For all the bravado about standing up to powerful interests, this shows you who the most powerful interests are in that space.
For all the bravado about standing up to powerful interests, this shows you who the most powerful interests are in that space.
There is a lawsuit around that ballot initiative, and iFixit and EFF just filed an Amicus on Monday supporting the law. https://www.eff.org/deeplinks/2021/06/eff-files-amicus-brief...
Sometimes it's better to fight the giants one arena at a time.
The auto industry giants are still being fought - just not over this bill.
I think that if the laws overlap it will be opposed by multiple industry giants and will be harder to pass. At least that’s what it seems from the post above.
I believe that is intended to be read as "digital electronic product or embedded software found in medical settings."
After all, the description of what the bill does apply to is "digital electronic equipment". Interpreting it to apply to "equipment" but not "products" doesn't really make sense.
California's Right to Repair bill, which got very close to passing this year, was solely focused on medical equipment. https://leginfo.legislature.ca.gov/faces/billStatusClient.xh...
https://www.google.com/amp/s/medicalxpress.com/news/2019-06-...
Sorry for the Google amp link.
There’s also this kind of medical device hacking (again not black hat):
https://hackaday.com/2020/07/15/diy-dongle-breathes-life-int...
And open-source ventilator software:
https://hackaday.com/2020/03/30/professional-ventilator-desi...
That said, Safety is red herring that the industries use to justify their anti-consumer actions with zero actual data to back their position.
The Record are cars is clear and estiblished people self repair and use independant repair all the time to fix mechnical safety systems like breaks with no systemic issues or damage to public safety
For medical devices I have yet to see any data the independent repair causes any harm, in fact I believe the the US Government has a study that states Independent Repair of Medical Equipment is critical to maintaining the US Health System, so in the case of Health Care prohibitions on independent repair may CAUSE public health issues by taking critical equipment out of service waiting on "authorized" repair or parts
Depending on the law, it may also require more documentation, ban on total lockdown of devices and obligation to sell spare parts(but you often can buy genuine spare parts through service centers)
Right to fix also doesn't cover warranties, as you will loose your warranty when doing it yourself.
For cars or medical equipment - that's clearly political influence, masquerading as "public safety".
There's nothing stopping me from modifying my car to be very dangerous right now, without even affecting my warranty. The difference - I cannot install a third party keyfob, because the protocol is locked down.
The kind of medical equipment that hospitals require, already comes with multi-decade support. And your CPAP device can be serviced by someone without manufacturer specific training(that costs a fortune, for little practical value).
The Magnussen-Moss warranty act of 1975 states (IANAL) that a repair cannot void the warranty unless the manufacturer can prove that your repair caused the damage in question.
https://en.wikipedia.org/wiki/Magnuson%E2%80%93Moss_Warranty...
IMO it comes down to this: do we advocate for laws that give companies the ability to decide what is right/safe for the public, or do we advocate for laws that reflect trust in the individual?
Well, while this applies to medical devices, worth noting this doesn't apply to cars, for which safety inspections have existed in many states for quite a while.
This is a really great way to put it, and it applies broadly to so many fundamental disagreements in the tech world.
I firmly believe it’s better to trust the individual—so I think users should be able to sideload iOS apps (only if they want to) and install their own root certificates. Others think individuals can’t be trusted, and so we should let tech companies dictate what is safe for everyone else.
In the US, I think, some companies sell weapons and nobody seems to care if people can hurt themselves with them.
people forget all this. this is the same thing people want for farm vehicles and personal electronics.
we got it done for cars and trucks in the late 1980s. I don't understand why it's so hard to get lawmakers on the side of the customer --their constituents-- today.
I also agree with Apple's implicit claim that if iOS users could sideload apps, millions of idiot iOS users would get their devices owned after they followed some "follow these seven steps to get free $POPULAR_MOBILE_GAME tokens!" guide they found on the web, making the platform less trustworthy overall.
Apple makes a good argument that buying an iPhone is also buying, in a sense, a remote managed security service for the device at the same time. The net effect of this is that millions of people now have devices mostly free of the most egregious malware (and it's limited to just spyware, delivered via the App Store). For most users, this is a better state of affairs (at least in peacetime, or outside of China/Vietnam/Russia/etc).
You don't have to install updates.
However, if you install an update to try it out, or because you didn't realize that it would e.g. break 32bit support, you can never downgrade again (unless you happen to be within a two-week-ish period.)
"Apple makes a good argument" Their argument doesn't give near enough excuses for their mafia level racket to shake down businesses of protection money. "Pay us or Joey will break your kneecaps. Its for your own protection."
Millions of Android devices have malware problems, yes. I might even agree with a claim that it is ZOMG millions.
Estimates claim that as far back as 2016, a million new Android devices were being infected with malware per month. The current figures are estimated by AV vendors at 4-7 million infections per month.
My claim is that for most users of iPhones, the situation of Apple being in control of their device, rather than themselves, results in a better outcome for that user (and is oftentimes explicitly preferred by that user as a result, and is reflected in their purchase of an iPhone).
In fact, Apple delegates control of an iPhone's userspace execution environment to any iPhone owner who wants it: they will give you a signing cert for use in xcode to run any app you want on your own device (no developer subscription necessary). This is how AltStore works, and allows AltStore users to run emulator apps on the iPhones they own.
Okay, but that comes out to the same thing, since I can't buy an iPhone which isn't Apple managed. If Apple offered a choice, that would be one thing—but they don't.
> In fact, Apple delegates control of an iPhone's execution environment to any iPhone owner who wants it: they will give you a signing cert for use in xcode to run any app you want on your own device.
What they give you is the ability to sign up to three apps at a time, all of which expire after seven days. It's not useful for anything but testing.
Plus, you're stuck in the App Store sandbox. You can't downgrade to an earlier operating system, you can't inspect the HTTPS traffic being sent out of your phone, and you can't even run anything that uses a JIT.
Well, you know this state of affairs well now, so when you buy an iPhone you willingly opt in to these remote management restrictions. There are lots of smartphones you can buy without such cryptographic boot restrictions.
Many people willingly choose iPhones (even given these constraints), and would prefer a remote party manage their device's security.
Apple's argument is a legitimate one, and you should be able to operate in the market in this fashion. Nobody's forced to buy an iPhone if they don't like how the bootloader is configured or the App Store is run.
I mean, but you're making a big assumption there! I buy iPhones in spite of those restrictions, because the only other options have worse processors and cameras, and because most of the people I know use iMessage.
I'd pay double the cost of a normal iPhone for a Security Research Device, if they were available to the general public.
And if they decide to they can flip a switch on their server to disable your account and stop “your” apps from launching.
Medical devices I think should need a someone well versed to work on it.
With cars, the current model most states in the US have is a good middle ground. You can do whatever you want to your car, but it needs to pass a safety inspection every 2 years to drive it legally.
The inspections in my state are fairly comprehensive. Airbags, seat belts, headlight brightness, and structural stability of the frame to name a few.
It also helps the US has a strong car culture with tons of experienced DIY-ers, which I imagine helps.
Modify a dishwasher and now it fills your kitchen with soap bubbles? Modify a CPAP machine and get killed by it? Not the manufacturer's fault.
The US is too litigation happy as it is...
Without clear quality and regulatory control there must be an objective method to discern between personal repairs and non-personal ones.
Disclaimer: didn't read the actual right to repair being passed in detail. Not sure if it does discern already.
To really fix it we need a non-profit group to be in charge of the certification, preferably one who can be held accountable for failure due to their certification. My removing the incentive for profit we make it so the Medical industry won't try to control it, the insurance industry to mitigate their requirements, and government from trying to have political agendas pushed.
I have more that I would love to put in here but my employer has opinions that might differ from mine, and can be directly involved with some things that the law can impact.
There's no legal requirement in the US federally, or in any state I'm aware of, to have any certifications for general automotive repair. The EPA does require it for working on air conditioning systems, though. [0] However, many employers do require certification and/or will assist in getting the certifications. Some of the smaller shops are more likely to have mechanics without certifications or with expired certifications (I believe ASE certs are five years). ASE does require hands on experience for their certifications in addition to the test, though. [1]
The BLS also describes this, probably better than I do. [2]
[0] https://www.epa.gov/mvac/section-609-technician-training-and...
[1] https://www.ase.com/work-experience
[2] https://www.bls.gov/ooh/installation-maintenance-and-repair/...
That's not nearly nuanced enough. Manufacturers should still be responsible unless they can prove you caused the failure. We currently require this standard for something as simple warranty coverage, we ought to require it for something as severe as death.
Only 4 US states have biannual safety inspections. Another 11 have annual inspections. The other 35 states + DC do not have safety inspections.
https://en.wikipedia.org/wiki/Vehicle_inspection_in_the_Unit...
Car SW that can control the vehicle motion goes through very rigorous ISO processes, it's not something you just casually tinker with as an individual. Given its hard to visually inspect, one needs a way to understand if a car has been modified or not. This article also on the front page here yesterday explains the complexity and cost of integration verification https://spectrum.ieee.org/cars-that-think/transportation/adv...
Enabling serious third party aftermarket companies that have gone through same level of certification, nothing against that, but individuals, not so sure.
I see where you are coming from but right now, if autopilot kills someone, then Tesla are on the hook for it (ok, there may be grey areas but ultimately, they made it so that has to point back to them in a big way when it comes to court cases). However, if I jailbreak my autopilot and kill someone, it's me that has to face the music!
I don't see the harm in scaling the jailbreak hoops you need to jump through.
For example, if I wanted to safely jailbreak my iPhone, there is nothing stopping Apple having an official app that you need to get a special key from Apple for. Maybe a phone call or something, or an email to support. It would come with a caveat that says your jailbroken phone forfeits any warranty claims. Fair enough.
When you are talking about jailbreaking a Tesla, there could be other layers. Like, for example, you have to go to a Tesla dealer where they explain the legal and support ramifications and whatnot. Then you sign a bit of paper with witnesses. Then they send you out a usb dongle in the post after a few days etc. Maybe, though with the Tesla, there would be limits. Like, you can't get the source code, or you are only able to to X things with it.
You get the idea... there could potentially be a scale for stuff like this.
I'm just chucking stuff out there, this isn't a realistic example so please put your pitch forks away :)
But if little Johnny wants to drive his Tesla around a private racetrack with homespun Autopilot software, by all means! It's hardly the weirdest hobby, and who knows—maybe he'll grow up and form a startup that uses modified Tesla's to transport products in large warehouses. That's how innovation happens.
And often with medical devices, they may often be supporting the life of someone other than the original purchaser and sole maintainer.
edit: may have misinterpreted what you wrote. Nobody should have to have amateurs perform repairs, whether they are first party or not.
Given the cost of medical care in this country I think it would be a very good thing if that agreement not to sell parts was against the law. Surely an electric motor to raise a chair up and down could be replaced with the correct part without compromising anyone’s safety.
although in this specific case in example, if the country you're talking about are the US, having access to the $500 motor only means wider profit margins for the hostpital, not necessarily lower bills for hospitalized people.
It would suck to die because the repair guy didn't solder the wire correctly.
It's really tough to draw that line though, and it's in the manufactures interest $ + lawsuit wise to play it safe.
the reason the US has such high healthcare is because healthcare is both private and paid-by-insurance.
a lot of other nations have free healthcare, both in the american continent and in Europe.
Lots of countries have combined public/private systems and get equal or better results with lower per capita and per GDP expenditure than the US.
The US has expensive healthcare because it has an exceptionally poorly designed public/private system, not because it has a public/private system.
This "greater safety" concern is nothing but masquerade.
Even the GPLv3 makes an exception for this class of device.
Citation very fucking needed, because exceptions for specific fields of work directly contradict the underlying principles of the GPL, and indeed [0] contains no occurence of the word "medical".
The anti-tivoization text in the license applies to these User Products. Medical devices are not included in the definition.
(I'm excluding cribs...because my partner laughed at me when I suggested building our crib and told me that was fine as long as I followed all the rules)