Earlier quoted context omitted.
Still, those permissions are standard Linux permissions. So the argument that Linux is less secure than Android is a little hard to understand. A little more specificity might help.
They're definitely not "standard Linux permissions." Yes Android does use many of those (such as standard user IDs, file system permissions, and now SELinux) to implement some of its permissions, but it adds a ton of permissions on top that are not part of Linux.
Right to root access
381–390 of 428 posts
Re: Right to root access
#382Banking, some government and crypto apps on Android think: no They sometimes actively search for root evidence.
Namely, that's what I do with proprietary software on my desktop. Nothing that's closed runs with access to my files. Further, a banking app shouldn't need to know I'm running a rooted device. For some reason, I can do banking with an open source browser on a rooted phone just fine. It's just the proprietary blob that comes with TPM shackles, and I think I should be the owner of those shackles because I own my phone.
Re: Right to root access
#383Earlier quoted context omitted.
I'm actually confused about why banks are so aggressive in denying users the ability to use their apps while rooted. Unlike Google and Apple I can't think of any financial incentives for this, and the security argument is quite obviously nonsense, as I don't think there has been a single person in history who managed to fall for a scam that made them follow the complicated procedure of rooting a smartphone. Neverthel…
I believe the root detection is a form of security-by-obscurity. Bank applications are required to be obfuscated, so you can't simply statically decompile them. The other way to do that is to run the app and set runtime breakpoints, which you can't do on production firmware. Once the application is decompiled the attacker then can proceed to pentest the bank backend, or find any frontend-only security measures to byp…
Re: Right to root access
#384Earlier quoted context omitted.
This is the first time I heard about it. Has anyone looked into their claims? Would love to buy an affordable Linux pad or a mini PC.
FWIW, I have no idea if this is any good. My point is, I found this after maybe 3 minutes searching. If we were to spend 30 minutes, we would definitely find something reasonable.
Re: Right to root access
#385There are a ton of products on the market that are vastly more dangerous than computers: guns, cars, motorcycles, bicycles, chainsaws, table saws, cigarettes, alcohol, junk food. Yes, consumers do sometimes harm themselves by using these products. That's the price of freedom . I think it's bizarre that we treat computers as the most dangerous products in the world that for some reason demand paternalism, when none of…
Before we put all the blame on vendors, I submit to you, ladies and gentlemen, this: the public finds this tradeoff (privacy for entertainment) completely acceptable. With all the outrage, privacy-centric solutions are out there and relatively easy to find, how come they don't get more traction? Including among the HN crowd?
Re: Right to root access
#386Earlier quoted context omitted.
I agree useful rooting should be easier, but it's definitely possible and not super hard to hide rooting. I'm typing this on a rooted phone where all (banking) apps work just fine. All it takes is downloading an app (magisk) and add apps to a list that need to have rooting hidden.
> it's definitely possible and not super hard to hide rooting. Worth noting that this could change with every update. It's an unstable situation right now, which is undesirable. For that reason, e.g. the GrapheneOS team isn't employing measures to fake compliance at all. They'd really like to get SafetyNet compliance for their operating system (you need that to get Google Pay/Wallet to work), but funamentally can't g…
Re: Right to root access
#387Earlier quoted context omitted.
You appear to be conflating two different things: legal mandates and vendor lockdown. There are legal mandates regarding the sale and use of certain products. For example, you have to be a minimum age to buy cigarettes and alcohol, stores in some localities can only sell alcohol during certain hours, bars have to close at a certain time, you can't drive drunk, you must wear a seatbelt, you can't exceed the speed limi…
A cigarette will not allow anyone to smoke it if the vendor locked down sales and can't sell it to you, so you don't have it. This is a much more serious restriction of consumer freedoms than if anyone can buy and use, but can't smoke when drunk and in bed (fire safety) due to some other lockdown mechanism built into the cigarette itself. More people are affected, and the effect of full exclusion is stronger even tho…
You're equivocating on the word "vendor". You know full well that in this context, the vendor means the manufacturer of the computer, for example, Apple, and not the retail store selling the computer, which may not be Apple but rather Best Buy, for example. Likewise, in my analogy, vendor lockdown of a cigarrete would mean lockdown from the manufacturer of the cigarette, for example, Philip Morris, and not the retail store selling the cigarette.
> This is a much more serious restriction of consumer freedoms than if anyone can buy and use, but can't smoke when drunk and in bed (fire safety) due to some other lockdown mechanism built into the cigarette itself. More people are affected
This is actually false, because the only restriction on the sale of cigarettes is that you can't buy them if you're under age 18. Anyone age 18 or older is free to buy and smoke as many cigarettes as they want. Adults have full, unrestricted freedom. And that's what they should have for computers too. For better or worse, children have a huge number of legal restrictions on them.
Computer vendor lockdown affects all adults, no matter how old. Indeed, some people claim that the point is to protect your grandma, yadda yadda.
This is actually my point about being "dangerous". That is, we seem to consider computers as the most dangerous product for fully grown adults who have no age-related restrictions on purchasing things, because nobody is proposing or defending manufacturer lockdowns on other products for fully grown adults. We think that fully grown adults get to decided whether to smoke cigarettes, drink alcohol, eat junk food, etc., but for some reason fully grown adults can't decide to install software on their own computer.
> So here is your mistake when you only accept something almost literally identical to computer lockdown (same with your fridge example), but brushing off more serious usage "lockdowns" that don't exist with computers
I wasn't "brushing off" legal restrictions. I was merely distinguishing them from restrictions that come from the manufacturer.
The difference, of course, is that computer vendor lockdown is not legally mandated, and thus they don't have to lock down the devices. They're doing it totally voluntarily, and I believe the reason is increased profit rather than increased security.
> Yes, this exists and is common in complex mechanical things, e.g., you lose warranty if you use unapproved parts, or for some parts there is actually not even an alternative, so manufacture is the only one getting a cut
And this malicious practice is being challenged by "right to repair" laws.
> So again, there is nothing unique or "most dangerous" about computers in either reality or people's prescriptions
You're missing the entire point here. There are a lot of people who defend computer vendor software lockdown, in the name of "security", but there aren't nearly as many people who defend the warranty practices you just mentioned.
Re: Right to root access
#388Earlier quoted context omitted.
A cigarette will not allow anyone to smoke it if the vendor locked down sales and can't sell it to you, so you don't have it. This is a much more serious restriction of consumer freedoms than if anyone can buy and use, but can't smoke when drunk and in bed (fire safety) due to some other lockdown mechanism built into the cigarette itself. More people are affected, and the effect of full exclusion is stronger even tho…
> A cigarette will not allow anyone to smoke it if the vendor locked down sales and can't sell it to you, so you don't have it. You're equivocating on the word "vendor". You know full well that in this context, the vendor means the manufacturer of the computer, for example, Apple, and not the retail store selling the computer, which may not be Apple but rather Best Buy, for example. Likewise, in my analogy, vendor lo…
I find the limitations of your analogy artifical and thus irrelevant. Other people thinking about the trade-offs aren't bound by whether you decide that in the whole supply chain only the manufacturer's limits should be considered. So while you're free to arbitrarily limit your thinking, that won't help you answer questions like "Why do computers get this special treatment of vendor lockdown, but not any other product?"
> reason is increased profit rather than increased security.
That's fine, but we shouldn't rely on vendor motivation anyway, so the validity of your assessment doesn't help us decide when the increased security is worth it
> You're missing the entire point here
You've cut your quote off to make it seem so. I've explicitly mentioned the perception in the very next sentence
> but there aren't nearly as many people who defend the warranty practices you just mentioned.
That would depend entirely on the specific tech involved and other factors. Are you sure people defending software vendor lockdowns would not defend some limits for parts for nuclear plants? For guns? Also why did you skip the "for some parts there is actually not even an alternative" practice? Would fewer people defend the right of a manufacturer to also manufature parts for sale (forcing some kind of divestment so that the "vendor" doesn't get an extra "fee" from the parts business)?
Re: Right to root access
#389Earlier quoted context omitted.
> If protection of the casual user was an argument, there would be an easy option to unlock your system, be that phones or desktop computers. Making it easy to unlock could make it easy(er) for scammers to get it unlocked: > I received the same type of call a little later in the day. They were very adamant they were calling from the Bell data centre, on a terrible line and I made them call back three more times while…
Easy doesn't mean without any warning, it just means that the device is unlockable by design and without OEM's approval. It would be reasonable to: - factory reset the device before unlocking it to protect existing data (like Android phones require) - display warnings, for example "if someone's asking you to do this, it's probably a scam" - for the owner to be allowed to permanently disable unlocking, e.g. the common…
I never understood this point. From what threat is it protecting the data from? Surely a thief should not be able to unlock a device without first typing the correct pin/password, and it they can do that they should be able to access the data regardless.
Re: Right to root access
#390Yes, please! Unfortunately, your smartphone doesn't (really) belong to you. It's a shared property between the hardware maker, the low level software producer (Qualcomm or Apple), the os owner (Google or Apple) and maybe finally you. Undocumented hardware plus closed source drivers for almost everything make all this possible.
Speak for yourself. Sent from my Librem 5.