Live data from Hacker News

Pixel phones are sold with bootloader unlocking disabled

fitzsim.org

91–100 of 359 posts

Re: Pixel phones are sold with bootloader unlocking disabled

#91

> connect the device to the Internet before they are allowed to install the operating system they want Phoning home before undertaking such an activity takes away the ownership rights from the customers. They do not actually own these devices even after they have purchased them. The reason is that an important part of their ownership rights, i.e. the freedom to use the software of their choice, has been withheld from…

So google is going through all this effort and some guy in China will just bypass the bootloader lock for $30. There is absolutely no way that the intelligence agencies don't have this same capability, which makes all of this security posturing utterly pointless, other than to prevent regular users from owning their devices.

That's exactly the purpose of this measure - to prevent consumers from fully owning their device. Presumably the carriers are selling you the device at some discount for longer term loyalty (through constraining the phone). This is not a security measure and government agencies being able to bypass it seems irrelevant.

Re: Pixel phones are sold with bootloader unlocking disabled

#93
not only is the title misleading and click-baity (connecting to wifi is the only pre-requisite) the format of the blog doesn't format correctly (text and media is cut off on the right) . maybe spend less time writing misleading articles and more time fixing its viewability?

Re: Pixel phones are sold with bootloader unlocking disabled

#95

Earlier quoted context omitted.

So google is going through all this effort and some guy in China will just bypass the bootloader lock for $30. There is absolutely no way that the intelligence agencies don't have this same capability, which makes all of this security posturing utterly pointless, other than to prevent regular users from owning their devices.

That's exactly the purpose of this measure - to prevent consumers from fully owning their device. Presumably the carriers are selling you the device at some discount for longer term loyalty (through constraining the phone). This is not a security measure and government agencies being able to bypass it seems irrelevant.

You are confusing Verizon's motives with Google's motives. Verizon disabling the bootloader on phones that users are still paying off, or bought at a discount together with special terms of condition, is something that might be defensible.

Google however made it so that any Pixel phone bought anywhere, even by customers who pay 100% of the price themselves with no carrier involved are not actually owned by those users until they connect it to the internet and Google blesses the device.

Re: Pixel phones are sold with bootloader unlocking disabled

#96
post #48

Earlier quoted context omitted.

Xiaomi does the same (or at least did until my latest phone change i.e. around 3 years ago). You must unlock the bootloader before being able to install a custom recovery image such as TWRP, which itself is used to install custom ROMs. This unlock involves: creating a user account in the Xiaomi services website, logging into that account from your phone's system, then having the phone logged in for at least 7 days ,…

Xiaomi heavily subsidizes their phones. The idea is that they make it back with people using their apps.

Yep. All their stock apps, including those that have no business having any kind of network access as part of their functionality, come with a privacy policy, show it to you in a modal on first launch, and quit if you decline it. The calculator app has a privacy policy, so does the clock, the media gallery, the file manager, and the local music player. I was also told that there are actual ads sprinkled throughout the system.

I'm highly doubtful that it's possible to sell a phone for the equivalent of $100 at a profit.

Re: Pixel phones are sold with bootloader unlocking disabled

#98

Earlier quoted context omitted.

> So I’m guessing with this you’d use an alternative store like F-Droid instead of the Play Store? Not necessarily, but that's the best way to do it. Between apps from F-Droid and a browser, you don't need any apps from the play store. Your bank doesn't have an app on F-Droid you might say? Well that's what the browser is for.

Erm, why would you ever want an app for your bank on your mobile phone ? So that when you get mugged, it can turn into a kidnapping? I use some bank apps because they're quicker than the websites. But I do this with a cheap Nexus 7 tablet that stays at home with a label saying "full take" stuck to the top to remind me to not trust it with any sensitive information. Segregating apps onto different devices is the way t…

You can also just have multiple banks and then choose one of them to be the account where you put your 'working money'; i.e. an amount that you can afford to lose. This way you still get the convenience of having a bank app (quick payments, transfers & stuff), but not the risk of losing it all.

Re: Pixel phones are sold with bootloader unlocking disabled

#100

Earlier quoted context omitted.

> So I’m guessing with this you’d use an alternative store like F-Droid instead of the Play Store? Not necessarily, but that's the best way to do it. Between apps from F-Droid and a browser, you don't need any apps from the play store. Your bank doesn't have an app on F-Droid you might say? Well that's what the browser is for.

Erm, why would you ever want an app for your bank on your mobile phone ? So that when you get mugged, it can turn into a kidnapping? I use some bank apps because they're quicker than the websites. But I do this with a cheap Nexus 7 tablet that stays at home with a label saying "full take" stuck to the top to remind me to not trust it with any sensitive information. Segregating apps onto different devices is the way t…

> Erm, why would you ever want an app for your bank on your mobile phone?

To easily check balances and make transfers wherever I am. This is possible without the app, but the app makes it easier/quicker than the mobile site in most cases.

> So that when you get mugged, it can turn into a kidnapping?

How do you suggest a mugger to find out whether such an app is even installed, let alone do anything about it, in this day and age of full-device encryption being the default? Even assuming a mugger somehow has access to the nation-state-level compute resources and exploit tools necessary to gain access to anything on my phone, by the time the mugger has finished using said tools and compute resources, I'll have already changed my passwords and invalidated existing login sessions.

Also, kidnapping involves considerably more effort and risk than mugging, so this is a weird argument in general. The vast majority of people with both smartphones and bank accounts almost certainly have banking apps installed on their phones, and I know of precisely zero cases of muggers deciding "oh you have a banking app? lemme go find my windowless van and kidnap you, drawing considerably more attention to me and giving you considerably more reason to violently defend yourself instead of cooperating; surely nothing will backfire from that, no siree!".

Muggers quite frankly don't give a flying fuck about the apps on your phone. They want your cash and/or whatever they can quickly fence.

> Segregating apps onto different devices is the way to go to protect yourself from corporate malware.

Having firmware that gives you fine-grained app permissions that you can freely grant/revoke also accomplishes this. If apps on the Play Store are subverting that, then banking apps are probably the least of your worries.

Post reply on HN