> In this context this would mean having the ability and documentation to build or install alternative operating systems on this hardware It doesn't work. Everything from banks to Netflix and others are slowly edging out anything where they can't fully verify the chain of control to an entity they can have a legal or contractual relationship with. To be clear, this is fundamental, not incidental. You can't run your o…
My parents are getting old and they aren't tech savvy. The missing piece here is that I want my parents to have a computer they can safely do their banking on, without leaving them vulnerable to scams and viruses and the like. I like that they have iphones. Doing internet banking on their phone is safer than doing it on their desktop computer. Why is that? The reason is that the desktop PC security model is deeply fl…
We should have the ability to run any code we want on hardware we own
531–540 of 1001 posts
Re: We should have the ability to run any code we want on hardware we own
#532Including cars, TVs, and home appliances -- those are the items I really want to hack.
Conversely those are some of the devices that make me question the principle “I should be able to run whatever code I want on hardware I own”. Cars are increasingly controlled more via code than driver, but that (hopefully) goes through certification and oversight processes. Lane control, collision detection, self parking, self driving features - should people be able to hack these systems? Do we want people running…
Re: We should have the ability to run any code we want on hardware we own
#533Earlier quoted context omitted.
What worries me is that Google has a fairly legit argument to say "then Apple should as well". But we've accepted Apple's status for so long now, a lot of consumers are stockholmed into thinking giving away control is the only way to have a good phone (evidence: see any thread discussing that maybe Apple should allow other vendors to also use their smartwatch hardware to offer services in non-smartwatch-hardware mark…
> What worries me is that Google has a fairly legit argument to say "then Apple should as well". Not a legal argument, since Apple never claimed the iPhone was anything else but a walled garden, and walled gardens are legal as long as you are clear that users will be buying into a walled garden from the start. (For example: Nintendo, PlayStation and Xbox) Legally, the only thing you could do is change the law to make…
Legislation, as you say, seems like it'll be necessary :/
Re: We should have the ability to run any code we want on hardware we own
#534Earlier quoted context omitted.
My parents are getting old and they aren't tech savvy. The missing piece here is that I want my parents to have a computer they can safely do their banking on, without leaving them vulnerable to scams and viruses and the like. I like that they have iphones. Doing internet banking on their phone is safer than doing it on their desktop computer. Why is that? The reason is that the desktop PC security model is deeply fl…
Everything in life is about trade-offs. Certain trade-offs people aren't going to make. - If you want to run an alternative operating system, you got to learn how it works. That is a trade off not even many tech savvy people want to make. - There is a trade-off with a desktop OS. I actually like the fact that it isn't super sand-boxed and locked down. I am willing to trade security & safety for control. > Personally…
You only need to learn how to start a browser. You're a little behind the times, today browser is the OS.
Re: We should have the ability to run any code we want on hardware we own
#535Earlier quoted context omitted.
"Passkeys" is a new brand name slapped on an older open, interoperable technology, so it's difficult for me to be "against passkeys" as they haven't fundamentally changed anything. Before the branding they were known as FIDO2 "discoverable credentials" or "resident keys". Two things have changed with the rebrand: 1. A lot of platforms are adopting support for FIDO2 resident keys. This is good actually. 2. A lot of la…
Passkeys would be wonderful if they removed remote attestation. Remote attestation is still there, so I will not touch it.
Lots of services that don't support passkeys currently require remote attestation. Boycotting passkeys (an open, possibly beneficial tech that doesn't require remote attestation) will not prevent bad actors from requiring remote attestation (with or without passkeys).
Re: We should have the ability to run any code we want on hardware we own
#536> Forcing Apple to change core tenets of iOS by legislative means would undermine what made the iPhone successful. Even if this is true… so what? Perhaps the App Store monopoly has helped make the iPhone successful, but that doesn't make it a good thing. > If you want to play Playstation games on your PS5 you must suffer Sony’s restrictions, but if you want to convert your PS5 into an emulator running Linux that shou…
Re: We should have the ability to run any code we want on hardware we own
#537Earlier quoted context omitted.
What are the stats here, this sounds like pure bs to be honest. Main way people around me get scammed by far like 90% is social engineering
It will need just one more additional authentication factor and blocking side loading apps on Android - We promise, total security is close! /s
Re: We should have the ability to run any code we want on hardware we own
#538Earlier quoted context omitted.
"Passkeys" is a new brand name slapped on an older open, interoperable technology, so it's difficult for me to be "against passkeys" as they haven't fundamentally changed anything. Before the branding they were known as FIDO2 "discoverable credentials" or "resident keys". Two things have changed with the rebrand: 1. A lot of platforms are adopting support for FIDO2 resident keys. This is good actually. 2. A lot of la…
By the way, notice Yubikey did not really release any new series/models and jacked up their price in just a few years. About 50% in 4 years. The large adoption of those devices and standards did not lower the price. They probably just banked on the enterprise market where every CISO was pressured to tick the hardware/2FA checkbox. And is then gonna allow to use the Microsoft/Google "software" one because it is hard t…
It's also become a much more niche product as software based (and/or primary-device-hardware-based) solutions have evolved & improved. & niche costs more.
All that said I'm really not sure why they've been so quiet on new series releases.
Re: We should have the ability to run any code we want on hardware we own
#539Earlier quoted context omitted.
Everything in life is about trade-offs. Certain trade-offs people aren't going to make. - If you want to run an alternative operating system, you got to learn how it works. That is a trade off not even many tech savvy people want to make. - There is a trade-off with a desktop OS. I actually like the fact that it isn't super sand-boxed and locked down. I am willing to trade security & safety for control. > Personally…
> If you want to run an alternative operating system, you got to learn how it works. The typical user doesn't know how Windows works, and they can run that. These days, users can run a friendly GNU/Linux distribution not knowing how it works. So, disagree with you here.
That is because Windows for the most part manages itself and there are enough IT professionals, repairs shops and other third support options (including someone that is good with computers that lives down the road) where people can problems sorted.
This is not the case with Linux.
> These days, users can run a friendly GNU/Linux distribution not knowing how it works. So, disagree with you here.
Sooner or later there will be an issue that will need to be solved with opening up a terminal and entering a set of esoteric commands. I've been using Linux on and off since 2002. I have done a Linux from Scratch build. I have tried most of the distros over the years, everything from Ubuntu to Gentoo.
When people claim that you will never have to know how it works. That is simply incorrect and gives a false impression to new users.
I would rather that other Linux users tell potential users the truth. There is trade off. You get a lot more control over your own computer, but you will need to peek under the hood sooner or later and you maybe be on your own solving problems yourself a lot of the time.
Re: We should have the ability to run any code we want on hardware we own
#540Earlier quoted context omitted.
My parents are getting old and they aren't tech savvy. The missing piece here is that I want my parents to have a computer they can safely do their banking on, without leaving them vulnerable to scams and viruses and the like. I like that they have iphones. Doing internet banking on their phone is safer than doing it on their desktop computer. Why is that? The reason is that the desktop PC security model is deeply fl…
Is it really safer on a phone ? Don't banking apps reject latest community Androids builds with all the CVE fixes or Graphene OS yet work totally fine on years old, full of vulnerabilities yet signed official Android ROMs ?