Live data from Hacker News

We should have the ability to run any code we want on hardware we own

hugotunius.se

481–490 of 1001 posts

Re: We should have the ability to run any code we want on hardware we own

#481

Earlier quoted context omitted.

Incorrect. Choice 2. Empowered user. The end user is free to CHOOSE to delegate the hardware's approved signing solutions to a third party. Possibly even a third party that is already included in the base firmware such as Microsoft, Apple, OEM, 'Open Source' (sub menu: List of several reputable distros and a choice which might have a big scary message and involved confirmation process to trust the inserted boot media…

Consider the possibility of an evil maid type attack before a device is setup for the first time, e.g. running near identical iOS or macOS but with spyware preloaded, or even just adware.

It's possible to make this detectable, and chromebooks already do.

On a chromebook, if you toggle to developer mode you get a nag screen on early-boot telling you it's in developer mode every time, and if you're not in developer mode you can only boot signed code.

Basically, just bake into device's firmware that "if any non-apple keys have been added, forcibly display 'bootloader not signed by Apple, signed by X'", and if someone sees that on a "new" device, they'll know to run.

Re: We should have the ability to run any code we want on hardware we own

#482

Including cars, TVs, and home appliances -- those are the items I really want to hack.

Conversely those are some of the devices that make me question the principle “I should be able to run whatever code I want on hardware I own”.

Cars are increasingly controlled more via code than driver, but that (hopefully) goes through certification and oversight processes. Lane control, collision detection, self parking, self driving features - should people be able to hack these systems? Do we want people running their own collision detection routines that are less sensitive, because the stock option keeps slowing them down so much everyday when they drive past a school?

I imagine many of us here have encountered a computer that's broken because the user installed a programe to "make their machine faster" which deleted important windows files or removed everything from the startup folder that the user needs to use. I'm sure I could make a lot of money with a programme that decreases the time it takes to recharge your EV. Might remove heat protections, run at your own risk! (And the risk of passengers, neighbours, pedestrians and anyone your share a road with...)

I don't care if you want to run code that can allow more nuances to the seat heating, but do I think that's an important enough principle to also allow drivers to watch netflix on the in car display?

TVs and home appliances are less concerning, but I'm sure there's users out there who'd like to disable the annoying "don't run the dryer when it's full of lint" lock out or stop their garage door from beeping at their car everyday, not realising that setting also keeps it from closing on top of neighbourhood kids or cats.

I don't know if there's anyway to balance a reasonable right to tinker with a general right to live in a safe environment. I also suspect EU and US readers will have quite different takes on it - in part because of the current culture, in part because I think a lot of it is quite effected by geography. Live in dense housing and your neighbours ability to burn their house down is much more of your concern!)

Re: We should have the ability to run any code we want on hardware we own

#483
> Forcing Apple to change core tenets of iOS by legislative means would undermine what made the iPhone successful.

Successful for whom? If you're talking about the commercial success of apple through lock down behaviour, sure. But there is *nothing* that would prevent them from providing the exact same experience while adding a toggle in settings "allow sideloading". You want the "crisp" experience that comes from apple's strict review process, just use the official app store.

Looking at android till now, it is still possible to offer a "certified" os that is flexible enough for you to use foss stores. The argument pretending that removing sideloading is customer centric are borderline fallacious. I don't think that playing on semantics between hardware and OS changes any of that

Re: We should have the ability to run any code we want on hardware we own

#484
post #259
post #17

Earlier quoted context omitted.

That's a reductio ad absurdum conclusion. Both lobby for and are in major political cahoots with many governmental bodies worldwide. They lobby like crazy, and can defend just about any lawsuit that comes their way - including dodging congressional hearings, selectively adhering to laws other companies cannot afford to skip, etc. But I think you knew that. Being argumentative with the general point OP was making does…

Every point you raised is in fact evidence for how they are weaker than governments.

It depends on how you quantify it, which isn't really possible and isn't even the point of the comment.

It really feels like you're being intentionally obtuse here. The point was that they seem to be impervious to many governments. That would be having, by at least some measure, more power than the government.

They weren't meaning they were literal comparisons of amounts of power.

Re: We should have the ability to run any code we want on hardware we own

#485

This makes the point that the real battle we should be fighting is not for control of Android/iOS, but the ability to run other operating systems on phones. That would be great, but as the author acknowledges, building those alternatives is basically impossible. Even assuming that building a solid alternative is feasible, though, I don't think their point stands. Generally I'm not keen on legislatively forcing a deve…

> ability to run other operating systems on phones > building those alternatives is basically impossible For smart people it is not impossible. Just few years ago, few folks wrote complicated drivers for completely closed hardware, and I'm talking about M1 Macbook. Google Pixel, on the other hand, was pretty open until very recently. I might be wrong about specifics, but I'm pretty sure that most of software was open…

> I don't understand why mobile systems do not attract OS builders.

They're graphical consumer devices, the quality bar is so high nobody can reach it except huge well funded teams. It's like asking why desktop Linux doesn't still attract OS builders, or for that matter, why the PC platform doesn't attract OS builders. Occasionally someone makes an OS that boots to a simple windowed GUI as a hobby, that's as far as it gets now.

A lot of these HN discussions dance around or ignore this point. When people demand the freedom to run whatever they want, they never give use cases that motivate this. Which OS do they want to dual boot? Some minor respin of Android with a few tweaks that doesn't disagree with Google on anything substantial (Google accepted a lot of PRs from GrapheneOS people).

Nobody is building a compelling new OS even on platforms that have fully documented drivers. There's no point. There are no new ideas, operating systems are mature, it's done, there's nothing to do there. Even Meta gave up on their XROS and that was at least for a new hardware profile. Google did bend over backwards to let people treat phones like they were PCs but it seems regular Android is in practice open enough for what people want to do.

Re: We should have the ability to run any code we want on hardware we own

#486

Earlier quoted context omitted.

Technical solutions and alternatives can provide enough leverage for the common citizen to force the hand of those in power. It might not fully "solve" the issue, but making it easier to route around will always force those in power to bend somewhat.

In practice the opposite happens - when new technical workarounds are popularized, more technical solutions are found to prevent them and legislation is proposed to mandate them. Look at Chat Control in the EU: they started with mandating server-side scanning. Nobody liked that so everyone implemented E2EE. Now there's a new law that adds mandatory client-side scanning. Most of my tech-brained friends are saying "wha…

> whatever, we'll just compile from source or use alternative means of distribution.

google is clamping on this already so yeah

Re: We should have the ability to run any code we want on hardware we own

#487
post #31

> It should be possible to run Android on an iPhone and manufacturers should be required by law to provide enough technical support and documentation to make the development of new operating systems possible As someone who enjoyed Linux phones like the Nokia N900/950 and would love to see those hacker-spirited devices again, statements like this sound more than naïve to me. I can acknowledge my own interests here (ha…

>I also don’t see Apple or Google as merely companies that assemble parts and selling us "hardware". The decades when hardware and software were two disconnected worlds are gone. That when you buy a phone you're also buying software components doesn't change the fact that the phone is owned entirely by you. You're not entering into a partnership to co-own the phone with anyone else, it's entirely yours. No one should…

that has never been true, your phone contains a radio, governed by the relevant laws of your locale.

Re: We should have the ability to run any code we want on hardware we own

#488
post #341

Earlier quoted context omitted.

You realize you’re discounting 98% of the world’s population, right?

I think that the majority of the population can figure out how to stop installing software from untrustworthy sources, seeing as that was pretty much the norm 20 years ago. Everyone else can put on their loincloths and go back to living in flinstones-esque rock huts.

I think you’re mistaken, assuming that you’re even serious.

Re: We should have the ability to run any code we want on hardware we own

#489
post #165

> In this context this would mean having the ability and documentation to build or install alternative operating systems on this hardware It doesn't work. Everything from banks to Netflix and others are slowly edging out anything where they can't fully verify the chain of control to an entity they can have a legal or contractual relationship with. To be clear, this is fundamental, not incidental. You can't run your o…

I think you're right but I'd say it even more generally: we just can't let companies get so big that they can do these things without facing pushback and competition from other entities.

You'll find that a lot of 'normal', for lack of better word, support this.

Re: We should have the ability to run any code we want on hardware we own

#490
post #461
post #410

Earlier quoted context omitted.

I wonder if full device wipe would be the solution to "annoying enough that regular users don't do it even when asked by a scam, but power users can and will definitely use it".

That's how bootloader unlocking has worked on Android phones for ages, and I've never heard of it being abused, so I think it's a good model.

If that comes to pass I hope that one would be able to install a regular firmware with full DRM support / banking app support which only differs by allowing one to install apps freely. I don't think that's the case currently with firmwares that allow root. The security implications are somewhat different (root is more permissive) but I guess that the kind of person that wants to run arbitrary apps also prefer root access (maybe not at the cost of access to everyday apps with bullshit protections however).
Post reply on HN