5 ms·
> Mandate that all devices should be unlocked and allow installing alternate operating systems, with the requisite documentation to build such operating systems
by kogepathic 3y ago
> Mandate that all devices should be unlocked and allow installing alternate operating systems, with the requisite documentation to build such operating systems published.
I develop for embedded devices and I don't see this working as intended.
Embedded devices often have secure boot efuses burned during manufacturing. There's no way to reverse that later or install your own cert.
Datasheets and SDKs for the chips are behind expensive support contracts and onerous NDAs.
Industry and middleware vendors are absolutely opposed to giving away anything, even though many of them fork existing FOSS projects for their SDKs.
We already have mechanisms to obtain source code, and yet there's no effective enforcement mechanism for companies that ignore GPL requests.
I agree that more needs to be done to prevent planned obsolescence, but I do not believe lawmakers have the technical knowledge to write anything effective.
- K0nserv 3y agoNot my area of expertise and I agree with your concerns about lawmakers, but with the input of experts, such as yourself, would it not be achievable? What I described is, after all, how desktop computers work. I can buy off the shelf components, assemble them, and install a variety of Linux distros or Windows. I don't quite understand why the same thing wouldn't be possible on mobile devices.
- toyg 3y ago> Industry and middleware vendors are absolutely opposed to giving away anything I mean, "industry and vendors" were also opposed to everything from the 40h week to pollution filters. That's why they are laws: because otherwise money trumps the common good. It's absolutely doable and enforceable that any consumer device sold in a given market should be repurposeable after, say, a period of 5 to 10 years from the end of its manifacturing run. On expiration of such window, schematics, software, and keys, should be provided to some central state-run repository. If a company is sold, acquirers should inherit all obligations, hence improving the situation with "lost" IP as a side-effect. It would be the hardware equivalent of patent expiration.
- thesnide 3y agoAwesome idea! But why a fixed year range? ;-) Make it "as soon as EOL, and at least 5y" That will put some incentives of longer support, as otherwise everything will be released immediately.
- RealityVoid 3y agoYou usually have some sort of boot chain signature for the efuses. You have an initial bootloader and then that checks the signature of the next in the boot chain and so on. You could write an unlocked signed bootloader on the board, that is valid and boots and that can boot into anything. If I'm not mistaken, that's _exactly_ what G is doing with the Chromebooks.
- yjftsjthsd-h 3y agoOn the contrary, Chromebooks are one of the better options; they can generally have their bootloader unlocked, unlike ex. most phones
- RealityVoid 3y agoI might have been unclear. I meant that google ship devicess e-fuses enabled but with the unlocked bootloader option (using, I believe, the mechanism I tried describing above). They do make this, a lot of other vendors don't. Good for them!
- kogepathic 3y ago> You could write an unlocked signed bootloader on the board, that is valid and boots and that can boot into anything. True, but almost no one does this (Google/Chromebooks being an exception). It would be a hugely positive step if manufacturers were required to ship/escrow/provide an unlocked bootloader to sell their products. Unfortunately, that isn't the case today and it's only through goodwill that this is possible.