3 ms·
> User-settable keys also compromise the security of the device. Not if a physical modification to the hardware, a set of button presses, a hardware token or
by bobcallme 9y ago
> User-settable keys also compromise the security of the device.
Not if a physical modification to the hardware, a set of button presses, a hardware token or a fuse is needed to set said keys.
> And in general it's risky to introduce stuff like this because the potential for unforeseen security compromises is very high
There is little to no risk if physical interaction with the hardware is required for setting keys. If you have physical access and enough time, all bets are off anyway.
> ...and the upside is very low (the number of people who'd actually take advantage of this is extremely low relative to the number of iPhone users).
There are many people who dream of having the freedom to roll their own firmware on a particular device and it can be done without compromising the security of said device. This was not just about iThing users (who might/not take advantage of this), this was about people spreading FUD about the tivoization part of the GPLv3. Root signing keys don't need to be shared and the only requirement is that the user can take the sources, compile them and then run the result on the target device. As long as the OEM distributing the GPLv3'ed program gives a clear path for running the compiled code on the target device, then it is not a problem.
- natch 9y agoYou and others like you who take this line of argument are either ignorant of, or willfully pretend away, the abusive/spying household member problem.
- frenchy 9y agoA walled garden OS doesn't do much to stop the abusive/spying household member problem. They can just beat you up until your give them your password, or spy on you and catch you entering it.
- mseebach 9y agoBut they can't compromise the device without the victim knowing about it. Not all abusive relationships are violent or even directly coercive like that.
- natch 9y agoIt does plenty to help stop it. So much so that in your attempt to find any toehold to criticize it, your comment had to resort to coming up with scenarios that go outside of the system and rely on human vulnerabilities.
- cyphar 9y agoWhich is why most systems that allow you to change the boot chain or otherwise mutate the chain of trust will clear the storage on the device (such as unlocking the bootloader in Android). And on Chromebooks, you cannot easily (read: without getting a flash programmer and doing it manually) subvert the boot chain and not let the user be aware of it (that's what developer mode is used for -- it shows a scary warning if the measurement and secure boot are disabled). The reason nobody mentions this is because the solution is so trivial there's really no point in repeating it each time.