7 ms·
What about the right to use our electronics? Google has been silently pushing their "SafetyNet" APIs into Android, including an "attestation" API[1] that dynami
by amckinlay 9y ago
What about the right to use our electronics? Google has been silently pushing their "SafetyNet" APIs into Android, including an "attestation" API[1] that dynamically fetches and runs an opaque binary program[2] served and signed by Google that collects whatever data they deem necessary to verify the "integrity" of a device.
Devices that are rooted will not fail to attest via the API. Devices where the user has chosen to install a custom ROM will fail to attest (even with a locked bootloader and no root). Apps from Google Play can use these APIs to decide whether to work on a user's device.
This is macOS SIP taken to a different level. You can't watch Netflix and whatever other app decides to use these APIs unless Google has complete control over your device, including the ability to remotely collect and transmit opaque and arbitrary data at any time. This is a dishonest attempt to disguise a draconian DRM scheme as pro-user, pro-safety, anti-virus/rootkit. We're at the point where you don't even own your own filesystem anymore on a Linux device. I think this is a step beyond traditional DRM, including traditional hardware content protection.
[1] https://developer.android.com/training/safetynet/attestation.html https://developer.android.com/training/safetynet/attestation...
[2] https://koz.io/inside-safetynet/ https://koz.io/inside-safetynet/
- farhanhubble 9y agoNot only mobiles, PC OEMs are going to extreme lengths to tie down the users into using whatever crap the manufacturer installs by default.
- sspiff 9y agoCare to explain what you mean by that? As far as I can tell, vendors ship crapware as software installed on Windows, and you can always remove it by reinstalling Windows or often just uninstalling the bundled software. Do they ever go beyond that?
- inapis 9y agoLenovo used the UEFI/BIOS tables to load crapware back into a fresh retail user-installed windows setup. The bios table was named Window Platform Binary Table
- mcv 9y agoLenovo? That sucks. I was considering a Thinkpad to get out of Apple's stranglehold. I'd put Linux on it of course, but I'm still not happy buying from a company that pulls crap like that.
- exodust 9y agoLenovo don't do this any more, and offers a way to remove the LSE: https://support.lenovo.com/au/en/product_security/lse_bios_notebook https://support.lenovo.com/au/en/product_security/lse_bios_n... No excuses of course, and Microsoft can share the blame too.
- lorenzhs 9y agoI’m not defending the shit Lenovo‘s been pulling these last few years, but it’s worth noting that none of it (neither the Superfish fiasco nor this) affected ThinkPads. Apparently their consumer line and ThinkPads are run quite separately. I hope that keeps them from messing up the ThinkPads...
- wiz21c 9y agoI wonder if russian or chinese or indian computers have that kind of annoying software...
- slrz 9y agoThat mechanism only works through cooperation of the OS installation process. It's actually the OS that asks the device whether there is any crapware it is supposed to ingest and then goes on to ingest it. As long as you consent to that, everything is fine I guess. The software is doing its job as an agent of its users.
- eadmund 9y agoYup — and this is the same Google who have conspired to prevent you from installing your own SSL certs, so that you can see what data that module is sending to them.
- chrisper 9y agoIf you have root, can you not install SSL certificates?
- dasil003 9y agoI am totally ignorant of Android, but they could be pinning, and do so in such a way that it fails silently without sending data. As root you could probably detect this but you'd really have to know what you were looking for.
- userbinator 9y agoAs root you could probably detect this but you'd really have to know what you were looking for. I can think of two relatively easy and probably-not-secure (you were asking for freedom, not security...) ways to not only detect but also bypass this: - Hook certificate verification APIs to always return true. - Scan for certificates embedded in the binary and overwrite them dynamically. This will work if the app decides to use its own crypto but standard certificate formats.
- zeveb 9y agoAnd if you have root, then your device fails to attest. Who owns your device: Google or you? This is about control.
- amckinlay 9y agoYou don't have root, that was a typo, sorry. I cannot go back and edit the post.
- kuschku 9y agoSpecifically: User-installed TLS certificates are now in a separate keystore from system CAs, users can not disable system CAs, and apps can choose which keystore to trust, but the default is that user CAs are not trusted unless apps explicitly opt-in. This is extremely user-hostile.
- JoshuaRLi 9y agoThis makes me sad...
- burntrelish1273 9y agoDRM is a corporate infection that has an opportunity to advertise to you, monitor your activity and gather intelligence on you.
- a_t48 9y agoOn the one hand, this is kind of sad for device owners. On the other, it sounds really nice if you're making a game on Android with clientside aspects and want to stop cheaters.
- Kenji 9y agoI have a rooted phone. I used to play Pokemon Go. I loved it. One day, they just decided to lock out all rooted users. Good bye Pokemon Go. There would have been ways to circumvent this (i.e. by unrooting or hiding my root) but it wasn't worth the trouble. It made me sad.
- rcxdude 9y agoIt's proven pretty ineffective at that. Ingress and pokemon go use it to try to avoid cheating through spoofing your location and they're both still riddled with such cheaters.
- bubblethink 9y agoThe problem with android on the whole is that it got good enough, quick enough that it prevented any meaningfully open and consumer friendly alternatives to emerge. Safety net is a part of the play services, which on the whole is opaque and binary. So not much is new there.
- taneq 9y agoAlso it wore the skin of a free, open platform pretty well for quite a long while. It was only after it got popular that Google started subverting that and turning it into the creature it currently is.
- cyphar 9y agoYet another reason why we shouldn't accept being sold such proprietary garbage. SafetyNet is another attempt at creating a system similar to Treacherous Boot[1] -- similar to what people feared that UEFI's "Secure Boot" would become (luckily we avoided that fate on x86 systems, but all of the Windows RT devices are by definition "Treacherous Boot"). I would personally _love_ if we could get proprietary software to become illegal (or for there to be some sort of disincentive such as taxing proprietary software, or enforcing and extending warranties on proprietary software). But large proprietary software companies hold such sway in politics that hoping for that doesn't really help. It would be a much better idea to simply stop buying their crap, and helping others around you "break the shackles" (as it were). Digital Restrictions Management is something that I always mention when people talk about Netflix or other such streaming services -- because once you explain the issues with those kinds of services I find that most people are at least intrigued by alternatives (which usually have features that the DRM systems don't, because DRM has always been clunky as they're trying to accomplish something that is effectively not possible). [1]: http://www.fsf.org/campaigns/drm.html http://www.fsf.org/campaigns/drm.html
- agmcleod 9y agoI feel like taxing proprietary software, or making it illegal would be awful. Many companies big to small run businesses off of proprietary software. You have the big players like Microsoft, Apple, Amazon, and Facebook. Not sure how some of these compare in size, but you also have Github, Shopify, Squarespace, Reddit, Atlassian, Basecamp, robo advisor companies. Then you consider not purely based online companies like banks or retail stores that sell their products online, or give you the ability to trade ETFs. Some of those they could use open stuff instead, as they make money off of trades. I do agree that making DRM is a losing battle, and they are transferring that cost to legitimate customers. Really though I don't have much other options for streaming. Amazon prime has the same setup, and CraveTV probably does too. Though Crave doesn't have much for content that I'm interested in.
- cyphar 9y ago> I feel like taxing proprietary software, or making it illegal would be awful. Maybe taxing on the distribution of proprietary software would be more palatable? After all, software that is written can only become proprietary if you distribute it to other people under a non-free license. I personally think the warranty idea is much softer on companies (while still giving some more protection for end-users). I don't think banks should be taxed for having propreitary systems. I do have a problem with SaaS[1] companies, and companies which make money of selling software which is proprietary -- because they are actively creating a monopoly on the expertise in and ability to support their particular software (known more politely as vendor lock-in). Not to mention that proprietary software developers incredibly often mistreat their users through a variety of schemes. [1]: https://www.gnu.org/philosophy/who-does-that-server-really-serve.en.html https://www.gnu.org/philosophy/who-does-that-server-really-s...
- Yetanfou 9y agoWhen you use such a device (with a 'custom' distribution) you need to go 'all the way' with regard to shunning software which depends on this 'verification'. This is the most logical course to take anyway as the assumption is that you want to use a device which only runs such software you know about, not things pushed by vendors with their own agendas. So, sad as it might be for some, the likes of Netflix (et al) will not run on devices which refuse to listen to their master's voice (i.e. to Google, Netflix, etc) but only do the bidding of the device owner. I have no problems with this as I don't want to use such 'services' anyway. I keep my own digital library, on my own server, using free software. I have no problems foregoing the latest H*llywood 'blockbuster' to keep a semblance of control over what I consider to be my private sphere.
- wiz21c 9y ago>>> I have no problems with this as I don't want to use such 'services' anyway. I keep my own digital library, on my own server, using free software. Fortunately, we can still make that choice. I did the same. But sometimes I feel that we are so much a minority...
- hutzlibu 9y agoWe are. But as long as we still can do the things we want, I do not see it as a problem ... but well, yes, since we have to struggle hard to just controll our devices a bit, because the rest does not care and so they can allmost implement whatever spware they want - it is a problem .
- aabbcc1241 9y agoyou're right logically but kind of wrong socially. let's say your friends are using WhatsApp, or Skype, via proprietary protocol, but you only use open sourced IM, then you are isolated from them.
- dhimes 9y agoNot to mention that the friends won't help stop bad laws from being passed because they don't understand how the laws affect them.
- MichaelMoser123 9y agoThey had a link here about running Linux within a container on Android. Can they control processes in such a container? (they could ban this trick, couldn't they)
- morsch 9y agoSo if I want to keep watching Netflix I'll have to stick with the outdated and severely insecure Android version my manufacturer is shipping? The one where anyone in Bluetooth range has full access to my digital identity? And they're calling this feature SafetyNet?
- yann63 9y agoWar is Peace; Freedom is Slavery; Ignorance is Strength;
- userbinator 9y agoDevices that are rooted will not fail to attest via the API. Will not, as in you can theoretically get it to "say the right answers" if you have root? It seems like the best way to "crack" this protection would be something like virtualisation, where the binary is run in an environment that "looks good" to it. (This also reminds me of a lot of malware, which actively tries to determine if it's being run in a VM or otherwise being analysed.)
- kuschku 9y agoCurrently you can use Magisk to get around this, which roots without changing the filesystem. But Google is moving towards reading hardware fuses, and has been working together with OEMs to use secure enclaves to securely attest the status of the system in the future. By requiring the attestation results to be signed by a key burnt into the CPU, they also prevent virtualisation.
- amckinlay 9y agoAnd yet having a hardware enclave is necessary to secure private keys for device encryption and user privacy. I'm not against, non-network, hardware-based security features. In fact, I think we need them. I would certainly desire a phone where someone can't simply access my private key with a soldering iron and flash programmer. And I wouldn't mind a bootloader that is locked to prevent tampering with the device, as long as I can unlock it, and unlocking it wipes the device or something. I wouldn't mind using Android as intended without root access. But, I want control over the decision. I want to control the OS I run on my device. I want the freedom to increase its lifespan beyond whenever the manufacturer stops provided security updates. I want to have the ability to enable root to inspect my data on my device using my storage, without sacrificing my ability to watch movies on the $600 device I paid for that somehow has a better quality display than my monitor. And also, I want the ability to block ads that gulp down my expensive mobile data so that I can instead pay for a service like Netflix.
- kuschku 9y agoAnd I want the ability to lock the bootloader again, but with my own keys.
- otakucode 9y agoWow, I was not aware of those things and I thank you for bringing them to my attention. It sounds like we had better get busy busting that apart before the exemptions the SCOTUS gave to DMCA 1201 for fair use expire in a couple years.
- JadeNB 9y ago> Devices that are rooted will not fail to attest via the API. That should be "will fail", right? > We're at the point where you don't even own your own filesystem anymore on a Linux device. Is this really true? It seems to be of the form "if you decide to own your file system, then you are not given access to certain proprietary media resources or applications". That's a shame, and I'm not happy about it, but my access to Netflix is a convenience, not a fundamental right.
- amckinlay 9y ago> That should be "will fail", right? Yup. Sorry, typo, I can't edit it now. :( With regard to your second comment, that was one perspective that I do consider. There are still plenty of media sources that do not use device attestation. But the trends are not showing in the right direction. Also, as you say, you could decide that maintaining root is more important than being able to consume movies or whatever other DRMd media on your device, but you are sacrificing some of the main features that were marketed to you during your purchase, while still paying full price. Also, it's not just content-delivery apps that take advantage of the APIs, utility apps like Android Pay require their availability. Multiplayer mobile games are also beginning to implement them to "combat cheating" (correction: preserve the viability of microtransactions, but I'm just a cynic). I think the Android Pay case is a bit more understandable, but still, why not implement it as an optional feature a user can enable? If it is designed to save money from fraud, then why not give users a small financial incentive to enable it? Taking the choice away from the user is the enemy here. Don't forget that the lockdown of software on mobile devices goes beyond these new attestation APIs. For 5+ years, phone manufacturers been shipping bootloaders that cannot be unlocked, devices that cannot be rooted, and firmware/OS that cannot be flashed. There is an attempt to ultimately control all the freedom a user has to install their own software. The technology to prevent user freedom is only going to get better and better, as exploits are covered up and manufacturers become smarter about code signing and secure hardware design. So there is much more to the issue than I think is present at first glance. It affects everything, and it is only getting worse. Forget the closed-source firmware that can be delivered and installed at any time over the air and has unrestricted access to your device's unencrypted RAM... that's been going on forever. But now even Wi-Fi routers are being shipped with locked down bootloaders, killing any chance of upgrading or fixing security issues in your device once a manufacturer decides to stop supporting a device. Guess you'll just have to buy a one in two years. That new AC-2300! 802.11AC is going to be so much faster than that old measly AC-1900. Don't forget the crystal oscillators wear out over time, anyway. /s Sorry to go on such a wild rant, but I'm pissed. I'll go on over to the AMD profits thread, and feel a little bit more optimistic about the future of freedom.