". Not every crime is reported, duh. > Anyway, you spent a lot of words avoiding my question Nope. I can't answer the question because it's non-answerable. If you believe that nobody has ev…

> You asked for (quoting) "Exactly how many people have fallen for the scam, out of all computer users". Not every crime is reported, duh.

Not every crime is reported, but it's indisputable that a lot of crimes are reported. So give me a statistic, any reported statistic.

> If you believe that nobody has ever fallen for phishing, Nigerian-prince, etc. etc. scams, well, I don't know what colour the sky is on your world, but it's not the same as on mine...

How do you know this, except from reports by victims? That's what I'm asking for.

And once again, you haven't explained the mechanism by which vendor lockdown prevents this scam. However many or few victims there are of the scam, precisely zero of them are helped by vendor lockdown. I'm not going to stop asking how to explain how vendor lockdown is event relevant here.

> If you further believe that allowing everyone root access to devices that are also linked directly to their bank accounts, social security numbers, driving licenses, etc. etc.

This is hand waving, and it's not clear how root access by the owner of the device somehow exposes userland data to criminals. Moreover, all of this data is on desktop computers, and it's mostly fine.

Re: Right to root access

#334
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

Locking them down also makes supporting them *FAR* simpler.

Re: Right to root access

#335
post #32

There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…

It also significantly hampers progress and the utility of tools themselves. This is hacker news after all. What made the computer great was programs. What made the smart phone great (smart) is applications. It's insane to me that these companies are locking down their most valuable assets. The only way this works is if you're omniscient and can make all the programs users could want yourself. This is impossible consi…

this!!! sustainability is a huge aspect that seems to be getting lost in the broader discussion. locked devices are leading to an incredible amount of e-waste and it's entirely preventable.

Re: Right to root access

#336

Earlier quoted context omitted.

Not only profits, but control. Remember the whole CSAM scanning debacle from Apple?

was that when they said “instead of uploading the images to our servers to do the CSAM scan, we’ll do a quick once over in the privacy of your own phone to see if we can allow-list your photo” ? And then the whole world suddenly went apeshit, so Apple basically shrugged, said “fine, we’ll do it just like everyone else and put your photos in the relatively unprotected server domain to do the scan”. Sucks to be you. Un…

A server is someone else's device. Your phone is your own device. So no, doing the scan on your own device and making your device your potential adversary is not better than doing it on the server. You can always choose not to use the server.

Re: Right to root access

#337
post #308

Earlier quoted context omitted.

> If protection of the casual user was an argument, there would be an easy option to unlock your system, be that phones or desktop computers. Making it easy to unlock could make it easy(er) for scammers to get it unlocked: > I received the same type of call a little later in the day. They were very adamant they were calling from the Bell data centre, on a terrible line and I made them call back three more times while…

Unlocking should require a physical modification, like soldering a jumper or flipping an internal switch requiring disassembly. That would filter out basically all scam victims. If a scammer can teach a complete novice how to do micro soldering, they've earned their pay.

The Prusa Mini required you to snap a part of the pcb off to flash custom firmware. I actually like this approach, you have to very deliberately break apart of it to signal that you know what you are doing.

Re: Right to root access

#338
post #133

Earlier quoted context omitted.

Why should a software vendor be allowed to say what I can and can't run on my machine?

Because it’s their software? It is well within your bank’s rights to deny you access to their online banking system for pretty much any (technical) reason they choose; why are you entitled to run their app on what they deem to be an insecure platform? If you don’t like it, either pick a different bank or deal with not having access to their software. Freedom cuts both ways here; if you want absolute freedom to do wha…

> why are you entitled to run their app on what they deem to be an insecure platform?

For starters, because they're wrong, and they're wrong in a way that makes their users less secure. Allowing the use of Windows or Android with open CVEs while blocking completely up-to-date Linux or aftermarket Android ROMs clearly shows that this nonsense is contrary to security.

> If you don’t like it, either pick a different bank or deal with not having access to their software.

And that's the next biggest reason: Customers don't have the same amount of power that the companies have, so it's perfectly reasonable to tilt things in the customer's favor.

Re: Right to root access

#340
post #233

Earlier quoted context omitted.

> privacy-centric solutions are out there and relatively easy to find Really? Please name them. Over the past 10 or 15 years, I've never seen anything other than the iPhone/Android or Mac/Windows duopoly for sale in any retail store. I've never seen any advertising for other than those duopolies. The HN crowd may be aware of obscure options, but for the vast majority of consumers, they don't exist. And since we as de…

Here you go: https://us.starlabs.systems/ Now, how many of you guys have this? Or anything like this? I bet 95% of the HN crowd happily uses iOS/Android daily.

This is the first time I heard about it. Has anyone looked into their claims? Would love to buy an affordable Linux pad or a mini PC.
Post reply on HN