6 ms·
> Most Android devices these days have bootloaders that cannot be unlocked [citation needed] I'm finding the majority of devices to be unlockable as long as y
by techrat 5y ago
> Most Android devices these days have bootloaders that cannot be unlocked
[citation needed]
I'm finding the majority of devices to be unlockable as long as you don't buy your device from a carrier.
Carrier locked devices are not typically the norm but in the US.
And if you truly cared about software freedom, you wouldn't be buying carrier locked devices in the first place.
I really wish people would stop griping about losing security features when you flip the one switch that ensures the security of the system. Unlocking the bootloader means it is now possible to modify system files. Of course Safetynet is going to fail. The point of Safetynet is to ensure the system hasn't been tampered with.
However, despite all of your doom and gloom posturing without actual examples, I've yet to actually use a single app (and I use several banking and root detecting apps like remote features for my car) that will prevent me from continuing to use the app if rooted. It just pops up and says "We see you're using a rooted device, this is not recommended." I click "OK" and proceed as normal.
The alternative is to use Apple and whelp, that'll never happen... since I actually do care about software freedom.
- the8472 5y ago> I really wish people would stop griping about losing security features when you flip the one switch that ensures the security of the system. Unlocking the bootloader means it is now possible to modify system files. Of course Safetynet is going to fail. The point of Safetynet is to ensure the system hasn't been tampered with. That's pretty much drinking the DRM koolaid. You can have both, verified boot and freedom. All it takes is a mechanism to replace the manufacturer's trust root with an owner-supplied one. The process would wipe anything secured by the trusted components (including keys securing the user data) but that should be fine since you can make a backup. The only thing that wouldn't work is software that wants to ensure that the user has no control over the system - DRM or "the user is too dumb to be trusted with their own device" security theater.
- pjmlp 5y agoIt is no longer a security theater when the user gets a malicious app installed, that takes over their bank management app.
- the8472 5y agoChanging the root of trust doesn't mean applications can suddenly take over other applications. It also requires granting the malicious app sufficiently elevated permissions for that takeover. The user made several choices along the way. If your argument is that there's the possibility that they could make the wrong choice then this is in my opinion security theater because it posits that a thing can only be secured by taking away choice and no other way.
- pjmlp 5y agoOn this kind of devices the security chain of trust needs to take into consideration the same kind of users that fill their Internet Explorer with random toolbars from website popups. Not the user with a CS degree that knows what they are doing.
- the8472 5y agoThose kinds of users are unlikely to replace the root of trust, simply due to the process being onerous. And even if everyone were to install malware. There are other ways to secure banking. E.g. by providing an external token with a display. This is how hardware crypto wallets and some PIN generators for in-browser banking work. Or they could ask the owner to upload the attestation pubkey to their website, then the bank could still check if it's really their app that's running (as confirmed by the boot trust chain). I'm not sure how fingerprint scanners are tied into secure boot, maybe they could be used to verify user intent too.
- wizzwizz4 5y agoOkay, so the app's running. Except the app is remote-controlled by a malicious “display driver” that waits for the user to do all this authentication set-up, transfers the money away, “are you sure”s it, then prevents the user from seeing any of the on-phone scam warnings until it's too late to reverse the transaction.
- 5y ago
- wizzwizz4 5y ago> And if you truly cared about software freedom, you wouldn't be buying carrier locked devices in the first place. This irks me. Not everyone has such choice about what to buy.
- techrat 5y ago> This irks me. Not everyone has such choice about what to buy. Not an excuse anymore. Motorola has universal devices that work on all carriers. Including the most difficult ones in the US, Verizon and AT&T. The unlocked Motorola devices are also often cheaper than getting a device through a carrier.
- lotsofpulp 5y agoIt has not been an excuse since 10+ years ago in the US.
- krzyk 5y ago> Not everyone has such choice about what to buy. There is always a choice. There are multiple devices at given price point. Taking credit to buy a mobile is not a wise choice ever.
- selfhoster11 5y agoI trust an unlocked Chinese phone with Lineage OS a lot more than whatever it came with, whether that's for speed, features, security or robustness.