Live data from Hacker News

We should have the ability to run any code we want on hardware we own

hugotunius.se

401–410 of 1001 posts

Re: We should have the ability to run any code we want on hardware we own

#401

Earlier quoted context omitted.

This is the crux of the matter. Maybe conceptually you will be able to run some kind of open operating system with your own code, but it will be unable to access software or services provided by corporate or governmental entities. This has been obvious for some time, and as soon as passkeys started popping up the endgame became clear. Pleading to the government definitely can't save us now though, because they want t…

> as soon as passkeys started popping up the endgame became clear That's why I'm 100% against passkeys. I'll never use them and I'll make sure nobody I know does. They're just a lock-in mechanism.

"Passkeys" is a new brand name slapped on an older open, interoperable technology, so it's difficult for me to be "against passkeys" as they haven't fundamentally changed anything.

Before the branding they were known as FIDO2 "discoverable credentials" or "resident keys".

Two things have changed with the rebrand:

1. A lot of platforms are adopting support for FIDO2 resident keys. This is good actually.

2. A lot of large companies have set themselves up as providers of FIDO2 resident keys without export or migration mechanisms. This is the vendor lock-in part (no export feature), but it's not a feature of the underlying tech itself.

Fwiw FIDO are actively working on some standard for exporting/importing keys so that's something.

If you want to use passkeys without lockin, just use Bitwarden or KeepPassXC - they all have full support. Or you can also store a limited number of passkeys on your FIDO2-compatible hardware key like Yubikey or the open-source Nitrokeys.

Re: We should have the ability to run any code we want on hardware we own

#402
post #61

As other comments have pointed out, this statement (one I 100% support, BTW) is a little naive. I can see how it might be unreasonable to expect companies to publish documentation, build infrastructure, etc. to support running your own code on the hardware you own (which 99% of people will never need to do). However, I strongly believe that - should one choose to do so - you should not be stopped from jailbreaking, c…

> Companies aren't obligated to support me doing this Where does one draw the line on support? If I jailbreak an iPhone, should I still get Apple customer support for the apps on it, even though they may have been manipulated by some aspect of the jailbreak? (Very real problem, easy to cause crashes in other apps when you mess around with root access) Should I still get a battery replacement within warranty from Appl…

Imagine Lenovo refusing to service your ThinkPad because you've compiled your own kernel.

Charging IC has NTC thermistor and battery absolutely must withstand the system running on 100% and then some.

As for battery lifetime, batteries are cheap, unless you glue them to an expensive assembly and force people to replace whole assembly as phone vendors do.

Re: We should have the ability to run any code we want on hardware we own

#403
Or:

One (a big entity with enough resources) should take this as an opportunity and create a new, third truly open alternative to iOS and Android (no, I'm not talking about an AOSP fork, I'm saying something totally new) and let iOS/Android have their thing as they want, letting consumers decide between the three instead of forcing vendors into ridiculous business decisions like forcefully opening their own platforms for others.

Re: We should have the ability to run any code we want on hardware we own

#404
post #393

Earlier quoted context omitted.

> as soon as passkeys started popping up the endgame became clear That's why I'm 100% against passkeys. I'll never use them and I'll make sure nobody I know does. They're just a lock-in mechanism.

For someone who hasn't spent any time thinking about that matter, could you please elaborate your point?

"Passkeys are incompatible with open-source software" https://www.smokingonabike.com/2025/01/04/passkey-marketing-...

Re: We should have the ability to run any code we want on hardware we own

#405

This makes the point that the real battle we should be fighting is not for control of Android/iOS, but the ability to run other operating systems on phones. That would be great, but as the author acknowledges, building those alternatives is basically impossible. Even assuming that building a solid alternative is feasible, though, I don't think their point stands. Generally I'm not keen on legislatively forcing a deve…

The real battle is over Google selling the public on the notion that Android would be the "open" platform that allowed people to run anything they liked on their device, and then deciding to use anticompetitive means to take that freedom away. Without that fraudulent marketing, Android never would have crowded out other options so quickly in the marketplace. The solution is to either have Google back down on breaking…

What worries me is that Google has a fairly legit argument to say "then Apple should as well". But we've accepted Apple's status for so long now, a lot of consumers are stockholmed into thinking giving away control is the only way to have a good phone (evidence: see any thread discussing that maybe Apple should allow other vendors to also use their smartwatch hardware to offer services in non-smartwatch-hardware markets that Apple also offers services in. Half the users seem like they're brainwashed by the marketing material they put out). I don't know that we can convince the general public anymore that 1984 is bad (thinking of Apple's own 1984 ad, specifically) and, without general public, there can theoretically also not be political will

I was part of this problem. I've accepted what Apple is doing because I had Android. I didn't think they'd come for me next so I didn't speak up

Re: We should have the ability to run any code we want on hardware we own

#406
13 years ago, Cory Doctorow warned us: https://www.youtube.com/watch?v=gbYXBJOFgeI

So basically market forces and profit optimization is at work here as always.

However, if we can still unlock the boot loader and install Lineage OS or something like that and have a way to pay for developers to release their apps on stores like f-droid we can use the hardware.

The biggest problem with having freedom to use our devices is that the model is broken for the developers who support them. You "can donate", but from the numbers I've seen it's like 1 in 1000 donate. No pay == developers can't invest their time to improve the software.

So if there is "really" a substantial number of enthusiasts that are ready to pay for the freedom they crave, then companies like Librem will have enough customers to create decent and usable products for this audience. Want digital freedom - prepare to support the people who provide it.

Yes, that might mean that we'll need to have 2 devices, 1 for "banking/government services" that is "certified" and one for our own usage. Shitty but we'll be forced to do that sooner on later. The efficiencies for the government to enforce the policies is so strong that they can't helps themselves. And corporations like to have more data to squeeze every cent from the customer.

So if there is a working business model for "freedom" we might have a partial freedom. If there isn't we'd be just a digital farm animals to be optimized for max profits and max compliance.

Re: We should have the ability to run any code we want on hardware we own

#408
post #393

Earlier quoted context omitted.

> as soon as passkeys started popping up the endgame became clear That's why I'm 100% against passkeys. I'll never use them and I'll make sure nobody I know does. They're just a lock-in mechanism.

For someone who hasn't spent any time thinking about that matter, could you please elaborate your point?

Imagine using ssh-keygen, but it locks the private key in a vendor-managed secure enclave. You can't copy it, export it, rename it or do anything wth it.

Re: We should have the ability to run any code we want on hardware we own

#409

Earlier quoted context omitted.

My parents are getting old and they aren't tech savvy. The missing piece here is that I want my parents to have a computer they can safely do their banking on, without leaving them vulnerable to scams and viruses and the like. I like that they have iphones. Doing internet banking on their phone is safer than doing it on their desktop computer. Why is that? The reason is that the desktop PC security model is deeply fl…

Everything in life is about trade-offs. Certain trade-offs people aren't going to make. - If you want to run an alternative operating system, you got to learn how it works. That is a trade off not even many tech savvy people want to make. - There is a trade-off with a desktop OS. I actually like the fact that it isn't super sand-boxed and locked down. I am willing to trade security & safety for control. > Personally…

AFAICT the only trade off is there's no support and few apps for Qubes OS. If it was as popular as MacOS or Windows what would the trade off be?

Re: We should have the ability to run any code we want on hardware we own

#410

Earlier quoted context omitted.

Incorrect. Choice 2. Empowered user. The end user is free to CHOOSE to delegate the hardware's approved signing solutions to a third party. Possibly even a third party that is already included in the base firmware such as Microsoft, Apple, OEM, 'Open Source' (sub menu: List of several reputable distros and a choice which might have a big scary message and involved confirmation process to trust the inserted boot media…

I like the way Chromebooks do things, initially locking down the hardware but allowing you to do whatever if you intentionally know what you're doing (after wiping the device for security reasons). It's a pity that there's all the Google tracking in them that's near impossible to delete (unless you remove Chrome OS).

I wonder if full device wipe would be the solution to "annoying enough that regular users don't do it even when asked by a scam, but power users can and will definitely use it".
Post reply on HN