Live data from Hacker News

We should have the ability to run any code we want on hardware we own

hugotunius.se

651–660 of 1001 posts

Re: We should have the ability to run any code we want on hardware we own

#651

Earlier quoted context omitted.

Incorrect. Choice 2. Empowered user. The end user is free to CHOOSE to delegate the hardware's approved signing solutions to a third party. Possibly even a third party that is already included in the base firmware such as Microsoft, Apple, OEM, 'Open Source' (sub menu: List of several reputable distros and a choice which might have a big scary message and involved confirmation process to trust the inserted boot media…

Incorrect. For us as tech people this is an option. My older family members will definitely install malware and send all their data to China. Please don’t let me go back to the early days of the internet where my mother had 50 toolbars and malware installed

> Please don’t let me go back to the early days of the internet where my mother had 50 toolbars and malware installed

I removed hundreds of toolbars from my mother/grandmother/anyone computer.

I still prefer that to techno-fascism where it's ok for companies to brick my hardware remotely, to lock me out of all my hardware because I have a picture of my kid in a bath, to read all my messages for whatever reason, to extract value from my personal files, pictures, musical tastes, to not allow me to install an app I bought because it have been removed from the store, to not allow me to install an app my friend created, to not allow me to create an app and sell it myself, to not allow me to not do the action ever but just "Later this week", and so on and so on.

This toolbar thing is a wrong excuse. And it was 90% because Windows was shitty.

Most mothers would have easily downloaded and installed crapware embedded with whatever they downloaded, but most mothers aren't doing to go to "Settings > About > Tap 10 times on OS version > Bootloader > Disable Bootloader protection > "Are you sure because your phone will become insecure ?" > Yes > Fucking yes.

And if they still do it to purposefully install malware, I'm sorry to say they are just stupid and I cannot care less about the toolbars.

Re: We should have the ability to run any code we want on hardware we own

#652
post #165

> In this context this would mean having the ability and documentation to build or install alternative operating systems on this hardware It doesn't work. Everything from banks to Netflix and others are slowly edging out anything where they can't fully verify the chain of control to an entity they can have a legal or contractual relationship with. To be clear, this is fundamental, not incidental. You can't run your o…

My parents are getting old and they aren't tech savvy. The missing piece here is that I want my parents to have a computer they can safely do their banking on, without leaving them vulnerable to scams and viruses and the like. I like that they have iphones. Doing internet banking on their phone is safer than doing it on their desktop computer. Why is that? The reason is that the desktop PC security model is deeply fl…

It is the other way around. The security model of mobile devices seriously inhibits innovation and we end up with ever the same crappy apps we don't really need.

I also don't believe more people get scammed on PC compared to mobile platforms. Scammers go where the most naive people congregate.

A sensibly configured Linux system is very secure compared to your mobile device. No security model can really shield against user stupidity. The people would need completely different devices as they simply aren't fit to use a computer. My parents are the same, but I won't accept a bad compromise of an OS just because they essentially need other devices.

At some point a user will be asked to allow execution of code they got through some fishy mail. There is no defense against that other than for the user sticking to books.

Re: We should have the ability to run any code we want on hardware we own

#653

I think the conversation needs to change from "can't run software of our choice" to "can't participate in society without an apple or google account". I have been living with a de-googled android phone for a number of years, and it is getting harder and harder, while at the same time operating without certain "apps" is becoming more difficult. For example, by bank (abn amro) still allows online banking on desktop via…

Can you make an argument as to how this is different from having to have an account with, say, your ISP?

Re: We should have the ability to run any code we want on hardware we own

#654
post #84

We need both options to coexist: 1. Open, hackable hardware for those who want full control and for driving innovation 2. Locked-down, managed devices for vulnerable users who benefit from protection This concept of "I should run any code on hardware I own" is completely wrong as a universal principle. Yes, we absolutely should be able to run any code we want on open hardware we own - that option must exist. But we s…

Agreed and I think we're already here. Hardware is so cheap now its trivial to have both multiple streaming devices and multiple open computer platforms. There are advantages to both and no way to compromise to have one device for everything.

Re: We should have the ability to run any code we want on hardware we own

#655

I think the conversation needs to change from "can't run software of our choice" to "can't participate in society without an apple or google account". I have been living with a de-googled android phone for a number of years, and it is getting harder and harder, while at the same time operating without certain "apps" is becoming more difficult. For example, by bank (abn amro) still allows online banking on desktop via…

> I called their support line for a lost card, and had to go through to second level support because I didn't have the app.

What’s the alternative? The bank sending out a debit card to anyone who calls up and says “I’m @kristov, trust me…”

You were not able to served by the standard path, because you couldn’t authenticate yourself via the standard mechanism. You still got service by an alternate path. No different from opting out of the airport scanner; it takes longer and is a little less convenient, but you still get service.

Re: We should have the ability to run any code we want on hardware we own

#656
post #574

Earlier quoted context omitted.

My parents are getting old and they aren't tech savvy. The missing piece here is that I want my parents to have a computer they can safely do their banking on, without leaving them vulnerable to scams and viruses and the like. I like that they have iphones. Doing internet banking on their phone is safer than doing it on their desktop computer. Why is that? The reason is that the desktop PC security model is deeply fl…

Good point. The current security model of desktop OSs sucks. I was recently reminded of this by an issue at work. I'm used to devs having admin rights on their laptops, but here they closed that down: you have to request admin rights for a specific purpose, and then you get them for a week. I recently requested those rights again because I needed to install something new for a PoC I was working on, and that wasn't al…

There is software that does exactly that. You install a software kiosk were users can pick from and users don't get admin rights.

Won't satisfy developers for long though because it cannot work.

The problem is that mobile OS security systems isn't fit to develop anything but shit. It is simply no solution for desktop.

Re: We should have the ability to run any code we want on hardware we own

#657

Earlier quoted context omitted.

My parents are getting old and they aren't tech savvy. The missing piece here is that I want my parents to have a computer they can safely do their banking on, without leaving them vulnerable to scams and viruses and the like. I like that they have iphones. Doing internet banking on their phone is safer than doing it on their desktop computer. Why is that? The reason is that the desktop PC security model is deeply fl…

It is the other way around. The security model of mobile devices seriously inhibits innovation and we end up with ever the same crappy apps we don't really need. I also don't believe more people get scammed on PC compared to mobile platforms. Scammers go where the most naive people congregate. A sensibly configured Linux system is very secure compared to your mobile device. No security model can really shield against…

>A sensibly configured [desktop, i.e., not just a headless server] Linux system is very secure compared to your mobile device.

That is not true. It is understandable that you believe it because it gets repeated a lot, but those repeaters are doing what you are, namely repeating what they heard (and sometimes what they want to be true) without sufficient actual knowledge of what they are talking about.

Re: We should have the ability to run any code we want on hardware we own

#658
post #194

It's a matter of ownership vs. licensing. You own the hardware you buy, but you license the software. I agree with the author that as long as you use that software, you should be subject to the constraints of the license. The key is that if you choose not to run that software, your hardware should not be constrained. You own the hardware, it's a tangible thing that is your property. Boils down to a consumer rights is…

That's an oddly legalistic line to draw. What if they start licensing the hardware too? Surely if we care about users being respected by technology, the line between software and hardware or between ownership and licensing is immaterial. These are all excuses to deny users the opportunity to do things they should be entitled to do, like installing arbitrary applications.

Well, the line is drawn by the fact that hardware and software have intrinsic differences. It sounds like we're on the same page about hardware -- with the software, should we not be bound by licenses in client/server services (phones, consoles)? You are using someone else's service with others, for some collective benefit like playing a game, and being bound to constraints on that software doesn't seem that offensive. Modified clients can piss in the pool for others using the services and affect the network's quality.

Again, if you want to run purely OSS software with permissive licenses, that should be your prerogative. But you might miss out on the Play store. If you want to mess with Valve anti-cheat, you can't connect to Steam games online. Etc. I think these companies do have a right to dictate software requirements for client code accessing their servers.

But, you should be able to wipe those clients if you don't care about them and play tux racer on Arch.

Re: We should have the ability to run any code we want on hardware we own

#659

I think the conversation needs to change from "can't run software of our choice" to "can't participate in society without an apple or google account". I have been living with a de-googled android phone for a number of years, and it is getting harder and harder, while at the same time operating without certain "apps" is becoming more difficult. For example, by bank (abn amro) still allows online banking on desktop via…

[dead]

Re: We should have the ability to run any code we want on hardware we own

#660

I think the conversation needs to change from "can't run software of our choice" to "can't participate in society without an apple or google account". I have been living with a de-googled android phone for a number of years, and it is getting harder and harder, while at the same time operating without certain "apps" is becoming more difficult. For example, by bank (abn amro) still allows online banking on desktop via…

Can you make an argument as to how this is different from having to have an account with, say, your ISP?

You have many ISPs to choose from. There are not many "Googles" nor "Apples" to choose from.
Post reply on HN