The fact that that is an extremely complicated thing to do is not apple’s problem.
My issue is that Apple (and many other manufacturers, this isn't really Apple specific) add complexity solely to act as digital locks on what is otherwise a fairly obvious and achievable task.
Take your ROM example - Why should I even need to rip it off and replace it? I know damn well how to flash ROM. I have the software tools available. I have the image file with all the drivers I need/want. The only thing stopping me is digital locks in the device.
Are the locks themselves evil? No, clearly not - I lock my house when I leave, and I'll probably leave my phone locked most times too.
Are the locks evil if I don't own a key? Pretty clearly yes.
Can I rip the whole device apart, interface directly with the ROM, and flash it? Probably - assuming I buy some much more expensive hardware. But that sorta defeats the point of having the device, yes?
Just like it's not reasonable to sell me a car without a key.
---
- Congratulations - you own this brand new car you just bought!
- Great! Thank you so much, can I have the keys to drive it now?
- No, no... of course not. When you want to drive it, you phone us up, and we come unlock and start it for you
- Wait... what? That's bullshit - I just bought this car!
- Well, you're welcome to break a window and hotwire it to drive it. But do be aware we'll report this as theft to the police, and depending on what you tinker with we might also throw the DMCA at you
Apple adds these arbitrary digital locks since they protect against the threat model of physical access, whether that be an attack thanks to leaving the phone unlocked or giving your passcode to your friend to use for a while. This is all in disregardless of whether or not the customer actually has this as part of their personal threat model.
Zero of which will be bought by me.
>Apple adds these arbitrary digital locks since they protect against the threat model of physical access
Apple can add as many arbitrary digital locks as they want. The problem is that they keep the key instead of giving it to the user.
Which they still own and have.
Adding an optional "You phone us and we can unlock your car with a copy of your key" is fine by me. As long as I still have the fucking key.
----
For the second part - The security boogey man is not a compelling argument to give up ownership rights and enter digital serfdom where you only own a device if you use it in the way the manufacturer intends and approves of.
I'm not asking them to stop selling devices with locks. Hell, I'm even fine with them keeping a copy of the keys (which they have right now). I'm just saying: As the owner of a computer, I deserve to have a copy of the fucking keys that make it work.
- I just want to be able to drive MY car as fast as I like!
- okay, but the trouble is the way this car works, if we give you the ability to disable the speed limiter, there's literally no way we can do that that doesn't also open up the possibility that when you turn on the radio, the radio station might broadcast an ad that causes an uncontrolled acceleration.
- that's a stupid way to design a car
- well yes, but this is an analogy car, not a real car. The real system in question is a turing-complete networked device designed to run arbitrary third-party software, so... the analogy is going to be slightly flawed.
And no, Apple isn't going to report a theft if you physically damage your phone, nor are they going to have a DMCA complaint if you hack your own phone in ways that let you change the way the software on it behaves (you might run into DMCS issues if you try to distribute tools to help other people do that, which is... definitely dubious, but that's what the law says; it doesn't have a great deal to do with this case of the Apple restrictions on which software the OS trusts to use its multicast API, though.)
---
This - this piece here is the fallacy in your argument. There absolutely are ways to do this. Matter of fact, Apple themselves have a nice little set of digital keys that lets them turn all these locks off as they please.
So the argument is not "We have no way to do this safely" it's "We don't believe you (the owner of the damn device) can be trusted to do this safely."
Which brings me right back to - you don't own the damn thing.