Earlier quoted context omitted.
> A scam app with root Sure. But the people who are actually rooting their phones are advanced users and aren't going to install a malicious custom OS. Are naive users getting tricked into rooting their own phones? I'm dubious what the security benefit is of this decision.
These types of discussions on HN get confused because people aren't always clear what they mean by the word "rooting". There are two ways to root a phone: 1. Unlock the bootloader, install a well designed and highly secure aftermarket OS, relock the bootloader. The device is still just as secure against malware as it was before. Remote attestation shows the vendor that you're running Graphene or Lineage or whatever.…
The Vietnam government has banned rooted phones from using any banking app
371–380 of 643 posts
Re: The Vietnam government has banned rooted phones from using any banking app
#372The biggest "evil" that has been committed (and is still being committed) against computing has been normalizing this idea of not having root access to a device you supposedly own. That having root access to your computer, and therefore being the ultimate authority over what gets run on it, is bad or risky or dangerous. That "sideloading" is weird and needs a separate name, and is not the normal case of simply loadin…
I think, practically, everyone will need at least a cheap-ish android or iphone, perhaps $300 (and a new one every few years ...), to be their locked-down "agent" for using financial or government services. It's not for you, it's for the government/banks, it is their agent for talking to you. Kinda weird, if you think about it. But that seems to be the way it's heading.
Re: The Vietnam government has banned rooted phones from using any banking app
#373Earlier quoted context omitted.
The problem is mostly that normal people can't be trusted with system-level access but some people can. And it's literally, provably not possible to tell them apart. For the masses, lack of system-level access is a benefit because they won't be able to ruin their device. For hackers and hobbyists, lack of system-level access is a hindrance because they won't be able to control their device.
> normal people can't be trusted with system-level access but some people can. Why can "normal people" be trusted with a car then? Or firearms? Or kitchen knives?
Tylenol is another example. Building materials is a third (building and fire codes are a relatively recent invention). Hell, even penicillin is by prescription only.
Letting the circumstance happen where median people can easily cause externalities through ignorance or carelessness is how we incinerated the planet and destroyed the biosphere as we know it with fossil fuel emissions, because it’s nbd (still even now in 2026, when we know about runaway polar greenhouse curves) to get in your ICE car and drive to the corner store.
When normal people had GP computers, we got botnets millions strong and DDoS in the Tbit/sec range and keyloggers on every hotel lobby computer hooked up to the boarding pass printer. Median people are way safer on the internet now than before.
Re: The Vietnam government has banned rooted phones from using any banking app
#374The biggest "evil" that has been committed (and is still being committed) against computing has been normalizing this idea of not having root access to a device you supposedly own. That having root access to your computer, and therefore being the ultimate authority over what gets run on it, is bad or risky or dangerous. That "sideloading" is weird and needs a separate name, and is not the normal case of simply loadin…
And a full on fight against ownership of stuff you paid, right to repair something you own with your own money, and general computing access.
Re: The Vietnam government has banned rooted phones from using any banking app
#375It's not just root that they block.
Re: The Vietnam government has banned rooted phones from using any banking app
#376Earlier quoted context omitted.
It’s not an evil at all. For 99% of people who aren’t “computer people”, when we gave them that, we got the Bonzai Buddy and 47 other malware toolbars installed. Did we forget 2003 already? App sandboxing and system file integrity is one of the most beneficial security features of modern computing, and the vast majority of people have no desire to turn it off. You can buy rootable phones. People overwhelmingly choose…
> App sandboxing and system file integrity is one of the most beneficial security features of modern computing, You can have sandboxing and system integrity while still giving the user overrides. But hey this is not Google and Apple's business model because it makes you less dependent on them. And it interferes with their sweet 30% rent-seeking app stores. Mobile security works this way not because it's best for us b…
Re: The Vietnam government has banned rooted phones from using any banking app
#377The biggest "evil" that has been committed (and is still being committed) against computing has been normalizing this idea of not having root access to a device you supposedly own. That having root access to your computer, and therefore being the ultimate authority over what gets run on it, is bad or risky or dangerous. That "sideloading" is weird and needs a separate name, and is not the normal case of simply loadin…
Re: The Vietnam government has banned rooted phones from using any banking app
#378Earlier quoted context omitted.
The problem is mostly that normal people can't be trusted with system-level access but some people can. And it's literally, provably not possible to tell them apart. For the masses, lack of system-level access is a benefit because they won't be able to ruin their device. For hackers and hobbyists, lack of system-level access is a hindrance because they won't be able to control their device.
In other areas of life, people self-select at their own risk. You can diagnose medical issues yourself, buy power tools you don't know how to use safely, and invest in assets that you don't understand. All other things being equal, we should try to protect people. But we shouldn't force everyone to make the choices that are best for the people with the least comprehension of what they're doing.
We also limit investing in certain types of investments to so-called “accredited investors” which is just legal jargon for “millionaires”.
I don’t think the point you are trying to make about letting people own-goal is as strong as you think it is. (I would have gone with “roulette is legal”, which is a better one that the investment one, as the accredited investor rule is in all 50 states.)
Re: The Vietnam government has banned rooted phones from using any banking app
#379Earlier quoted context omitted.
It’s not an evil at all. For 99% of people who aren’t “computer people”, when we gave them that, we got the Bonzai Buddy and 47 other malware toolbars installed. Did we forget 2003 already? App sandboxing and system file integrity is one of the most beneficial security features of modern computing, and the vast majority of people have no desire to turn it off. You can buy rootable phones. People overwhelmingly choose…
> App sandboxing and system file integrity is one of the most beneficial security features of modern computing, You can have sandboxing and system integrity while still giving the user overrides. But hey this is not Google and Apple's business model because it makes you less dependent on them. And it interferes with their sweet 30% rent-seeking app stores. Mobile security works this way not because it's best for us b…
I think this is wishful thinking, and the most experienced organizations in the world in this field agree with me. You can’t square this circle.
We can pretend that these two things can coexist, but they cannot. Where there are overrides, there are youtube tutorials on how to disable the overrides to install malicious botnet vpn surveillance proxy apps to get free robux. (to borrow a turn of phrase from @ptacek iirc)
If you give users an escape hatch, they will get malware in ring 0 and Apple Pay will stop being a thing because people’s cards will start getting remotely skimmed at scale. (Or Amazon will give you 1.5% off all purchases to install a rootkit that uploads your complete realtime cc nfc purchase boop history and email receipts and location track so they can figure out which businesses to clone/dump on next.)
If you say “…but not the SEP” then you’re just admitting that you need a part of the phone the user does not and cannot control. Most users care about the privacy of their nudes and sexts so they’d rather it be the whole damn phone.
Did we forget that even the not-full-scale escape hatch that was enterprise app certs was abused by Meta (then Facebook) to install surveillance VPN backdoors on customer phones at scale? Apple didn’t even know bc they were sideloading them via enterprise certs and when they found out they revoked them across the board, but by then thousands of people had had 100% of their phone’s network traffic surveilled by an ad company without consent.
Re: The Vietnam government has banned rooted phones from using any banking app
#380Earlier quoted context omitted.
When I was running a home server as a kid, I IP-blocked the entire continent of Asia because I was constantly getting pings, portscans, HTTP path guesses, SSH auth attempts, etc randomly from there. Of course I secured my stuff to the best of my knowledge, but I still didn't want that harassment cause 1. who knows 2. could be ddos'd. When finding help on how to do this, people were saying it's useless cause they can…
lol you should see how bad it is nowadays. Like 90% of my traffic is from SE Asia or germany trying to scrape my site. I blocked like a dozen countries because of it. Singapore itself is an insane amount of traffic for me.