Wow. Please stop spreading things like this.
Not having root means not owning a device you paid for and have in your home.
Wow. Please stop spreading things like this.
Not having root means not owning a device you paid for and have in your home.
Of course root allows you to tinker with your device and make it run what you want, but:
- Rooted devices make devices unpredictable. As shown in the video: How do you trust that your hotel/AirBnB is not using root on _their_ TV to use its microphone to spy on you? Or actually records your video output (instead of "just" ACRing it)?
- Re-selling: How do you know that TV you bought is untampered? How do you know it does not have software with malware installed that steals your credentials?
But in this case… I don’t know. The OEM is so actively hostile you might be better off just taking the risk with root if you must purchase it at all (and physically removing the radio/microphone hardware not being an option).
Many rooted devices display during boot a warning that they have been rooted. This is a problem that has been solved for more than a decade, but manufacturers pretend not to know the solution, because they are actively hostile to user freedom.
> How do you trust that your hotel/AirBnB is not using root on _their_ TV to use its microphone to spy on you? Or actually records your video output (instead of "just" ACRing it)?
Let's pretend there aren't plenty other ways they could spy on you. If it's bad if a hotel does it, why is it okay if LG does it? Do you honestly trust LG, and the thousands of "partners" that they sell your data to, and every government whose warrants they have to honor?
Your argument reduces to "if the warden lets us out of our jail cells, who will make sure we behave?"
Usually, this happens after a bootloader unlock because then verified boot is disabled. You can still have a rooted device and not break verified, resulting in no warning. See: jailbroken iPhones.
I wouldn't say it's a solved problem. Just have to find an exploit that works with verified / attested boot.
And device manufactures are getting more and more restrictive here, too. Why do you think that is?
> Let's pretend there aren't plenty other ways they could spy on you.
Sure, of course there are other ways to spy on people. But as we see here: If the device itself does it, then we like to blame LG. If they used an exploit to do that, then we blame LG's shitty security.
If a hotel owner installed a microphone inside one or their specific TVs, then we blame the hotel owner at least - not LG.
> If it's bad if a hotel does it, why is it okay if LG does it?
It doesn't seem like it is okay. We are discussing this right here.
> Do you honestly trust LG, and the thousands of "partners" that they sell your data to, and every government whose warrants they have to honor?
Do I trust LG more than a shady hotel / BnB owner or eBay seller? Yes. Do I trust them fully? No. It's not fully binary, I'd say.
> Your argument reduces to "if the warden lets us out of our jail cells, who will make sure we behave?"
I am just trying to say, it's really not that binary. You can extend that to other places whenever attestation is involved.
Do I like Linux and open platforms? Sure! Tampering is fun! Do I hate people using open platforms to scrape my websites and constantly cause load, steal my content and use that for AI training? Also, yes.
But how can I fight that? We run into CAPTCHAs, Cloudflare, Anubis and co. Now that issue is reduced, but the openness is also gone.
And you always see in tech spaces we rather want "dumb" devices rather than smart devices, because we cannot trust them.
Attestation buys you more trust, but at the cost of openness.
In general though on devices that are rootable, white-hat hackers are more inclined to responsibly disclose vulnerabilities instead of releasing them as a way to root said device. So having a rootable phone does increase security.
What doesn't increase security is when bank apps that are essential to daily life start detecting that a device has been rooted and force a lot of people into using closed source extensions to hide the fact that the devices is rooted.
> What doesn't increase security is when bank apps that are essential to daily life start detecting that a device has been rooted and force a lot of people into using closed source extensions to hide the fact that the devices is rooted.
I'll ask naively: Why not? I can come up with a bunch of arguments why it does help the bank and why it might reduce the risk of certain attacks.
If it’s a problem, unplug it.
If it’s a problem, don’t buy it.
Works for everything!
you/we/me not having root while, for example, Google Play Services does on invalidates everything you said.
Compared to, say, random Magisk modules or some random crap the OEM developed?
The inevitable outcome of this video is that TV vendors are pushed to harden the security and preserve the trust-chain, because part of the (valid) claim is that nefarious actors may break the security to use the device for spying on you.
With support from an actual journalist, it could be reframed to also emphasize the importance of controlled root-access to monitor and control the devices behavior.
But none of this was done unfortunately, and if I'm LG I don't want to see another video where someone reframes user-initiated voice-input for a web-search as spying initiative by showing some device-logs of the transcription process in parallel...
Like every single Microsoft laptop out there does so? Think a bit harder before sentences like this, please.
Did you read and comprehend the rest of my statement?
I'm trying one more time. I'm not arguing against you, maybe read this again in a few hours:
I believe you want to have full control over the device you own (like I do btw).
For this you need to acknowledge that right now it is not in the interest of any party to provide that, because it requires additional effort, carries additional risks and doesn't create an economical benefit.
You have to MAKE it the interest of ANY party in the chain (the manufacturer, the seller, the consumer, the lawmaker,...).
Being an angry consumer is not getting you there, asking people to "vote with your wallet" is not getting you there.
--> Why? Because you won't reach a critical-mass of consumers to move the needle for the manufacturer to notice and take action.
Creating noise on security issues and potential hacking won't get you there.
--> Why? Because IF it creates ANY reaction, the public reaction will be to hold device-manufacturers responsible, which (if it works!) will cause them to just spend more effort to lock down their products even more, secure the trust-chain in the OS and simply stop operation when it is broken at any point.
Trying a mix of topics by mangling everything together, to create as much noise as possible? It will not get you there.
--> Why? Because even if that noise is creating a critical-mass, if it's not based on a sober solid foundation with a clear demand, it is not actionable and will die down. Everyone knows that this will happen and affected parties will count on that.
So. What GETS you there is "artificially" making it the interest of the involved parties, STEERING the manufacturer into the desired direction.
How do you steer things if the sheer economics don't do it?
(I don't know your experience, so YMMV from here)
From my experience, the only sustainable way to achieve this is that you literally regulate it, by demanding a LEGAL requirement.
e.g. Pushing for regulation to provide the user full control over the product if he wants it, acknowledging that the process reduces the responsibilities of the manufacturer for that device.
You do that by finding as many reasons, as much evidence as possible that this is a solid direction: Security concerns, environmental concerns/waste elimination, "ensuring a free market",...
--
So how do I know that?
Because I LIVED through it already (with many other active people in the scene), trying to make bootloader-unlock and community OS a default thing on Android Smartphones.
We amplified the topic when the industry was still new and growing, created more noise than there actually was, riled up journalists to act like this is a crucial buying decision for the market, lobbied the whole industry, to a point that they actually made it a competitive feature.
Doing all that against a juggernaut of interests AGAINST it (in US e.g. Verizon, which never bulged, vendors with concerns about unjustified warranty-claims, journalists/users stating that this is weakening security, etc.)
And what happened? It all died down because we didn't use the momentum to get it into a regulation when there was the chance. Some fruit-company demonstrated over years time and again that this doesn't matter, then even turned it into a marketing-feature to NOT give full control to the user.
Meanwhile the momentum and interest in the market died down, and for the past years we started to lose bootloader-unlock again in many brands, without any notable impact on their sales.
So if we have to do it again, in a matured market (like TV is), how do we do it now?
Again, YMMV, but for me, having lived through that already, the only viable way is regulation.
Regulation which demands a solid trust-chain in control of the vendor, AND the possibility for the user to unlock it to take control over the device.
Anyway. Peace.
If you don't have root rights, you don't really own it. All other arguments are talking past this key point.