5 ms·
I think Apple's approach is the only reasonable one for the general population. The technological complexity of any smartphone is far beyond comprehension for m
by andreasley 7y ago
I think Apple's approach is the only reasonable one for the general population. The technological complexity of any smartphone is far beyond comprehension for most people.
I write iOS software for a living, and even with complete access to the source code, I couldn't reasonably evaluate my iPhone's software - let alone the hardware.
The idea that ROMs from questionable sources make your device safer sounds very strange to me.
Basically every electronic device has countless security issues. Some of them are found of which some are published of which most are eventually fixed (by rather large teams of professionals). In that regard, Apple could and should do better.
But the burden of making such a complex device secure simply can't be put on the end user.
While I would welcome deeper access for technically inclined people, I'm not sure that option can really be given by Apple/Google without the risk of becoming a disadvantage for many users.
- thefz 7y ago> The technological complexity of any smartphone is far beyond comprehension for most people. Don't use it then. By shielding the stupid we are creating more stupid.
- 420codebro 7y agoThat’s not your call to make, ace.
- coldtea 7y agoThat idea is stupid in itself. The whole of civilization has been a process of shielding people from having to know stuff. The same way you don't know how to make fire from first principles, fix your car, make a CPU, or whatever... Even someone with a Ph.D in computer hardware is shielded from tons of complexities and never has to know the whole process end to end.
- 9HZZRfNlpR 7y agoBut they are allowed to learn, which Apple doesn't want you to do. They could make it so your mom doesn't get root by accident, but you would still have the right to do so.
- jsjohnst 7y ago> They could make it so your mom doesn't get root by accident, but you would still have the right to do so. How? Serious, genuine question. How can they give you “the right to do so”, but prevent “mom” from accidentally doing so or worse, having someone do it to their phone without them knowing?
- anang 7y agoI don’t think anyone is suggesting something similar to “This app would like to access your camera” but for unmitigated root access. It could even be as involved as getting an official image from apple/google that allows root access. I don’t think a “mom” would accidentally download an image and flash their telephones.
- jsjohnst 7y ago> I don’t think a “mom” would accidentally download an image and flash their telephones. Who says “mom” flashed her phone? How does “mom” know the shady place they took their phone to repair a broken screen didn’t do it? (P.S. many documented cases of this) How does “mom” know their jealous/cheating/whatever spouse/bf/gf/whatever didn’t do it? (P.S. many documented cases of this) How does “mom” know the phone they bought off someone didn’t do this? (P.S. many documented cases of this) How does “mom” know their kid didn’t do this so they could install stolen games? (P.S. many documented cases of this) The list goes on and on.
- anang 7y agoThese concerns all apply to existing jail breaking methods. An official image would be much easier to make obvious that it’s not the same as the non-rooted image. In order for any of those threats to work it would require physical access and access to passwords and accounts (for example reconnecting to cloud services, restoring backups or even just unlocking the phone to perform a flash). At that point I don’t think it’s having or not having root access that is the issue.
- r3bl 7y ago> The idea that ROMs from questionable sources make your device safer sounds very strange to me. It's about owning your hardware, not safety. A person that's willing to go through the hassle knows the consequences of such actions and how to deal with them. Do "normal people" need to do that? Absolutely not. Should it be easy to do that? Absolutely not. But for those of us that really want to own our hardware, there should be a way of doing so without relying on exploits.
- andreasley 7y agoI totally agree, but I don't have any good ideas on how to implement that. I'm not even sure if such a barrier should be technological or legal.
- r3bl 7y agoYeah, pointing to the problem is quite easier than figuring out a solution. As far as I'm concerned, I actually read the popups and having to click okay about five or six times in a row would make me second-guess my decision. Would that work for everyone? Most of the people? Some of the people? I don't know that answer. > I'm not even sure if such a barrier should be technological or legal. My answer would be both. I highly doubt it's in hardware manufacturer's interest to figure out a technological solution, but if there's some legal incentive for them to at least try, they'll figure out a technological solution.
- lern_too_spel 7y agoAndroid's option of connecting the device to a computer over USB, running a program on the computer, logging into the device, seeing a scary warning and wiping the device seems to work well. I don't think I've heard of a large number of people being tricked into unlocking their bootloader — at worst, a handful of script kiddies might have been tricked.
- gpvos 7y agoWell, they didn't say the ROMs made their device safer, just that they gave them some semblance of control.
- dessant 7y agoI think locking down a system by default, but offering a way to gain elevated priviledges, while educating and properly warning users before certain actions is better than taking away everyone's control over their own devices, and therefore restricting their freedom.
- athenot 7y agoThe problem with that approach is $popular_social_media app comes along and coaxes users to relax said privileges "because reasons" and before long there's a signigficant proportion of users who altered the security model of their device without understanding what is going on.
- dessant 7y agoPersonal freedoms have always had risks, but is it really warranted to take them away in this case and not offer a way to get them back in any shape or form? Looking at recent Samsung devices, is Google Services Framework really that integral to the security of my device that I must be forbidden from disabling that package? Isn't there an alternative way to achieve a comparable level of security, but without slurping up my personal data? The consequence of security does not have to be a complete loss of control, nor the inability to prevent in a practical way the collection of our personal data. Not to mention the whole security argument falls apart when perfectly fine Android devices are left without security updates 2-3 years after purchase.
- traviscj 7y agoI think there could be an argument that the personal freedom you mention, when risks are realized, can degrade the experience of the world at large. Lazy example: a botnet running on many machines compromised as described above sending spam email to innocents. I’m still on the fence about whether that justifies their protocols. I think I actually lean toward “no”, but I’ve also lately become keenly aware of the difficulty of even simple things like keeping everything up to date, and my lack of real insight into what those updates include. If I’m effectively trusting them anyway, might as well trust them to get it to me ASAP, right? I’m also enough of a realist to assume there’s a Fight Club style “A times B times C > X” reputational/financial risk logic going on here. If there’s few enough of the devices out there, it’s probably cheaper to apologize (legally, as in settle).
- solarkraft 7y ago> even with complete access to the source code, I couldn't reasonably evaluate my iPhone's software - let alone the hardware That's not the point. The point is that the community will be able to do it and auditors' lives will be much easier, which benefits everyone because it vastly increases the likelihood of an issue being found. > The idea that ROMs from questionable sources make your device safer sounds very strange to me. On Android by default most vendors ship a lot of bloatware and have demonstrated almost infinite incompetence or malice of both. While the developers "custom ROMs from questionable sources" (XDA forum threads) may not be experts in their fields at all and are quite likely to misconfigure the software possible creating some new holes, at least those images are compiled from open sources and are not the terrible manufacturer OS (I wouldn't onlike bank on stock Xiaomi software).
- lloeki 7y ago> The idea that ROMs from questionable sources make your device safer sounds very strange to me. The first step on Android is usually to unlock the device boot loader in order to flash a recovery that will allow to erase partitions and install a tarball of the system. I saw no tutorial suggesting to re-lock the device boot and I bet people rarely do it. This means anyone can take the device, boot it into recovery, plug it into USB and throw some adb/fastboot commands to do anything they want. Device encryption becomes moot because neither the recovery nor the bootloader can be trusted.
- freeone3000 7y agoYou don't relock the bootloader because every lock/unlock cycle clears user data, and you might need to update recovery to update your ROM. Even if you relock the recovery, next step is the infamous "no sha1 signature found, flashing boot sector unconditionally" (which is a step up from md5!)
- freeone3000 7y agoYou don't relock the bootloader because every lock/unlock cycle clears user data, and you might need to update recovery to update your ROM. Even if you relock the recovery, next step is the infamous "no sha1 signature found, flashing boot sector unconditionally" (which is a step up from md5!) TWRP has enough attack surface; android devices have very little physical security.
- deleted 7y ago[deleted]
- userbinator 7y agoThe idea that ROMs from questionable sources make your device safer sounds very strange to me. "questionable" according to who? The authoritarian companies and the whole "security" movement behind it, whose primary purpose is to turn the population into a mindless flock of consuming sheep that they can manipulate easily to extract profit... The Android modding community is definitely not stupid, anyone who tries to deceive will soon be outed and ostracised. A lot of its members aren't all that smart; but it only takes one to find out and post proof. Edit: the state of this comment reflects the state of the industry: spread fear and keep people from thinking for themselves.
- kyle-rb 7y ago>The technological complexity of any smartphone is far beyond comprehension for most people. The exact same goes for regular computers and operating systems. And we still have those. Shouldn't we at least have the option on mobile?
- alkonaut 7y ago> And we still have those. You have computer form factors and OS'es invented in the 80's and 90s for desktop. The only reason they still work that way is because of legacy/inertia. The exception is the ChromeBook and CromeOS and that works similar to a smartphone. For a reason.
- kyle-rb 7y agoChrome OS now has Crostini, which allows you to install basically any Linux app. Or is that also attributed to the legacy/inertia of Linux?
- pier25 7y ago> I think Apple's approach is the only reasonable one for the general population. The general population uses macOS just fine.