Live data from Hacker News

We should have the ability to run any code we want on hardware we own

hugotunius.se

571–580 of 1001 posts

Re: We should have the ability to run any code we want on hardware we own

#571
post #462
post #165

> In this context this would mean having the ability and documentation to build or install alternative operating systems on this hardware It doesn't work. Everything from banks to Netflix and others are slowly edging out anything where they can't fully verify the chain of control to an entity they can have a legal or contractual relationship with. To be clear, this is fundamental, not incidental. You can't run your o…

What I like about your comment is that it points out that all technical work-arounds are moot if people as a whole are not willing to stand up with pitchforks and torches to defend their freedoms. It will always come down to that. A handful of tech-savvy users with rooted devices and open-source software will not make a difference to the giant crushing machine that is the system. And I'm afraid most of us are part of…

Most people don't want to have to learn multiple operating systems or ways of doing things.

Re: We should have the ability to run any code we want on hardware we own

#572
post #84

We need both options to coexist: 1. Open, hackable hardware for those who want full control and for driving innovation 2. Locked-down, managed devices for vulnerable users who benefit from protection This concept of "I should run any code on hardware I own" is completely wrong as a universal principle. Yes, we absolutely should be able to run any code we want on open hardware we own - that option must exist. But we s…

If there is a big enough market for 1), shouldn't it exist?

The problem in my eyes seems to be that there isn't enough capital interested to sufficiently fund 1) to compete and create a comparable product. Thus, at best, we end up with much inferior products which even people semi-interested in 1) are not willing to adopt due to the extreme trade offs in usability.

Re: We should have the ability to run any code we want on hardware we own

#573
post #283

Earlier quoted context omitted.

Your parents are more likely to be a victim of a phone call scam than malware, even on PC. There is also no guarantee that malware will not slip through cracks of official stores or signatures. You can also choose to do your banking at the physical branch. We already had "best of both worlds", especially on mobile OSes - granular permissions per-app were quite good, and on Android until few years ago root was widely…

> Your parents are more likely to be a victim of a phone call scam than malware, even on PC. There is also no guarantee that malware will not slip through cracks of official stores or signatures. So what? The lack of perfect security is a terrible argument against better security. For example, lockpicks exist. Is that a reason to stop locking your house? Our TLS ciphers might eventually be broken. Should we throw awa…

It's not about being defeatist, atleast not for me. It's about what is considered good enough.

Sure, locking down the OS in this way is more secure, but it's also very restrictive and personally I don't think the added security justifies this. Lock picks do exist, but I am still entirely content with a single lock on my front door. I do not need an extra biometric sensor or camera or security representative standing outside my door to check id's of people passing by in order to consider myself reasonably safe.

Maybe this is cultural/geographical, but I've yet to hear of anyone who lost access to their mail or had unauthorized access to their bank account as a result of malware. I'm sure you can find examples, but I do not consider this an attack vector that is prevalent enough to warrant requiring signed apps or preventing manual installation.

Re: We should have the ability to run any code we want on hardware we own

#574
post #165

> In this context this would mean having the ability and documentation to build or install alternative operating systems on this hardware It doesn't work. Everything from banks to Netflix and others are slowly edging out anything where they can't fully verify the chain of control to an entity they can have a legal or contractual relationship with. To be clear, this is fundamental, not incidental. You can't run your o…

My parents are getting old and they aren't tech savvy. The missing piece here is that I want my parents to have a computer they can safely do their banking on, without leaving them vulnerable to scams and viruses and the like. I like that they have iphones. Doing internet banking on their phone is safer than doing it on their desktop computer. Why is that? The reason is that the desktop PC security model is deeply fl…

Good point. The current security model of desktop OSs sucks. I was recently reminded of this by an issue at work. I'm used to devs having admin rights on their laptops, but here they closed that down: you have to request admin rights for a specific purpose, and then you get them for a week.

I recently requested those rights again because I needed to install something new for a PoC I was working on, and that wasn't allowed anymore. But during onboarding I had those rights and installed homebrew to more easily install dev tools, and homebrew keeps its admin rights to install stuff in a directory owned by admin. So that circumvents this whole security model (and I did, for my PoC).

The problem is that it's all or nothing. Homebrew should have the right only to install in a specific directory. Apps shouldn't automatically get access to potentially sensitive data. Mobile OSs handle that sort of thing more granularly. Desktop OSs should too.

Because the overly restrictive security rules at my work are little more than security theatre when it's so easy to circumvent.

Re: We should have the ability to run any code we want on hardware we own

#575

> If you want to play Playstation games on your PS5 you must suffer Sony’s restrictions, but if you want to convert your PS5 into an emulator running Linux that should be possible. This is what Sony did with the PS3, but afaik Linux was then used as a backdoor to jailbreak the "PS3 OS" and sideload games. I guess, this is why Sony abandoned the idea of allowing Linux on their consoles. Kind of sad, but understandable…

The overarching issue is that this feature of the PS3 not only created cost in development/maintenance, but then negatively affected the core revenue-stream. So it was shut down, and Sony will never do this again.

Now we're at a point where there is no justification even for the cost of development/maintenance of such "open compute" features. Why even create a path for parts of your product to be "without rails" when there is no (legal) requirement for it and no significant commercial market, but just increased cost and complexity as well as security-risks.

I would like to see more devices being unlockable and provide the freedom to run "any code we want". But as there is no visible critical mass willing to pay for this, there is no market, and this means the current economic system doesn't support a company walking such a path.

So the only path I can see is to introduce an incentive for this into the system via a legal mandate, or change the system.

Re: We should have the ability to run any code we want on hardware we own

#577
post #283

Earlier quoted context omitted.

Your parents are more likely to be a victim of a phone call scam than malware, even on PC. There is also no guarantee that malware will not slip through cracks of official stores or signatures. You can also choose to do your banking at the physical branch. We already had "best of both worlds", especially on mobile OSes - granular permissions per-app were quite good, and on Android until few years ago root was widely…

> Your parents are more likely to be a victim of a phone call scam than malware, even on PC. There is also no guarantee that malware will not slip through cracks of official stores or signatures. So what? The lack of perfect security is a terrible argument against better security. For example, lockpicks exist. Is that a reason to stop locking your house? Our TLS ciphers might eventually be broken. Should we throw awa…

This hardly stops anything, app stores are full of malware, and the cost is very high.

It's like having an automated turret on your lawn because sometimes people bring bad snacks to your dinner parties.

Re: We should have the ability to run any code we want on hardware we own

#578
post #57

I want my less tech savvy family members to be able to buy locked-to-the-company-store hardware, that they can’t run other things on, as it protects them from one avenue of scams and hacks. This protection can and will be worked around if it can be easily disabled. Fully open phone systems consistently fail to sell enough to make a difference, which is a bit of a shame, but honestly at this point the market has spoke…

You provided an alterative solution yourself. Make protection harder to disable, so non-tech savvy users can't disable it easily, always inform them of the consequences of disabling it and make it that it's only needed in exceptional cases (there a lot of room for improvement here).

If they want to climb over the protection fence, they should be able to do it as they clearly WANT to do it. Why should you have control what they can or cannot do? (Unless they are your kids.) Should experts in other fields also be able to control over what their layman family members are allowed to do?

Re: We should have the ability to run any code we want on hardware we own

#579
post #84

We need both options to coexist: 1. Open, hackable hardware for those who want full control and for driving innovation 2. Locked-down, managed devices for vulnerable users who benefit from protection This concept of "I should run any code on hardware I own" is completely wrong as a universal principle. Yes, we absolutely should be able to run any code we want on open hardware we own - that option must exist. But we s…

This is just insane. Lock the devices down by default, and allow the user to unlock them if they want. Why do we have to have Big Brother devices that "benevolently" restrict what you can run "for your own good"? Why can't all phones have unlockable bootloaders? My phone has a big, scary "DO NOT DO THIS UNLESS YOU'RE A COMPUTER EXPERT" warning screen to unlock the bootloader, and that's fine.

Why do we need devices we can't unlock? Who is harmed by unlocking? This is the major point nobody has ever been able to explain to me. Who exactly does the big scary unlocked bootloader hurt? My parents have unlockable devices and they haven't had all their money stolen, because they haven't unlocked them.

Re: We should have the ability to run any code we want on hardware we own

#580
post #568

Earlier quoted context omitted.

These are basics of capitalism. Company aims for profit. Bigger scale allows for better efficiency. So companies naturally grow big. The bigger they are, the easier for them to compete. Big companies have access to tremendous resources, so they can push laws by bribing law makers, advertising their agenda to the masses. There's no way around it, not without dismantling capitalism. Nations will serve to the corporatio…

Bigger scale allows for better efficiency. This is dogma, not proven fact, and most people that argue this tend to use self-serving metrics and a tailored definition of "efficient". Some counterexamples: early Google was much more efficient in responding to market changes than the current top-heavy organization; small hospitals tend to have better health outcomes (both per patient and per dollar) than large chains. T…

I think you mean "nimble", "versatile", or "agile". None of these imply efficiency in the same sense economy of scale does (ie cost to produce a single deliverable unit).

There are good examples, though—you can produce a single gold ring a lot cheaper than you can produce a one-of-a-trillion of them, cuz at some point you simply run out of gold. Another example is running into a cap in demand. Classic sigmoid vs exponential patterns.

Post reply on HN