Why Google should make Android root access an official feature
extremetech.com
extremetech.com
AT&T: Looks nice. We'd like this one to look more iPhone-like.
Samsung: No problem. Our designers are very talented. One new feature of these devices is root access for any advanced users who want to customize their phones.
AT&T: We don't think that's a good idea.
Samsung: You got it. Root access is gone.
I think far fewer Americans would own smartphones if they had to pay the full, unsubsidized cost up front.
Change will require a (major) disruption.
Is it just because Apple is the only company ballsy enough to walk away when a carrier says no? (And they bring the iPhone to the table, but 5 years ago that wasn't necessarily such a good thing)
Power users do. Most do not. That alone is the reason Google will never make it a priority.
But yes: gaming, browsing and texting don't require it. And a big portion of the user base never leaves that box.
I think the most practical solution, given that people are always going to want to push the limits of the devices, is to permit, but disclaim responsibility/liability where possible. "By accessing the root features of this phone, you're no longer eligible for $x direct support, and you're aware of $bignum ways in which this could be a Bad Idea"
The problem with that is too many people are going to put on their disclaimer-blinders, and click straight through anything that isn't Making Their Damn Internet/Facebook/Game Work, and call you anyway when it screws up. Maybe a certain barrier to entry does have some merit after all...
Carriers and platform vendors (but not, in general, hardware manufacturers) don't want users running unauthorized code because they don't want to lose access to revenue streams therein; and by extension that they fear the loss of control means they will lose access to any future revenue streams.
In the case of Apple products, I'd take my shiny laptop back to the Apple store, and they'll deal with it (generally). So is that support cost baked into the already-high cost of Apple hardware+software?
That said, your argument is probably a good one, too--the carriers and platform vendors really do like lock-in, so they would likely do whatever they could to turn off root access.
Yes, there are issues about carrier licensing. Let's not get into that. I'm simply talking about why people root their phones.
Take webOS which you could put into dev mode (essentially rooting) by entering the Konami code (upupdowndownleftrightleftrightbastart ).
Didn't seem to do them a bit of good. So easy rooting may be a desirable feature but doesn't seem to sufficient feature to ignore other more important features.
Or does Android require some additional breaking in order to achieve the equivalent of init=/bin/sh?
I would like to to see Android get a well known, official way to get root, a way to install authorized root/setuid programs, AND a multiuser model of operation.
When I mention wi-fi tethering and explain how it works people's eyes light straight up whether they are a "normal" user or not. Some phones come with that feature enabled out of the box but most require root.
however, i'm not sure i see how giving a choice of easy root to the end user would de-incentivize the development of malicious exploits which seek to gain it through other non-interactive means which bypass the officially provided method - there will always be incentive to do this, though i agree than it may take much more dedication and time to develop since there is not a huge community after it. on the flip side of the coin, these 0-day exploits likely would not be publicly disclosed as they are today for the sake of giving freedom to the end users.
I can say with absolute certainty that we've held previously back active, root-level exploits in the OS or supporting Android libraries that we've found to a later date, solely to ensure that users continue to have access to root.
holding back exploits is always a two edged sword in the walled garden created by carrier subsidies. it's a never-ending balancing act of security concerns and device freedom. capitalism will never provide us with both - a stallman-level open ecosystem and the low prices we pay to be bent over backwards by vendor lock-in.
It wouldn't have to be rooted by default. The ideal solution would be a USB tether + dev tool connection required to turn this on, so unsuspecting users aren't compromised by malicious apps.