Oregon passes right-to-repair law Apple lobbied to kill
techdirt.com
techdirt.com
Anyway, as far as I can tell, this law defines an independent repair provider as someone with a valid and unexpired certification demonstrating that they have the “technical capabilities and competence necessary to safely, securely and reliably repair consumer electronic equipment” and that the manufacturer is allowed to decide which certifications they trust.
Without these certifications, you are not an independent repair provider and manufacturers can refuse to allow you to do anything. You can be just an average person repairing your own device, in which case the manufacturer must work with you. But you can expect to be forced to prove that you own the device before that happens.
[1] https://olis.oregonlegislature.gov/liz/2024R1/Downloads/Meas...
Not saying it's a good system, just that it's consistent.
No doubt they will weaponise this ability
What happens if the manufacturer decides to be unreasonable, by saying that no industry standard of certification is acceptable, or just the one organization they founded themselves, or that sort of thing, is that they get a sharply-worded letter from the Oregon DA. If they don't sort it out then legal action will be taken. So they're not going to do that in the first place, because everyone actually involved in this stuff already knows that.
The law isn't compiled. Its function relies on a common understanding of context which is the major course of study in law school. If a CEO ordered a company to do the sort of thing you're proposing, it would be against the advice of council.
That assumes that the Oregon DA isn't collecting a bunch of campaign funds, gifts, etc from Apple in which case the DA will do nothing and taking apple to court yourself will likely end in a loss since our legal system is often pay to win and apple can out-spend you.
>If a CEO ordered a company to do the sort of thing you're proposing, it would be against the advice of council.
CEOs often break the law because they (and their council) know the risks of getting caught are small and/or that if they are caught the worst punishment they'll face is a fine which won't come anywhere close to the amount of money they'll make by breaking the law.
Generally, it's a good thing that laws are subject to interpretation by humans and not treated like code written for machines because we want flexibility, but without enough oversight and accountability that doesn't work out so well for us either.
If this is true, it doesn't seem like it's actually "right to repair" at all.
I wouldn't be surprised if they use this law to now sue "uncertified" repair shops.
Which, of course, is obviously false when you think about it.
(C) Makes parts available directly or through an authorized service provider to: (i) An independent repair provider or an owner at costs and on terms that are equivalent to the most favorable costs and terms at which the original equipment manufacturer offers the parts to an authorized service provider and that:
the word owner shows up 17 times in the bill, and seems to give the same rights to an owner, that an authorized repair shop has.
[edit: boo it was Maine! Happily "Oxford comma lawsuit" is sufficient search term: https://www.npr.org/2017/03/23/521274657/the-10-million-laws...]
I’ve got some feedback about it at work, so now I genuinely try to be a bit better about it. It is a bit easier for me to be mindful of it on HN, but, as evident by my comment history, I am still far from being consistently good about it.
It is still often a “stream of consciousness written down as I would speak it outloud”, but now I at least started doublechecking the punctuation (or lack of it) for any potential confusion it could create before hitting send.
Much to the chagrin of the computer scientists who think it’s some sort of robust formal specification for civil society.
Does this specific context allow for interchanging?
While this: "Wanted: dead or alive"
could be interpreted as: "We haven't decided yet what we actually want, if it's dead, or alive, but it's one of those".
Then it can be good to give them (the police) a call and ask if they have decided yet, before you go looking for the wanted person
Law is actually code, just written in a language that is full of UB and you need to have if run on the system to know exactly what it does, the system being the hierarchy of jurisdictions.
Which is why legalese exists. To try to limit undefined behavior by being extremely verbose to cut out any loopholes.
Like...imagine a kid jumping on their bed. Mom says "Stop jumping on the bed!" and the kids stops. Comes back to the kid's room later, kid is jumping on the bed again, tells the kid to stop. Kid says "I'm not jumping, I'm hopping!" and goes into a diatribe about the difference between jumping and hopping, mom says to stop hopping and leaves. Goes back again later, kid is STILL jumping on the bed, and mom is angry! "You said no jumping or hopping, I'm not doing either, I'm bouncing!"
Eventually the mom has to say something like "Do not jump, hop, bounce, spring, leap, or otherwise propel yourself upwards or laterally from the bed, mattress, or any other part of furniture intended for sleeping".
And then it goes on even further, because she did not say, that the kid must never "propel themselves upwards or laterally from the bed", and only stopped that action in that moment ...
They're going to kill the independent repair industry.
This bill does not kill anything that is not already dead.
What's that you sa? The requirements on certification are impossibly high. Oh noes.
Any bar at all is an improvement over what presently exists, wherein: There is a vacuous void.
Or they could offer their own certification, but make attaining it prohibitively expensive or difficult.
It's not a mountain of certificates, you just need one of many different options.
They explicitly mention A+ which I assume is the CompTIA one.[0] Yeah, I'm not going to say it doesn't suck to have to pay $250, but there are free practice exams[1]. Here, I even took a screenshot of their sample questions[2] there are things like
Which of the following password choices increases the chance that a brute force attack will succeed?
A. Dictionary words
B. Special characters
C. Long passwords
D. Capital letters
I'm okay verifying that someone has this basic level of competence. I would be surprised if any given Hacker News user couldn't pass one of these tests without studying. You need like a 78%...But let's be real, if you're repairing for a friend, you just fucking order the stuff for them and put in their name and info (with their permission of course). The only "for anyone else" part that requires certs is if you're operating a business. I think you all are blowing this part out of proportion. Mountains out of mole hills. I know it is the internet and we like to complain without knowing what we're complaining about, but come on...
[0] https://www.comptia.org/certifications/a
[1] https://www.comptia.org/training/resources/practice-tests
It's probably worth doing so before taking a stance. I'd highly encourage this if you see people arguing about something in the comments. Especially when it is linked. Here, I'll save you the trouble
(e) “Independent repair provider” means a person that:
(A) Engages in the business of diagnosing, maintaining, repairing or updating consumer electronic equipment in this state but is not an authorized service provider; and
(B) Possesses a valid and unexpired certification that demonstrates that the person has the technical capabilities and competence necessary to safely, securely and reliably repair consumer electronic equipment in accordance with widely accepted standards, such as a Wireless Industry Service Excellence Certification, an A+ certification from the Computing Technology Industry Association, a National Appliance Service Technician Certification or another certification that an original equipment manufacturer accepts as evidence that the person can perform safe, secure and reliable repairs to consumer electronic equipment that the original equipment manufacturer makes or sells.
We can see that it literally says what I indicated.>> It's not a mountain of certificates, you just need one of many different options.
Possesses __A__ valid and unexpired certification that demonstrates that the person has the technical capabilities and competence necessary to safely
Nowhere does it say that many are needed and the continued text makes a stronger indication that these are examples of such sufficient certifications rather than the specific ones needed. If you're willing to believe the other comments maybe you're willing to believe I googled the requirements and can find no such clear description in Oregon Law that one must have a mountain of certificates. All I can find is that you must be certified (with similar but not identical examples provided) and a specific requirement about the certification including discussion of pollution. Which those practice exams I showed even have such a question. But also IANAL, but neither are most of the commenters. Still, I did read the text before responding and tried to do due diligence before taking a position. I hope we can reduce the number of arguments by RTFMing.The National Appliance Service Technician Certification shows that the holder knows how to repair ovens, refrigerators, and other major household appliances. Your interpretation of the text says that the Oregon legislature believes that this qualifies someone to repair anything covered by their wide-ranging right to repair law. That can't be right, can it?
No, a more logical interpretation is that the list of certifications is just a set of examples, but that manufacturers will have to decide what is applicable to whatever it is they manufacture.
My guess is there would be challenges in court if they made the certification process onerous.
https://ij.org/press-release/oregon-engineer-makes-history-w...
So yeah, when I see verbiage about certifications like this as a barrier to repair electronics, it's pure protectionism and the state impeding actual ownership rights over whatever this crap is.
(Put bluntly, my hardware is mine. If I want to take it to someone else for repair, that's 100% on me and my property rights to decide that. 'CerTiFicAtIoN', especially with the shit company or govt in question should have no say on who can or cant fix MY hardware.)
When I want to get a battery replaced I take my device to the repair shop and they replace the battery. I don’t ask them if they are “certified”. If they break something the liability is on them. Every single repair shop I’ve ever been to offers a warranty on their repair.
The guy ipersting out of The back of his car at a flea market?
The state, the company, or some 3rd party independent org?
The bill also requires that a manufacturer does not "impose a substantial condition, obligation or restriction that is not reasonably necessary to enable an independent repair provider or an owner to diagnose, maintain, repair or update consumer electronic equipment that the original equipment manufacturer makes or sells"
> You can be just an average person repairing your own device, in which case the manufacturer must work with you.
https://www.law.uh.edu/faculty/adjunct/dstevenson/2018Spring...
So the language says "...in accordance with widely accepted standards, such as..." and lists stuff like A+ and WISE certs. The per the OEM standards is probably best undrstood as modifying the or another certification, so I think the language you are referring to is allowing an additional certification that the OEM considers valid.
It's unclear whether that means it counts as a widely accepted standard, or is allowed even if it's not a widely accepted standard, but pretty sure it's understood as modifying the last antecedent, rather than the clause as a whole in a way that eliminates the widely accepted standard portion..
It would require ignoring the widely accepted standard language and several other departures from the canons of construction to reasonably have the interpretation you use.
The language could be cleaner like they could use either and two sub clauses, but it doesn't need to be.
"Possesses a valid and unexpired certification that demonstrates that the person has the technical capabilities and competence necessary to safely, securely and reliably repair consumer electronic equipment in accordance with widely accepted standards, such as a Wireless Industry Service Excellence Certification, an A+ certification from the Computing Technology Industry Association, a National Appliance Service Technician Certification or another certification that an original equipment manufacturer accepts as evidence that the person can perform safe, secure and reliable repairs to consumer electronic equipment that the original equipment manufacturer makes or sells."
This is normal for legislation. The problem is that fairly often they end up with subsectioning so deep that you're running into the right margin -- I got about six levels deep -- so they simply don't do it. However, it's still standard to produce bills in PDF.
It does get easier with practice, but I still find myself copying and pasting into a text editor to reformat it. It actually is a helpful exercise just to read the law.
It's similar to reading a really long SQL query. Nobody formats them the way you prefer, so format them as you read and you'll force yourself to read the query with enough attention to understand it. It's simply the best way to read the things.
> Anyway, as far as I can tell, this law defines an independent repair provider as someone with a valid and unexpired certification demonstrating that they have the “technical capabilities and competence necessary to safely, securely and reliably repair consumer electronic equipment” and that the manufacturer is allowed to decide which certifications they trust.
That's true, but it also says:
"An original equipment manufacturer shall make available to an owner or an independent repair provider on fair and reasonable terms any documentation, tool, part or other device or implement that the original equipment manufacturer makes available to an authorized service provider for the purpose of diagnosing, maintaining, repairing or updating consumer electronic equipment that the original equipment manufacturer makes or sells and that is sold or used in this state."
The critical bit is that they have to supply owners, too.
“Fair and reasonable terms” means:
A) Makes documentation available at no charge [except cost to prep and print]
B) Makes tools for diagnosing, maintaining, repairing or updating consumer electronic equipment available at no charge and without impeding access to the tools or the efficient and cost-effective use of the tools [except cost to prep and ship]
C) Makes parts available directly or through an authorized service provider to independent repair providers or an owner at costs and on terms that are equivalent to the most favorable costs and terms at which the original equipment manufacturer offers the parts to an authorized service provider [with a bunch of limitations that try to ensure the OEM can't cheat]. Oh, and [there's limtations that authorized service providers have to be fair and reasonable to owners and independent repair providers, too].
AND, they can no longer use parts pairing to prevent third party replacement parts.
So:
1. An owner has a right to documentation at cost
2. An owner has a right to tools at cost
3. An owner has a right to replacement parts
4. Replacement parts going forward (essentially) can't employ parts pairing.
So, yeah the manufacturer doesn't have to have an authorized service provider, and doesn't have to support independent repair services. BUT THEY STILL HAVE TO OFFER DOC, TOOLS, AND PARTS.
Oh, and if the OEM doesn't have any authorized service providers, then the OEM is the authorized service provider.
What obligates Apple (or anyone) to trust ANY certification?
This is standard practice in the legal world because the nesting gets so deep if you indent you'd run out of page.
Maybe I misunderstand (I can't get the page to load right now) but what kind of document indents subsections? Not any book or article that I remember...
-> “We remain very concerned about the risk to consumers imposed by the broad parts-pairing restrictions in this bill,” John Perry, principal secure repair architect for Apple, said at a legislative hearing last month.”
There was a time when interpreting the “risk to consumers” as a risk of being prevented from gouging consumers would be cynical. Now I guess something like that occurred to the lawyers.
A better approach would be to force Apple to allow the device owner to pair parts (third party or not), and for Apple to provide a list of authorized non-OEM parts to anyone that was considering buying a used phone.
Also, I wonder what this does to the anti-theft mechanisms. Before touch id, basically nobody set screen passwords, and phones were stolen at extremely high rates. After that, and because a stolen iPhone is marked as such and won't work with Apple services, phone theft dropped to almost zero.
If Apple's not allowed to prevent the pairing of the stolen parts in Oregon, I'm guessing it will lead to a black market industry there, where people launder stolen phone parts into refurbished phones by mixing them with parts from broken phones.
IF their goal was merely to prevent theft, they could achieve that goal by simply blacklisting individual components when a device is reported stolen. Apple knows precise serial numbers of every paired component installed in that device, they just need to host a database of stolen parts that devices could query on every boot and on a set interval.
Of course, that's not their true goal, so they treat everyone like thieves in the hopes that they buy a new device instead.
Of course since this process needs to access networking stack etc it's going to be trivial to bypass if the device is jailbroken. Which means that users buying stolen phones need to be informed not to upgrade the OS otherwise their device is bricked. E-waste implications would be staggering.
If the device is jailbroken then all bets are off regardless? If you can bypass the theft database check, you can bypass the current parts pairing check, too.
> E-waste implications would be staggering.
Is that meant to support your argument? That's the status quo.
And you can't bypass the current pairing check since it is happening before the OS is launched.
Extremely relevant: https://xkcd.com/538/
They'll just use a 0-day exploit or a $5 wrench.
You will never guess what California requires to be inscribed on every converter sold in the state.
WARNING: This product can expose you to chemicals including arsenic, which is known to the State of California to cause cancer. For more information, go to www.P65Warnings.ca.gov
https://www.ifixit.com/News/91648/banning-parts-pairing-wont...
If Apple disagrees with iFixit and has genuine reasons to believe this will compromise security, they can share their reasoning publicly and let people judge. So far I don't think they have.
A shady shop buys a box of broken, non-activation-locked phones, and a box of stolen, working, but activation-locked phones.
They install parts from box two on mainboards from box one. This completely defeats activation locks and cell modem blacklisting.
The same thing is commonly done for other high-value products. It is what automotive chop shops do (there, a wrecked car with a clean vin + stolen car with dirty vin is turned into a sellable car with a clean vin).
> It is what automotive chop shops do
If you think this is about iPhone chop-shops, you have lost the script. Apple designed this scheme from the bottom-up, if they wanted you to have control over your phone they would have left an escape-hatch. When someone locks your door and doesn't give you the key, it's always worth asking: Cui bono?
- Require authentication including a second factor to initiate and confirm the removal
Assuming a mugger isn't likely to sit there for 30 minutes given the chance someone could walk by. If this is the only way to remove the part such that it can be paired with another device, doesn't it solve both problems? I get the feeling Apple is being a bit disingenuous with their "risk to consumers" claims.
Anyway, no, the mugger isn't going to try to unlock it while holding you at gun point. They'll rip and run, and sell it for $20 to a fence who will pass it up the chain. Usually they end up in other countries.
Similar in concept to the groups that will take cars stolen in the US, grind off all the VIN plates and other identifying marks, fake paperwork, and then sell them into markets in Africa and the Middle East where the buyers don't ask questions, and government officials are easily and publically bribed.
How feasible would it be to tighten up port security to stop the export of stolen cars?
Are there any other risks?
[1]: https://news.ycombinator.com/item?id=39707586 (in reply to you)
Apples approach has often been at a module level: replace the logic board, replace the battery, etc. Board repair houses often operate at the component level: replace a damaged chip.
In the case of the latter, access to schematics and board layout makes this possible, and I’m sure Apple (and everyone else) has zero interest in making these available. Likewise with custom parts. Modules, but not chips.
With a VERY liberal view of "module". I had an MBA with a damaged battery charging circuit. Battery was fine. Computer was fine on AC. Just couldn't get current to battery. Oh, okay, few hundred bucks?
"The estimate to repair is $850..."
Followed rapidly, "Do you want to take a look at the new MBAs and maybe we look at you getting into something upgraded instead?"
One, video game consoles have no pretense to being generalized computing devices. They are more similar to appliances, and while that appliance status is arguable, they are definitely closer to that right now than smartphones.
Two, people have nostalgia for video game consoles. They like the packaged nature of it and generally have more good will towards console manufacturers than computer manufacturers (although that part is arguable and may be changing).
Three is politics. It's already hard enough to go up against companies like Apple to get these bills passed. You do not want Microsoft, Sony and Nintendo lining up to oppose you as well.
With all that said though, there is no reason I can see that the arguments used for right to repair -- that users should have full control over the devices they own -- should not also apply to video game consoles. But doing so would mean that consoles are no different than PCs, and would have huge implications for the industry.
Those lines are being blurred already with things like the Steam Deck and I think we're just a few years away from that upheaval, but it hasn't quite happened yet -- hence you see these carve-outs.
edit: Upon rereading what I wrote I realize that I may be conflating right-to-repair with regulations around app stores and walled gardens. They're not exactly the same thing, but I do think they touch on the same issues of the meaning of ownership, which is what set me off.
I repair all of my other appliances, why should this particular type of appliance be any different?
Neurotransmitters signaling pain happen throughout our human population with these anti-consumer acts.
What I can't understand is: If a single human lobbied the government for a selfish cause, they would be an a-hole. Why is this different?
I'm all for an equal playing field, lets all go Realpolitik, everyone goes amoral. I just find it odd and a bit frustrating that corporations can commit immoral acts but humans cannot. I imagine this causes inequality.
We hold corporations in too high of regard and have intermingled what should be free and open exchange of money and goods with governmental power, lobbying.
Either the government is big and the corporations lobbies and gets undue influence over how society and it's laws operates though the government, or the government is small and the corporations get undue influence over how society and it's law operates though sheer unregulated societal power. The group who controls your means of getting food, shelter, medicine, and information will have power over your life, and will bend the rules to their advantage using that power.
You: "I found another job"
Boss: "What about loyalty? Are you a job hopper?"
You feel bad for some reason.
The morality we were taught in preschool largely serves the interests of the elite. Things like "if someone does you wrong, don't seek revenge, forgive them" are really helpful messages to have ingrained in society when you are a corporate looter with a name and a address.
Search for Apple and Right to Repair as keywords and see for yourself. Add Louis Rossmann to the mix and you can’t miss it.
One reason why lobbying is allowed in the first place is to let corporations express what is good and bad for them and have their interests in the balance. The assumption is what's good for corporations increases the overall market and benefits society.
Doubting that assumption is probably out of the current overtone window[edited]
You have to remember that tons of people have near zero tech awareness, and regardless of the laws, will just bring their iPhone to the Apple store if it breaks. The same way people still go to dealers to fix their car, even out of warranty.
This means Apple can say "Hey, give us full control of your phone repairs, and we can kill the theft market for iPhones. You are going to come to us anyway, so might as well let us end iPhone theft too"
So this is why lawmakers still sit down with Apple. And the generous lunches.
(Apple DRM'ing all the internal hardware does effectively make stolen iphones completely worthless, in whole or in parts.)
-For the record, I have personally written my senator before asking him to support right to repair laws.
And no, making it somewhat easy to check whether a phone is locked down wouldn’t help. Thieves and robbers won’t spend even a second to do that check while still near the crime scene. It would have to be absolutely obvious (say by having orange and black devices) for thieves to not steal the locked-down ones.
This claim, or to be more specific, the claim that this reduces theft, is missing evidence. Are iPhones really being stolen at a substantially lower rate than other brands, correlating with implementation of these locks?
They actually tried to extort $300 from me to get it back which I of course would not pay, but maybe there's still a market in that for some people?
I doubt they got any money for it, so it’s probably resting at the bottom of the Hudson River now.
It was especially frustrating for me because I was unemployed at the time, and really didn't want to be spending $700 of dollars on a new phone, so for a brief moment I will admit that I did consider paying the $300 if I had a way to guarantee that they'd actually give it back, but it didn't last long.
I have to say, this sounds trivially false, and I don't think I'm nitpicking.
Lawmakers sit down with Apple because Apple has an enormous amount of money and power.
After some of these lawmakers sit down for lunch with the lobbyist, perhaps they make the assessment that what Apple is asking for is still doable/ethical/practical/etc.
Edit: clarification
Nobody, not even Tim Cook, considers themselves the Bad Guy. The real world doesn’t work like that. This situation is certainly more nuanced than you’re making it out to be. If you’ve been part of basically any discussion about this topic, you’d see that there are multiple sides. Starting from a position of “my preconceived view is correct and no other view exists” is intellectually dishonest and wilful ignorance.
Would you consider this to be true if the government was on the wrong side of an issue?
Say politicians wanted to pass a law that every internet search query needed to reviewed and approved by a human before search results could be displayed. Would it be "measurably immoral" for Google to lobby against this law?
I love this formulation
Maybe there were good intentions in the beginning and path was truly a good one, but not for a nanosecond do I believe they really made it 100%. Phone is simply not a secure device, doesn't matter who manufactures it, period. Neither are all the networks used to connect anywhere.
If all this lowers theft its a good strategy overall, but with terrible misguided marketing.
If this had anything to do with theft, Apple would only blacklist parts which were inside the device at the time of theft, and otherwise provide "pairing" tools for free.
Or maybe not enough? Several philosophical frameworks are perfectly compatible with Apple doing legal things to benefit themselves and their customers.
The other day, a volume button on my bluetooth speaker stopped working and I could tell it was damaged so I opened it up and found the circuit board supporting the button was snapped. When I initially approached the manufacturer for a warranty, they declined because they assumed I had taken the device to a non-approved repair shop, which would void the warranty. When I explained, no I'm the owner (here's the receipt), and I opened it up to check for damage, then they fulfilled the warranty no problem.
In other words, do nothing of any impact.
What is great is that the repair was done in front of me while I waited. I didn't have to upgrade my OS or backup my data (though I did).
It was fast and inexpensive.
But... The automatic screen brightness no longer works. I have to manually adjust the brightness (which is sometimes challenging with dim screen in bright sunlight)
I think the ambient light sensor must be calibrated, and only by apple.
wonder if it can be fixed in oregon?
I support right to repair in general, and I’m not particularly opposed to this bill, but it seems a bit hopeless in the long run.
Manufacturers try to pretend that they are pro repair but very few are really.
Consumers just want easy repair/replace when it happens, and the more resilient the product the less they care.
Some more discussion last week: https://news.ycombinator.com/item?id=39606952
Still using an iPhone though - it is a bit crazy how expensive these have gotten and how repairs can be so expensive.
I agree that consumers are the real problem but government intervention provides a much needed safety net to keep these oligopolistic practices at bay while users slowly figure out why right to repair matters.
We should be happy for any and all help we can get on this front.
Thing is, it is not just Oregon. Massachusetts, Colorado, New York, Minnesota, Maine and California all have right to repair laws. It is not possible for companies to remain competitive and not sell in those states.
Nobody wants to build on your platform if you're a tyrant.
[citation needed]
In practice, I think people mostly follow the money and idealism barely factors into it.