10 ms·
Yes my scope is mainly tablets and phones, but still applies to other devices with locked down boot-ROMs or boot loaders where the device has no means for the o
by anfilt 5y ago
Yes my scope is mainly tablets and phones, but still applies to other devices with locked down boot-ROMs or boot loaders where the device has no means for the owner to disable it or load their own signing keys.
The right I am talking about is primarily the right of exclusion and its not just an American concept plenty of other countries have similar concepts or even the same name, but of course the exact details will vary from one legal system to an other.
Effectively apple retains the right of exclusion via extralegal means by using cryptography. Apple can unilaterally decide to exclude software from devices they don't own by not signing it. If you wrote some software yourself for instance you would also still have to ask apple to sign it which they only will do under certain conditions. Essentially if you have to keep having to ask a 3rd party to do something with something you “own” you don’t fully own it.
Why it’s extralegal is that normally a seller would require a buyer to agree to a contract to retain some rights over real or tangible property. Instead apple is using cryptography to effectively retain some property rights despite the buyer never signing a contract agree-ing to this arrangement.
- threeseed 5y ago> Instead apple is using cryptography to effectively retain some property rights despite the buyer never signing a contract agree-ing to this arrangement. You agree to the terms when you first use the device. And if you don’t agree to the terms you can get a refund and buy another phone.
- anfilt 5y agoYou can buy the device without agreeing to any terms of service. Now you may not be able to use iOS without accepting the TOS durning setup. However, the fact is the hardware is still a separate entity from OS and is still locked down. The problem still persists that apple is selling hardware that you don’t have full control over. What if I wanted to run linux instead or even bare metal code that I wrote myself? Apple does not permit this nor will sign such software so that boot-rom will load it to RAM. Just because your average user may not do those things does not mean their rights are not being effectively diminished compared to other tangible property they buy.
- threeseed 5y agoAnd you are free to do whatever you like with the hardware including installing any software you choose. Apple is under no obligation however to compromise the security of their device in order to help you.
- smoldesu 5y agoCorrection, they're under no obligation to provide support if I decide to compromise the security of my device. That decision should be left to the end-user though, and Apple's repeated action against people loading arbitrary code onto the iPhone is user-hostile, regardless of how you frame it. Offering third-party distribution channels is no less harmful than forcing users to access your content through a web browser, and the longer they deny it, the more frugal they'll appear when they face their final judgement. As of today, 35 states are stepping forward to call them on this behavior. Who knows what that figure will look like in a year's time.
- threeseed 5y ago> Offering third-party distribution channels is no less harmful than forcing users to access your content through a web browser This technically is ridiculous and completely untrue. Web applications, by design, have a tiny fraction of the capabilities of a fully fledged mobile app.
- vorpalhex 5y agoWell yeah, Apple refuses to support any modern browser API in Safari.. and prohibits any other browser engine.
- smoldesu 5y agoDon't [0] worry, they're[1] perfectly happy[2] to catch[3] up on the[4] critical vulnerability[5] front. [0] https://jonbottarini.com/2021/12/09/dont-reply-a-clever-phishing-method-in-apples-mail-app/ https://jonbottarini.com/2021/12/09/dont-reply-a-clever-phis... [1] https://www.theverge.com/2022/1/16/22886809/safari-15-bug-leak-browsing-history-personal-information https://www.theverge.com/2022/1/16/22886809/safari-15-bug-le... [2] https://nvd.nist.gov/vuln/detail/CVE-2021-30858 https://nvd.nist.gov/vuln/detail/CVE-2021-30858 [3] https://www.ryanpickren.com/safari-uxss https://www.ryanpickren.com/safari-uxss [4] https://www.cvedetails.com/cve/CVE-2021-30954/ https://www.cvedetails.com/cve/CVE-2021-30954/ [5] https://www.exploit-db.com/exploits/11567 https://www.exploit-db.com/exploits/11567
- oneplane 5y agoI don't get all the pseudo-lawyering. The firmware in your toaster is closed source too and you can't modify it either, yet that appliance doesn't get the same scrutiny? If you think: phone has CPU, memory and storage, thus it is a computer and I need to have the same "access" as a 1990's PC, then yes, the whole world might as well be burning right now. But if you take it for the appliance that it is, are you really surprised it works the way it does? If you are so worried about 'rights', where do you draw the line? (pun incoming) your modem, CMTS/CPE/ODN are all closed, crypto-sealed and inseparable hardware+software as well, as is the core router your packets flow through, the TCON board in your flat screen monitor and the microcontroller in your USB charger. Get a CPU from Intel, AMD, Qualcomm, TI, Nvidia, MediaTek, Rockchip etc., get a sealed boot loader that is cryptographically tied to the chip and the chip manufacturer. Heck, to get that sealed stuff as an ODM you sign so many NDAs it might as well be an appliance in itself. The days that you bought some end-user high-level hardware and had control over the stack are gone. Not because it can't be done differently, but because it's not viable. Even framework is having a hard time (as are Purism and System76) getting any true 'open' system. Not even a libreboot/coreboot system is actually unencumbered if you use any hardware from the last 5 years. People want a whole bunch of things, but the scale simply isn't there to carry the cost. Ironically, all of this stems from lawyering from the corporate side.