Remix.run Logo
p0lychromatic 3 hours ago

I know people here do not want to hear it, but it is a very two-sided sword.

Of course root allows you to tinker with your device and make it run what you want, but:

- Rooted devices make devices unpredictable. As shown in the video: How do you trust that your hotel/AirBnB is not using root on _their_ TV to use its microphone to spy on you? Or actually records your video output (instead of "just" ACRing it)?

- Re-selling: How do you know that TV you bought is untampered? How do you know it does not have software with malware installed that steals your credentials?

sdcfgy 4 minutes ago | parent | next [-]

All of those things are: you don’t.

If it’s a problem, unplug it.

If it’s a problem, don’t buy it.

Works for everything!

cryptonym 2 hours ago | parent | prev | next [-]

With an on premise device, the game is already lost. They may plant a separate mic device inside the TV, or elsewhere. Rooted TV doesn't really impact BnB security model.

like_any_other 2 hours ago | parent | prev | next [-]

> How do you know that TV you bought is untampered?

Many rooted devices display during boot a warning that they have been rooted. This is a problem that has been solved for more than a decade, but manufacturers pretend not to know the solution, because they are actively hostile to user freedom.

> How do you trust that your hotel/AirBnB is not using root on _their_ TV to use its microphone to spy on you? Or actually records your video output (instead of "just" ACRing it)?

Let's pretend there aren't plenty other ways they could spy on you. If it's bad if a hotel does it, why is it okay if LG does it? Do you honestly trust LG, and the thousands of "partners" that they sell your data to, and every government whose warrants they have to honor?

Your argument reduces to "if the warden lets us out of our jail cells, who will make sure we behave?"

p0lychromatic 40 minutes ago | parent [-]

> Many rooted devices display during boot a warning that they have been rooted.

Usually, this happens after a bootloader unlock because then verified boot is disabled. You can still have a rooted device and not break verified, resulting in no warning. See: jailbroken iPhones.

I wouldn't say it's a solved problem. Just have to find an exploit that works with verified / attested boot.

And device manufactures are getting more and more restrictive here, too. Why do you think that is?

> Let's pretend there aren't plenty other ways they could spy on you.

Sure, of course there are other ways to spy on people. But as we see here: If the device itself does it, then we like to blame LG. If they used an exploit to do that, then we blame LG's shitty security.

If a hotel owner installed a microphone inside one or their specific TVs, then we blame the hotel owner at least - not LG.

> If it's bad if a hotel does it, why is it okay if LG does it?

It doesn't seem like it is okay. We are discussing this right here.

> Do you honestly trust LG, and the thousands of "partners" that they sell your data to, and every government whose warrants they have to honor?

Do I trust LG more than a shady hotel / BnB owner or eBay seller? Yes. Do I trust them fully? No. It's not fully binary, I'd say.

> Your argument reduces to "if the warden lets us out of our jail cells, who will make sure we behave?"

I am just trying to say, it's really not that binary. You can extend that to other places whenever attestation is involved.

Do I like Linux and open platforms? Sure! Tampering is fun! Do I hate people using open platforms to scrape my websites and constantly cause load, steal my content and use that for AI training? Also, yes.

But how can I fight that? We run into CAPTCHAs, Cloudflare, Anubis and co. Now that issue is reduced, but the openness is also gone.

And you always see in tech spaces we rather want "dumb" devices rather than smart devices, because we cannot trust them.

Attestation buys you more trust, but at the cost of openness.

sersi 11 minutes ago | parent [-]

> I wouldn't say it's a solved problem. Just have to find an exploit that works with verified / attested boot

In general though on devices that are rootable, white-hat hackers are more inclined to responsibly disclose vulnerabilities instead of releasing them as a way to root said device. So having a rootable phone does increase security.

What doesn't increase security is when bank apps that are essential to daily life start detecting that a device has been rooted and force a lot of people into using closed source extensions to hide the fact that the devices is rooted.

armadyl 2 hours ago | parent | prev [-]

Honestly in a lot of cases people here are too ideologically blinded to see the logic that you’re laying out. It’s the same mental gymnastics that let many here praise something like GrapheneOS yet turn around and screech over it not allowing root which is nearly central to its entire security architecture.

But in this case… I don’t know. The OEM is so actively hostile you might be better off just taking the risk with root if you must purchase it at all (and physically removing the radio/microphone hardware not being an option).

mort96 2 hours ago | parent [-]

Wait who are these people who praise GrapheneOS but complain about it not allowing root? It sounds like you're conflating two groups of people