Live data from Hacker News

We should have the ability to run any code we want on hardware we own

hugotunius.se

621–630 of 1001 posts

Re: We should have the ability to run any code we want on hardware we own

#621

Earlier quoted context omitted.

No, not everything is a trade-off. Some things are just good and some are just bad. A working permission system would be objectively good. By that I mean one where a program called "image-editor" can only access "~/.config/image-editor", and files that you "File > Open". And if you want to bypass that and give it full permissions, it can be as simple as `$ yolo image-editor` or `# echo /usr/bin/image-editor >> /etc/y…

No everything is a trade off. That is a reality of life in general. Anything that is proposed has a cost associated with it (time, money). That always has to be weighed up against any potential benefit.

That claim is too generic to add anything to this discussion. Ok, everything has a trade off. Thanks for that fortune cookie wisdom. But we’re not discussing CS theory 101. In this case in particular, what is the cost exactly? Is it a cost worth paying?

Re: We should have the ability to run any code we want on hardware we own

#622
post #57

I want my less tech savvy family members to be able to buy locked-to-the-company-store hardware, that they can’t run other things on, as it protects them from one avenue of scams and hacks. This protection can and will be worked around if it can be easily disabled. Fully open phone systems consistently fail to sell enough to make a difference, which is a bit of a shame, but honestly at this point the market has spoke…

You provided an alterative solution yourself. Make protection harder to disable, so non-tech savvy users can't disable it easily, always inform them of the consequences of disabling it and make it that it's only needed in exceptional cases (there a lot of room for improvement here). If they want to climb over the protection fence, they should be able to do it as they clearly WANT to do it. Why should you have control…

> always inform them of the consequences

This would be about as useful as telling the cat why he can’t go out right now. The words would not be understood, as they won’t be by probably 90% of humanity.

> If they want to…

They don’t. Categorically. The only reason they would try is because they are being scammed with offers of getting something or cajolement entreating them to allow it.

> Why should you have control what they can or cannot do?

Me? I’m not asking for control. I’m saying that most people aren’t equipped to understand the threats they face, even in the face of explanation or warning, and their use-cases are comprehensively covered without it. My parents are old. My brother ends up with any PC he owns full of malware and viruses. The current status quo serves them and many millions of other people very well, and we need to be very cautious when arguing to rip this away in the name of our freedom - to them it only represents freedom to be exploited.

> Should experts in other fields also be able to control over what their layman family member…

Experts in other fields determine the extent of what all laypeople may do legally all the time. Or do you live somewhere that there are zero restrictions on (for example) gas plumbing or work on electrical systems?

Re: We should have the ability to run any code we want on hardware we own

#623
I think there are two issues, that maybe we should point out to help the debate:

- As a user sometimes I want to sideload legitimate applications (the question now is why can't these apps get approved on the appstore?)

- As a user sometimes I want to be able to use different devices from different vendors, I don't want to be forced to stay on Apple because airdrop or the keychain or login with Apple or my airpods pro don't work on Android anymore.

Re: We should have the ability to run any code we want on hardware we own

#624
post #525

Earlier quoted context omitted.

>There has never been a utopian past and there will never be a utopian future. I wouldn't call it utopian, but I'd say we are way past "peak democracy" at this point. There was a time in which corporations did get broken up when too large, when we did understand that it's about serving the population first and accumulating wealth after that, when corporations influencing politics was widely seen as a negative. It doe…

And when was this utopia in your opinion? This sounds like rosy retrospection to me. Or are you talking about a very specific industry, because the thread sounds like it is all society or "Late capitalism" which I disagree with.

I don't believe there was any utopian period in the past, but in US history, the Gilded Age had a lot in common with our current day (corruption, centralization of wealth and power, stemming from new technologies). And it was followed by the Progressive era and then the New Deal which were distinctly more populist in nature. Those were the eras of American history where the US got serious about anti-trust and unionization respectively.

Re: We should have the ability to run any code we want on hardware we own

#626

Earlier quoted context omitted.

My parents are getting old and they aren't tech savvy. The missing piece here is that I want my parents to have a computer they can safely do their banking on, without leaving them vulnerable to scams and viruses and the like. I like that they have iphones. Doing internet banking on their phone is safer than doing it on their desktop computer. Why is that? The reason is that the desktop PC security model is deeply fl…

This argument doesn't contradict the article. An expensive iPhone ships with iOS and a rigid security model. If you tap the `about` button 16 times and click a confirmation dialog, you disable certain security mechanisms against arbitrary software installation. Do something else easy but impossible to do accidentally, and you unlock the bootloader. You progressively lose portions of your warranty in doing so. This is…

Citation please? It’s my understanding that there is no officially approved way to unlock an iPhone.

They’ve had something like that for a long time on Android, and I think it’s a reasonable middle ground between making the platform open and closed. But as far as I know, Apple never did something like that on iOS.

Re: We should have the ability to run any code we want on hardware we own

#627

Earlier quoted context omitted.

In the netherlands we do not have physical branches anymore. They died out. All banking started to go through browser. This was very sensitive to malware and viruses, so two-factor was added through phones. Then less and less people had PCs because phone provides enough. Now mobile apps for banking is the only way to do banking. Or it is required for MFA. Even if you’re calling with the bank it is used as MFA

Same in Sweden, physical bank branches are rare and even they will often require an appointment. All banking is through bank apps or websites, and you use 2FA extensively. Sweden's digital ID system is called BankID because it was made by banks and, initially, for banking, though now BankID is used extensively for all kinds of government and private services. That doesn't stop scammers. They also keep getting more so…

Good to know. People should read this when they say cryptocurrencies are bad. Well, guess what, so is cash and your card. Any alternatives?

Re: We should have the ability to run any code we want on hardware we own

#628
post #165

> In this context this would mean having the ability and documentation to build or install alternative operating systems on this hardware It doesn't work. Everything from banks to Netflix and others are slowly edging out anything where they can't fully verify the chain of control to an entity they can have a legal or contractual relationship with. To be clear, this is fundamental, not incidental. You can't run your o…

I agree, but your points becomes stronger when you leave Netflix away. Netflix is a private entertainment company, and when I don't like their conditions I can always quit.

Banks on the other hand have so much more control over my life. With their apps being locked to the two major mobile OS I have many hoops to go through when I want to use an alternative one. It's not impossible yet, but it becomes very cumbersome to do so.

Re: We should have the ability to run any code we want on hardware we own

#629
post #84

We need both options to coexist: 1. Open, hackable hardware for those who want full control and for driving innovation 2. Locked-down, managed devices for vulnerable users who benefit from protection This concept of "I should run any code on hardware I own" is completely wrong as a universal principle. Yes, we absolutely should be able to run any code we want on open hardware we own - that option must exist. But we s…

You can have somr option burried in the settings, a 10yo kid would be able to think of this

Re: We should have the ability to run any code we want on hardware we own

#630
post #283

Earlier quoted context omitted.

Your parents are more likely to be a victim of a phone call scam than malware, even on PC. There is also no guarantee that malware will not slip through cracks of official stores or signatures. You can also choose to do your banking at the physical branch. We already had "best of both worlds", especially on mobile OSes - granular permissions per-app were quite good, and on Android until few years ago root was widely…

> You can also choose to do your banking at the physical branch The ones banks that do have physical presence are closing left and right? Also, I don’t think I can money transfers at the physical office of my bank.

> The ones banks that do have physical presence are closing left and right? Also, I don’t think I can money transfers at the physical office of my bank.

It's crazy if you really can't

Post reply on HN