Live data from Hacker News

Pixel phones are sold with bootloader unlocking disabled

fitzsim.org

71–80 of 359 posts

Re: Pixel phones are sold with bootloader unlocking disabled

#71
post #32

Earlier quoted context omitted.

You get to "own your device" after you connect it to the internet once, to make sure it's not pre-provisioned for enterprise use.

So you don't own it when you buy it. At best Google still owns it and they graciously allow you permission to change the bootloader after you submit to their terms of service. Also, better hope their servers are online and reachable, and that you have functional internet.

The best you can do is to consider it as part of the transaction of buying the device. If it fails for whatever reason, return the device.

Re: Pixel phones are sold with bootloader unlocking disabled

#72
I have a much older Google phone, a Verizon sold Pixel 2 which is not unlockable even after connecting to the internet. I got the phone second hand hoping to run LineageOS but I couldn't, so I just left it on my drawer. They really need to put an end to this ewaste generating policy. I should be able to do what I want with my device.

Re: Pixel phones are sold with bootloader unlocking disabled

#73

> connect the device to the Internet before they are allowed to install the operating system they want Phoning home before undertaking such an activity takes away the ownership rights from the customers. They do not actually own these devices even after they have purchased them. The reason is that an important part of their ownership rights, i.e. the freedom to use the software of their choice, has been withheld from…

[deleted]

Re: Pixel phones are sold with bootloader unlocking disabled

#74

Earlier quoted context omitted.

This is correct, people generally don't get to own a device provided by their employer. Not allowing the bootloader to be unlocked on company-owned devices seems like a very desirable feature.

Not allowing a bootloader to be unlocked on a company-owned device does sound like a desirable feature, but only for company-owned devices. Applying that setup to all phones assumes that the default phone is a company-owned device and is subject to external control.

It assumes that company owned and managed phones are more common than people who want to unlock the bootloader. I know this isn't ideal, but that's the correct assumption to make.

Re: Pixel phones are sold with bootloader unlocking disabled

#75
post #32

Earlier quoted context omitted.

You get to "own your device" after you connect it to the internet once, to make sure it's not pre-provisioned for enterprise use.

If the servers are running. If the servers deign to give permission to own the device you purchased. If they correctly recognize that this device is owned by the user. After I've purchased the device, the seller has no right to withhold ownership, and the existence of enterprise devices doesn't change that in the slightest.

If the process doesn't work then return it as defective.

Transfer of control isn't happening exactly at sale time but a few hours later isn't a big deal.

Though of course that depends on it staying unlocked.

Re: Pixel phones are sold with bootloader unlocking disabled

#76

Earlier quoted context omitted.

So I’m guessing with this you’d use an alternative store like F-Droid instead of the Play Store? (Pardon my ignorance, I’m an iOS dev and have been for a decade; I don’t really know the Android landscape.)

No, not necessarily. The project officially develops secure, private access to the Play Store and its apps. My interpretation is that the project's authors prefer users to use the secure Play Store implementation over alternatives like Aurora, even if Aurora works fine. https://grapheneos.org/faq#google-services

This is also a big part of the special sauce that GrapheneOS offers. I haven't seen the Play Services sandboxing built into any other OS.

Re: Pixel phones are sold with bootloader unlocking disabled

#77

Earlier quoted context omitted.

Pixel's are locked down a very tiny bit , and I don't think this is some kind of dystopian over-reach with security as an excuse. For all the security listed in this thread the whole "I must connect to the internet once" problem is a very fair tradeoff from the user's perspective.

> Pixel's are locked down a very tiny bit Other people might instead say "Pixels are locked down." > I don't think this is some kind of dystopian over-reach with security as an excuse. Why? > "I must connect to the internet once" problem is a very fair tradeoff from the user's perspective. Speak for yourself.

> Speak for yourself.

I am, that's what a "comment" is.

And the second (I dont think...) follows from the first (very tiny bit). I'd just be repeating myself.

This is opinion-based. We just disagree, that's fine.

Re: Pixel phones are sold with bootloader unlocking disabled

#78

> Request to Google: ungrey the “OEM unlocking” toggle in the factory, before shipping store.google.com devices to customers. Do not make your customers connect the device to the Internet before they are allowed to install the operating system they want. That won't happen. I can think of two big reasons off the top of my head: 1. Supply-chain attacks, someone gets a hold of the phone before it gets to you and unlocks…

> someone gets a hold of the phone before it gets to you and unlocks the bootloader and then proceeds to modify or install another OS

Doesn't the splash screen clearly show some scary warning when the phone was unkocked?

> very likely they want to have it phone back and send a record that it was unlocked so they can deny warranty in cases where user damaged the device through software

So burn an e-fuse like Samsung does.

Re: Pixel phones are sold with bootloader unlocking disabled

#79

> connect the device to the Internet before they are allowed to install the operating system they want Phoning home before undertaking such an activity takes away the ownership rights from the customers. They do not actually own these devices even after they have purchased them. The reason is that an important part of their ownership rights, i.e. the freedom to use the software of their choice, has been withheld from…

As a result, it seems like the only way to have a chance at unlocking such Pixel phones, which have been made by a US company and purchased from a US carrier, is to pay someone in China and hope for the best. It has gotten that far.

That reminds me of the right-to-repair article about patched John Deere firmware created by Ukrainian hackers.

It wouldn't surprise me that China has the same skills. I remember coming across a lot of products made to unlock/unbrick Apple's products too, although that was many years ago and I'm not sure if they've gotten through Apple's security for the newer models yet --- and it wouldn't surprise me if they knew but won't easily disclose.

Re: Pixel phones are sold with bootloader unlocking disabled

#80
post #63

Earlier quoted context omitted.

Pixel's are locked down a very tiny bit , and I don't think this is some kind of dystopian over-reach with security as an excuse. For all the security listed in this thread the whole "I must connect to the internet once" problem is a very fair tradeoff from the user's perspective.

The internet is not a thing you connect to, what you must actually do is register your intent to disable the bootloader with an adversarially controlled server, and that server must respond with a yes.

If the root comment is to be believed, this (connecting via the internet to Google's servers), is required to provide additional security. I'm just taking that as true and deciding that connecting to the provider of my phone's hardware and software _once_ as a purchaser of their hardware, is fine for me. I also imagine it's not too burdensome for others.

Scenarios in which that's not possible are hypothetical (disaster, totalitarian takeover, alien invasion, sudden policy change), and I'm fine calculating that into the risk calculus and deciding that, yep I don't mind driving home and unlocking it the same day I bought it and praying nothing changes in their policy during the drive.

That's basically what I did. We can disagree on this, but it has worked out OK so far.

Post reply on HN