logoalt Hacker News

p0lychromatictoday at 8:38 AM1 replyview on HN

> Many rooted devices display during boot a warning that they have been rooted.

Usually, this happens after a bootloader unlock because then verified boot is disabled. You can still have a rooted device and not break verified, resulting in no warning. See: jailbroken iPhones.

I wouldn't say it's a solved problem. Just have to find an exploit that works with verified / attested boot.

And device manufactures are getting more and more restrictive here, too. Why do you think that is?

> Let's pretend there aren't plenty other ways they could spy on you.

Sure, of course there are other ways to spy on people. But as we see here: If the device itself does it, then we like to blame LG. If they used an exploit to do that, then we blame LG's shitty security.

If a hotel owner installed a microphone inside one or their specific TVs, then we blame the hotel owner at least - not LG.

> If it's bad if a hotel does it, why is it okay if LG does it?

It doesn't seem like it is okay. We are discussing this right here.

> Do you honestly trust LG, and the thousands of "partners" that they sell your data to, and every government whose warrants they have to honor?

Do I trust LG more than a shady hotel / BnB owner or eBay seller? Yes. Do I trust them fully? No. It's not fully binary, I'd say.

> Your argument reduces to "if the warden lets us out of our jail cells, who will make sure we behave?"

I am just trying to say, it's really not that binary. You can extend that to other places whenever attestation is involved.

Do I like Linux and open platforms? Sure! Tampering is fun! Do I hate people using open platforms to scrape my websites and constantly cause load, steal my content and use that for AI training? Also, yes.

But how can I fight that? We run into CAPTCHAs, Cloudflare, Anubis and co. Now that issue is reduced, but the openness is also gone.

And you always see in tech spaces we rather want "dumb" devices rather than smart devices, because we cannot trust them.

Attestation buys you more trust, but at the cost of openness.


Replies

sersitoday at 9:07 AM

> I wouldn't say it's a solved problem. Just have to find an exploit that works with verified / attested boot

In general though on devices that are rootable, white-hat hackers are more inclined to responsibly disclose vulnerabilities instead of releasing them as a way to root said device. So having a rootable phone does increase security.

What doesn't increase security is when bank apps that are essential to daily life start detecting that a device has been rooted and force a lot of people into using closed source extensions to hide the fact that the devices is rooted.

show 1 reply