3 ms·
> compromises features like verified boot and selinux namespacing It only compromises those features because vendors refuse to build in the functionality to ha
by feanaro 4y ago
> compromises features like verified boot and selinux namespacing
It only compromises those features because vendors refuse to build in the functionality to have full control over your purchased hardware out of the box. Make it protected behinds loads of warnings and even hidden behind a trick like what you have to do to enable developer mode, but leave it baked into the OS.
- asimops 4y agoWell, I don't deny that there should be an option. Look at the parent post. But having root in the running OS seems to be a bad idea. I got this position after an extensive talk on this with some of the graphene os developers. They explained pretty good how rooting the device would impact the security measures taken in graphene. This is why I suggested putting the access behind a special boot mode.
- yoavm 4y agoCan you be more specific about your concerns? It's not like "having root" means "everything runs as root". You can enable/disable it per app, you always grant it explicitly when you want to - it's not very different from sudo on Linux.
- feanaro 4y agoI'd also like to hear these arguments, as I can't think of a technical reason why it would be unconditionally a bad idea.