Live data from Hacker News

We should have the ability to run any code we want on hardware we own

hugotunius.se

751–760 of 1001 posts

Re: We should have the ability to run any code we want on hardware we own

#751
post #622

Earlier quoted context omitted.

You provided an alterative solution yourself. Make protection harder to disable, so non-tech savvy users can't disable it easily, always inform them of the consequences of disabling it and make it that it's only needed in exceptional cases (there a lot of room for improvement here). If they want to climb over the protection fence, they should be able to do it as they clearly WANT to do it. Why should you have control…

> always inform them of the consequences This would be about as useful as telling the cat why he can’t go out right now. The words would not be understood, as they won’t be by probably 90% of humanity. > If they want to… They don’t. Categorically. The only reason they would try is because they are being scammed with offers of getting something or cajolement entreating them to allow it. > Why should you have control w…

>They don’t. Categorically.

They do. Categorically.

> The only reason they would try is because they are being scammed with offers of getting something or cajolement entreating them to allow it.

F-Droid installed German university made QR app. Messaging app that government does not like because it disallows spying on citizens.

> The current status quo serves them and many millions of other people very well

Said you.

So well that only time I had to deal with malware and scam in one was when my parent installed QR App from Google Play and got AD served to them to confirm mobile payment.

REALLY * WELL.

> to them

To you.

> it only represents freedom to be exploited.

There is no reason that verification cannot happen in SSL style - and no layperson will create CA certificate, believe me.

> be very cautious when

Because of that Google decided that it will first introduce it in Brazil, Indonesia, Singapore, and Thailand... wait a moment I think I seen that list somewhere...

https://en.wikipedia.org/wiki/Censorship_in_Brazil https://en.wikipedia.org/wiki/Censorship_in_Thailand https://en.wikipedia.org/wiki/Censorship_in_Singapore https://en.wikipedia.org/wiki/Censorship_in_Indonesia

This was created so governments can censor any application that allow people to communicate. To limit freedom of expression. You are made into useful idiot.

The fact alone that the 'test subjects' are people living in censorship-like countries should tell you enough.

> Experts in other fields determine the extent

There is exception here - no one determines who can speak - but now Google can do so by revoking application certificate.

> rip that away

You are ripping that away - all of current democratic infrastructure now requires computer communication.

You are removing user's ability to install software, You are giving governments way to censor and spy on citizen on massive scale. You want change. You should be careful not us.

> all the time.

Not all the time - only when there is reasonable ground. You do not provide one - if you think your 'reason' is good then we should ban all communications because someone may send malware in one of links in them.

If you want apple go apple.

> Me? I’m not asking for control.

Yes you do - you asking for control to be given to governments in long run, saying otherwise is disingenuous.

Re: We should have the ability to run any code we want on hardware we own

#752

So many people paraphrasing Stallman and GPL, and so few realizing that without legal enforcement these problems will keep happening over and over again. Yet there is more BSD and MIT code than ever. Android is full of open source stuff. GPL3 would have prevented this. We've all been bamboozled and we are starting to realize it. I wonder if any project will start switching license. Unlikely, but one can dream.

Switching licenses on a FOSS project without copyright assignment is almost impossible, unless the license already allows for it. See Linux kernel GPLv3 relicensing discussions of the latter aughts.

Re: We should have the ability to run any code we want on hardware we own

#753

I think the conversation needs to change from "can't run software of our choice" to "can't participate in society without an apple or google account". I have been living with a de-googled android phone for a number of years, and it is getting harder and harder, while at the same time operating without certain "apps" is becoming more difficult. For example, by bank (abn amro) still allows online banking on desktop via…

This.

I really liked Huawei phones and I wanted to keep using them after the US forced them to part with Google, but after doing some research and finding out some of the everyday things I wouldn't be able to do due to not having the Google Play Services (I'm not even talking about not having a Google account!), I just gave up.

Re: We should have the ability to run any code we want on hardware we own

#754

Earlier quoted context omitted.

That is a great analogy. There are countries where a police can throw you into a lifetime jail with zero option for justice unless you are a famous person from a well known western country. Those countries are North Korea, Iran, Russia, Google and Apple.

Well the US can do it with CBP/ICE, but not for life. I was placed in a jail without being arrested or being accused of a crime and they were very clear at all times I was not even arrested, nor did a federal criminal history search show any record of arrest. No access to lawyer either. US Citizen. Contacted lawyers, all informed me they'd given up trying to sue for these things because it's hopeless.

Founding fathers rolling in their graves.

Re: We should have the ability to run any code we want on hardware we own

#755
The editorializing of this article title changes the meaning, please restore it.

But to answer the claim, no, only software that you own or are allowed by the software owner to run, is obviously what should be allowed. And clearly illegal and harmful software should not be allowed at all. It's a no-brainer.

Re: We should have the ability to run any code we want on hardware we own

#756
post #283

Earlier quoted context omitted.

Your parents are more likely to be a victim of a phone call scam than malware, even on PC. There is also no guarantee that malware will not slip through cracks of official stores or signatures. You can also choose to do your banking at the physical branch. We already had "best of both worlds", especially on mobile OSes - granular permissions per-app were quite good, and on Android until few years ago root was widely…

> Your parents are more likely to be a victim of a phone call scam than malware, even on PC. There is also no guarantee that malware will not slip through cracks of official stores or signatures. So what? The lack of perfect security is a terrible argument against better security. For example, lockpicks exist. Is that a reason to stop locking your house? Our TLS ciphers might eventually be broken. Should we throw awa…

I don't think Google play integrity and only allowing installing blessed apps on blessed devices is more secure. I just don't.

Google blesses malware all the time because otherwise they would go bankrupt. They're an ad company, not a security company.

Re: We should have the ability to run any code we want on hardware we own

#757
post #671

Earlier quoted context omitted.

> I called their support line for a lost card, and had to go through to second level support because I didn't have the app. What’s the alternative? The bank sending out a debit card to anyone who calls up and says “I’m @kristov, trust me…” You were not able to served by the standard path, because you couldn’t authenticate yourself via the standard mechanism. You still got service by an alternate path. No different fr…

Off the top of my head: going in-person to the bank, email, phone call or sms to a number that you previously informed to the bank (say when opening the account), otp a la authy or aegis. None of these require you to be on google or apple's walled garden.

Nor did GGP's approach require them to be in google or apple's walled garden.

That's exactly the point: there's an easy and common method that many people choose to use, but there is still a perfectly working method for people who choose to not use apple or google.

Re: We should have the ability to run any code we want on hardware we own

#758

I think the conversation needs to change from "can't run software of our choice" to "can't participate in society without an apple or google account". I have been living with a de-googled android phone for a number of years, and it is getting harder and harder, while at the same time operating without certain "apps" is becoming more difficult. For example, by bank (abn amro) still allows online banking on desktop via…

Remember those naive days when everyone was scared about Big Government running their lives? Remember how the Free Market™, unimpeded by government interference, was going to ensure our personal freedoms were never compromised?

Good times.

Re: We should have the ability to run any code we want on hardware we own

#759

Earlier quoted context omitted.

> I called their support line for a lost card, and had to go through to second level support because I didn't have the app. What’s the alternative? The bank sending out a debit card to anyone who calls up and says “I’m @kristov, trust me…” You were not able to served by the standard path, because you couldn’t authenticate yourself via the standard mechanism. You still got service by an alternate path. No different fr…

> opting out of the airport scanner slightly OT, but where can you opt out of the scanner? Every time I've tried they told me I won't be allowed through security unless I subject myself to the scanner, despite me protesting that they can search me however else they please.

Anywhere that US TSA runs the AIT scanners, you can opt out of them*.

That is domestic US airports plus airports like Toronto and Dublin where you, for practical purposes, clear into the US on foreign soil and land in the US as a domestic flight.

* - I think this only doesn't apply if your boarding pass got tagged with the dreaded "SSSS" enhanced screening tag, but that's a fairly rare corner case for most passengers.

Re: We should have the ability to run any code we want on hardware we own

#760

Earlier quoted context omitted.

> If you want to run an alternative operating system, you got to learn how it works. The typical user doesn't know how Windows works, and they can run that. These days, users can run a friendly GNU/Linux distribution not knowing how it works. So, disagree with you here.

> The typical user doesn't know how Windows works, and they can run that. That is because Windows for the most part manages itself and there are enough IT professionals, repairs shops and other third support options (including someone that is good with computers that lives down the road) where people can problems sorted. This is not the case with Linux. > These days, users can run a friendly GNU/Linux distribution no…

> That is because Windows for the most part manages itself

Windows is the least "manage itself" OS out of all OS available today. It needs pretty constant maintenance and esoteric enchantments to keep trucking.

Post reply on HN