7 ms·
Yea the mentality with phones is super annoying from both Android and Apple.. The user should have access to everything via some special interface / typing in y
by xt00 4y ago
Yea the mentality with phones is super annoying from both Android and Apple.. The user should have access to everything via some special interface / typing in your pin / password or whatever. The idea that the owner of the phone can be prohibited from seeing what is actually running on their device is horrible. Hope one day the norm is that users can get root on the device they own rather than it being explained that “oh that’s too powerful for users to have.. we as the company who made the device have root but you cannot..”
- josephcsible 4y agoTo be clear, Google did the right thing here. Xiaomi proposed an evil user-hostile patch, which Google refused to merge.
- mistrial9 4y ago> evil user-hostile patch I do not doubt you, but that is not a fact-based statement. Can we do better?
- saagarjha 4y agoWhat would “better” be in this context? The decision to merge a patch is functions correctly is necessarily opinionated.
- josephcsible 4y agoThe patch inhibits the owner of the phone from accessing data stored on the phone.
- tomc1985 4y agoFunny, I thought this was Hacker News, not Reuters. What are facts, in this day and age, anyway? I guess 'objective reality' doesn't quite have the same ring to it.
- pjmlp 4y agoWhich means in the end Xiaomi phones will have feature anyway. The Android ecosystem is full of fragmentation, the same one that Google fanboys argue that Android was designed to fix in regards to J2ME. Another two common example among Android devleper complaints, is OEM support for cameras, and background services being killed in name of battery resources. Whatever Google decides is of little value for an ecosystem where the majority of consumers aren't getting Pixel phones.
- cowtools 4y agoWhat matters is that the consumers have choice to use free software if they want. If someone makes an app for a (locked-down) samsung phone, it's going to work on a pixel phone running some AOSP distro. If google took some hardline policy or license that prevented the likes of samsung or xiaomi from tinkering with the OS, then all of these companies would be spinning up their own OSes and you would have even more fragmentation. the end result would be worse for the remaining AOSP/Pixel users. Even if the consumers had privacy and control by default (which is a good thing, don't get me wrong), they still have to choose to take steps to maintain that privacy and control, because user respecting software is necessary but not sufficient for freedom. I think the android userbase will come around when they realize that plain AOSP and vanilla android are just way better than all the bloated shit these manufacturers are doing with android.
- pjmlp 4y agoThe OEMs are spinning their own OSes for years, as anyone trying to make their app work across the ecosystem painfully knows, what AOSP allows is that they don't need to start from zero. Android userbase, the one that actually matters to app developers, just goes to the shopping mall and gets whatever cheap Android devices are on sale with pre-paid cards. Again, Pixel phones are more symbolic than anything, outside US very few countries have them on sale on those shopping malls.
- cowtools 4y agoThat's true, but I think the wisdom of tech-inclined people will eventually reach the general public. See the rise (and fall) of OnePlus, which was once praised for making a good stock android phone.
- xt00 4y agoYes they did -- but as a thought experiment, these types of security measures could be totally reasonable to have if the owner of the phone had root. Sure, lock my phone down until the cows come home.. but I hold the master key (or I can get it easily in a fashion I have control over -- if you fear being forced to under duress then you can set something up to prevent that). Lets be real here (as many people mentioned) the key exists, its just not in your hands as the phone owner. It is in the manufacturers hands. And we want it. The one problem to solve is how to verify that you own the device. Saying that that is too hard to solve is not a good enough reason to deny people from having it. There are 100 solutions to this that cryptography folks could devise -- probably folks here could think of tons (one time keys, requiring physically going to a safe place to retrieve the key, requiring a secondary person, having the ability to provide provable information to the person who wants the key that the person who you are threatening does not have the ability to unlock it, etc) -- but yea, there is theft, hacking, border security snooping phones, etc.. those all exist, so blocking those people from getting root on your device is critical -- now lets think of solutions rather than saying OK Apple and Google get to own my device. If we are one patch away from essentially having no clue whats running on our phones, then we are in way more trouble than we thought we are in... we should have "right to root" on our devices now.
- Arnt 4y agoIt sounds as if you're confusing "the owner of the phone" with "the momentary user of the phone", as in, the DHS officer who may ask for your phone when you travel into the US.
- josephcsible 4y agoThe protection from "the momentary user of the phone" is supposed to be the encryption/lockscreen PIN. And even if that weren't the case, I'd rather that the DHS officer be able to access my APKs than for me to be unable to access them.
- deleted 4y ago[deleted]
- car_analogy 4y agoHow is it that in these discussions, apologists for removing user sovereignty become suddenly ignorant of every existing security solution (such as, in this case, even plain old passwords), to claim the only way to secure a device is to hand control to the manufacturer? "How will I keep people from breaking into my cell if the warden doesn't lock it?"
- Arnt 4y agoI think that happens as soon as someone writes "Hope one day the norm is that users can get root". The quote is from upthread. I have a phone on my hand, no proof of purchase, no proof of ownership, no traceable path of transactions back to the manufacturer, should I be able to get root?
- car_analogy 4y agoThat is a spectacularly, obtusely uncharitable interpretation of that statement. I didn't need proof of purchase, ownership, or a traceable path of transactions to the manufacturer when I got root on the PC I built. Or on my phone, for that matter. Yet somehow, it's now secure, and anyone else that gets their hands on it, won't be able to get root. This is the exact kind of amnesia I was talking about. Are you really unfamiliar with default passwords that one changes at boot, such as every consumer router has?
- renewiltord 4y agoEh? Android permits this user access and blocked a mechanism to remove this user access. This comment is a complete non-sequitur to the actual event.