Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not even mentioning the hardware bits, I have been collaborating with postmarketOS for a while now, and believe that the main thing we need to make those devices longer-lasting would be an unlockable bootloader by law.

This sounds so logical (why cannot I run, by voiding the warranty, any code I want on my machine, whatever it is?), yet apparently so hard to make openly illegal, since the problem is barely acknowledged in general.



User-replaceable batteries by law might be a better first step. Heck, maybe even some standard sizes for mobile device batteries (and while we're at it, also EV batteries... some sort of standard 'battery module' used by most/all vehicles would hugely help reuse/repair/recycling/upgrades).


User-replaceable has nothing whatsoever to do with right to repair.

Zero, zip, nada.

A right to repair law might mandate that any device with a battery also have the battery sold, by the manufacturer, for a reasonable period of time. That gives you a practical right to repair the device by replacing the battery, and it's well-defined.

"User replaceable" is not well defined. Does it mean you need to be able to do this with no tools at all? If not, what tools make it not 'user replaceable'? That no glue is used? Solder?

My watch is literally a cell phone, and I don't welcome law which might make it bulkier or more awkward, to mollify people who want a plastic hinge to pop out their smartphone battery and swap in a new one in the field.

The battery in my smartphone (and watch!) can be replaced by the manufacturer. Right-to-repair is about making sure that the owner of a device can do things themselves or from a third party, without licensing from the manufacturer: so selling consumable parts to all comers, providing some manuals maybe. It is not about whether you have the manual dexterity or special tooling to perform the replacement! If you want to optimize around that part being very easy, buy a product where it is, like the Dragonbox Pyra.


But there's not much point having the right to repair if products are designed to be non-repairable and spare parts are unavailable.

A battery is a consumable and should be user-replaceable. It might be a bit fiddly, with tiny screws and fragile connectors, but shouldn't require heat guns and chemicals to remove adhesives...

(And if we're about to replace billions of vehicles with EVs, perhaps consuming the entire planet's supply of lithium, we should be thinking very carefully about how those batteries will be constructed, replaced, reused, recycled - and ensuring that we don't let capitalism create EVs that after a few years are almost as disposable as few-year-old iPhones...)


Louis Rossman has a distinction about this - the difference between right to repair and user-replacable. I can't find the video but the argument is this:

Louis does not want to impede on Apple's ability to make devices smaller or more compact, as that is what the vast majority of customers prefer. Louis, as an independent repairman, has spent 10s of thousands of dollars on the appropriate tools to repair these devices at an incredibly small scale. The problem comes when he needs to buy a replacement part he is physically unable to get the part. Apple, in some cases, will forbid the supplier from selling the part to anyone but Apple.

It's not a question of difficulty. Louis is equipped with every tool and all the time of the world, but Apple is directly impeding his ability to repair customer devices by refusing him access to the parts. That is in large part what his bill aims to change - not to force Apple to go back to 90s style clip on batteries.


> Louis does not want to impede on Apple's ability to make devices smaller or more compact, as that is what the vast majority of customers prefer.

The vast majority of apple customers have Stockholm syndrome, or at least don't know what they're missing.

The first gen MacBook pro had a battery that just popped out and could be replaced. It extended the life of the computer, and was practical because you could carry an extra battery for long trips. You could say their customer wanted to lose the battery, but I doubt that's true. More likely, people who dislike the user hostile design stop being customers.


> But there's not much point having the right to repair if products are designed to be non-repairable and spare parts are unavailable.

There is some nuance you are missing here. Mandating some design decisions, such as "user replaceable batteries" limits the products that make be made and sold and unfairly adversely affects users with different priorities (such as water proofness, durability or bulk.)

However, there are design decisions that we should outlaw because they impose an unreasonable burden on repairability. I think it is reasonable to prohibit companies from attempting to detect non-OEM or refurbished components and bricking devices. I think it is also reasonable to prohibit companies from usong IP laws to legally attack refurbished component suppliers and third party repair services.

I think pressure to make devices more repairable could he accomplished by mandatinf inclusion of standardized repairabilitu scores so the consumera have better information available when making purchasinf decisions.


off topic: interesting that your last sentence has 4 off-by-one-to-the-left (on qwerty) typos on final letters of the words

I think these were just typos, but my initial assumption was that a cipher was embedded in this text for a minute.


Hah, nope. Just fat thumbs and poor proofreading.


Fiddly doesn't cover devices that need to be environmentally sealed. People want devices that can survive a drop into water or even devices designed to be submerged. Making a device with environmentally sealed, and having hatches, covers, etc., is very difficult. Without making the product really bulky.

My guess is people just want to be able to take their device to a repair shop and have the battery replaced.

My biggest gripe is that you cannot find OEM batteries from the manufacturer. The batteries I have replaced (through some effort) have been generally a disappointment. Particularly laptop batteries. The replacement market for laptop batteries is a scam.


An extreme example of this would be the CPU - should it be repairable as well? What if the SRAM cache needs to be replaced? Should they be forced to backtrack and make that a slotted component in the next generation of motherboards, costing performance for user repairability? Or is the list of components arbitrarily determined by some administration-appointed regulatory agency?


This is taking it to an absurd extreme though, which is not really how laws work. We would be better off with a right to repair on some sort of reasonable macro scale and letting a few court cases figure out where the line is, because its definitely not nano scale chip features.


My point is that no congresspeople would sign off on a law that would stifle innovation to such a degree. Customers should be given the tools to make better decisions regarding the repairability of products if they so choose to factor that into their purchasing decision, but if it means outright stopping purely positive improvements like faster CPUs then it's both harmful to consumers and not a law that would pass congress.

A lesser extreme is the southbridge/northbridge and how CPUs are becoming SoCs. If that fails, you pretty much have to buy a new CPU, when previously you could technically replace it if you wanted. Would have such a version of the R2R law prevented this?


A reasonable compromise would probably be to require that discrete parts be available for sale, hopefully with some reasonable price standard, not requiring that devices be designed to have more parts. If it's economical for the manufacturer to move to a SoC, fine. They should at least let people buy them. Any R2R law should incentivizes manufacturers not to make disposable unrepairable products, because business is about making money, generally opposed to acting responsibly in the best interests of the public and the world. Again, opinion.


The R2R proposals, at least in the form that Louis Rossmann is pushing for, doesn't prevent anybody from making hard to repair or non-repairable products. Nor does it require companies to make trade secrets publicly available. As far as I know, it doesn't even force companies into creating any documentation that enables a third party to repair their products.

There is obviously that "loophole" where a company can still deliberately make a product difficult or impossible to repair just by virtue of that product's design. However, if the law is implemented, any covered devices that can be repaired, regardless of how hard it is to repair, will be repairable by third parties without having to deal with legal gray areas just to be able to acquire tools, parts, and information that they will need to do those repairs.


User-replaceable battery means that entire product categories like wireless earbuds e.g. Airpods cannot exist.

A better solution is that the manufacturer must provide battery replacement services at a cost specified at the time of purchase and only allowed to increase at the rate of inflation.


> User-replaceable battery means that entire product categories like wireless earbuds e.g. Airpods cannot exist.

Acceptable, why turn an entire device into ewaste for a single component dying, especially one with a known limited service life, like a battery.

10 year warranties minimum on all electronics. Regardless of size and fragility. Any electronic device that can't last 10 years in service is unnecessarily contributing to ewaste and should not be allowed.

User replaceable batteries to avoid using battery life decay as a means to drive sells of "new" versions, something that causes e-waste.

To be honest, don't stop at batteries. Any component in a device that can not last 10 years while retaining atleast 75% of its "ability" must be user serviceable, no exceptions.

User serviceable is defined as any service a user can perform where the OEM will replace the device at no charge (not even shipping) if the device breaks during or because of the user servicing it during normal warranty.

Replacing a device under warranty resets the 10 year timer. To discourage OEMs halfassing it for 5 years and hoping for low warranty claims.

We can not allow companies to treat the earth like a garbage can.


The amount of ewaste in something tiny like a pair of Airpods is... tiny. Because they are physically small.

Probably Airpods thrown away every 2 years for 50 years is less ewaste than a single laptop, and those don't last 50 years.

So does banning Airpod-like devices really make sense as a policy to minimise total ewaste?


So basically, drive the cost of all products up to the point that only rich people can afford them, and disenfranchise an entire slice of the population.

If you want to have the ability to purchase ten year warrantied devices, that is a separate issue. And no one, no one, is going to 'reset' your ten year warranty at the time of repair/replacement. Never going to happen.


Wealth inequality existing is not a valid reason to pollute the earth with disposable products, and both issues can be tackled simultaneously.


How long do the batteries in those things last? If it makes it to 2 years then they're doing much better than any of my wired ear buds where the wire's or contacts usually break and are probably responsible for less waste.


Mine are about four years old, I got them not long after they came out. I’ve upgraded my iPhone but I’m still using the AirPods. Battery capacity is probably about 60% of new.

They’re easily the longest lasting in ear headphones I’ve used.


Thank you for demonstrating why smartphones and computers should be exempt from the right to repair


It would take some legislative creativity but why not put in some exceptions for tiny, or waterproof products etc. There are always exceptions in the real world. I fix all my phones but am fully willing to accept that I might not be able to cleanly install a gasket like the factory and lose some protection after I open it.


Creating an agency to flexibly interpret the laws thru regulations is the typical solution for legislative creativity.


'Cannot exist' or 'must be just a little bit bulkier'?


I miss my bulky motorola cell phone that weighed less and had decent plastic because weight and glass became luxurious.


Specify a minimum 'size' of battery that must be replaceable. Size might be physical dimensions but I have don't know enough to specify a meaningful metric.


There definitely ways it could work.


User replaceable means you can replace it during warranty and have the OEM repair/replace it if you broke anything while replacing it.


Um, user replaceable means just that -- the user can replace it, nothing of warranty and nothing about an OEM replacing if you broke something while replacing it.


Since the battery is just glued in instead of having a special vendor specific fitting, one could argue that they are easier to replace since you only need to supply the correct voltage.

Of course some vendors didn't like that and put chips on their batteries.


… that’s unique r&d for some companies. Why does it need to be standardised?

Apple batteries are typically much smaller than what is in androids, because their chips are less power hungry… same goes for Tesla, their cars are more efficient… so standard battery packs would harm their overall product

Don’t buy a device with a non replaceable battery if you don’t want one… why do you need the government for that?


In the US, at least, unlocking devices is legal as of 2015(?) through DMCA exemptions, which has been huge for recyclers and refurbishers.

Still couldn't get game console unlocking through, but at least phones / tablets / other devices that are locked can be unlocked and resold.

https://resource-recycling.com/e-scrap/2018/11/01/digital-de...


The DMCA exception only means that the manufacturer can't sue you for unlocking a device they meant to be unlockable. So, of you find a way to do it, it is not a crime to hack a device you own.

Right to repair laws are (would be) a whole different beast, it would mean the manufacturer would have to sell the devices unlocked or provide the unlock method themselves.

In other words, DMCA exception removes a legal hurdle for repeatability, but Right to Repair legislation would remove the technical hurdles (and some other legal hurdles).


Whoa there, that's stretching 'right to repair' particularly because everyone has a different opinion about what it should affect and how far it should extend. For example, Louis Rossmann's right to repair direct ballot initiative only focuses on repairing the hardware since that has a much higher chance of actually passing with support from both parties in congress, and doesn't actually jeopardize the fabric of entire markets like the game console market.


It's meaningless if hackers can't bypass the security, which is true more and more as the companies get better with their security. What we need is bootloader unlocking provided by the manufacturers.


How was it that the US version of the Note 9 (with a Qualcomm SoC) had a locked bootloader while the EU version (with an Exynos SoC) had an unlocked one? Is that still the case?


These exemptions have to be renewed every 3 years. The 2018 exemptions for "jailbreaking" phones and tablets are still in force, but they will expire if not renewed.


This was changed in the last cycle or so so if there aren't people challenging petitions they get semi-automatic renewals. Honestly, for unlocking bootloaders (note I initially wrote this comment in the mental context of carrier unlocks and then immediately went and edited it as I realized) we probably never needed the exemptions anyway, as there is a standing exempting for interop (which still does most of the work: the argument for the extra exemption is to provide one last step for the end-user as in 2009 it wasn't clear they could run the result, but currently everyone things they should be).


There's work happening to make these permanent. [1] Until that happens, there are tireless volunteers and organizations lobbying for these exemptions every 3 years.

[1] - https://www.ipwatchdog.com/2020/06/29/copyright-office-begin...


Isn't the article you linked referring to carrier unlocking? Because there are indeed laws regulating that (i.e., stating that after 2 years from the purchase all phones must be unlockable, or stuff like that), but in that case it's just a matter of having the modem run on all carriers IIRC.


There are loopholes.

I have a stack of smartphones I bought for 15$ but cannot legally unlock because I haven't paid simple mobile for a year of service on each. They're still fun and useful but not fully.


You can't do that because someone (probably not you) will then unlock the phone and [insert something evil here - perhaps involving the radio]


The radio firmware is something that is at another level. Even if you end up unlocking the bootloader, that doesn't give you access to the radio firmware, that is proprietary and needs to be signed, and cannot be modified. It's basically seen by the OS as a modem to which they talk trough AT commands (yes, they are still in use), the same thing that you would obtain by plugging in an USB modem to a normal PC.

For Wi-Fi you can tweak the driver, if you want. But you can do the same with a network card that you buy for a couple of dollars so what's the point? Transmitting on the 2.4Ghz is something everyone can do if he wants.

It's nonsense what you said. There nothing evil you can do by unlocking a phone. In Android an unlock triggers a factory reset, that will prevent accessing people personal data (and it's not really necessary if you have disk encryption, that every modern phone has as a default), so the concern of accessing people data doesn't exist.

The concern about: but then a criminal can steal your phone and use it. Yes, there is. We can require to unlock the phone requesting a code from a website of the manufacturer so they can prove that you bought the phone, as some manufacturers do. But in reality, does it make sense? You can nowaday get a phone that is more powerful than the PC that I used 5 years ago for 200$, I mean 8 core CPU, 8Gb of RAM, 256Gb internal flash, in the following years the price will probably go even lower. Should I care? They only thing that I care is that whoever stoles the phone cannot access my personal data, and this is achieved by the disk encryption, everything else to me is useless, I would just buy another phone, but in reality is more probable that I will loose or break my phone that someone steals it.


> The radio firmware is something that is at another level. Even if you end up unlocking the bootloader, that doesn't give you access to the radio firmware, that is proprietary and needs to be signed, and cannot be modified. It's basically seen by the OS as a modem to which they talk trough AT commands (yes, they are still in use), the same thing that you would obtain by plugging in an USB modem to a normal PC.

Who's to say this? What if i'm Apple and my ''partner'' radio chip manufacturer (cough qualcomm cough) doesn't give me access to changing the bootloader? Why wouldn't 'forced unlocked bootloader' also apply to Apple-owned devices?


This is not always true. There are chips where the radio DSP cores have their program loaded into main memory and it's unsigned. You talk to them with mutexes and shared memory pages. There is also no legal basis for requiring radio controllers to have signature enforced firmware loading.

He's being sarcastic. It's think of the children but with electronics and PII.


There is also no legal basis for requiring radio controllers to have signature enforced firmware loading.

If someone actually tried to write their own radio firmware and made a mistake, there very soon would be.

Messing around with radio transmission is not a game. Make enough noise on the wrong frequency and now you're interfering with communications for emergency services responding to a disaster or air traffic control guiding flights in crowded airspace, with a very real danger of loss of life. And there is no way for anyone to stop you until they've physically tracked down the source of the bad transmission, which can take hours.

I am very much in favour of rights to repair and against almost any restriction on what individuals can do with their own hardware, but giving people who don't know what they're doing unrestricted access to a radio transmitter on that basis is a bit like giving everyone in your city a button that detonates the nuke because you believe in a right to bear arms. At some point, you need to draw a line and say only qualified people past this point, or very bad things start to happen.


People can buy software defined radios and effectively already have that access.


Note that for engines the EPA has been cracking down on all the mods that bypass software emission controls. The fines (though rare from what I know) have been large to small scale people selling such things. You can probably still make/mod your own engine by yourself, but if you sell and engine mod software you better meet emissions - I suspect that they will crack down on "free" open source mods as well which will kill collaboration (unless those involved are extremely careful to meet emission standards).

The FCC hasn't cracked down - yet. As other have pointed out that is probably because they don't see a widespread problem and so the politics aren't worth it. I'm sure someone reading this is involved with radio, I hope they take the warning (I believe their response will be a form of we already know)


Indeed. Not a lot of people are interested enough to experiment with radio transmission and fortunately the ones who are tend to be keen hobbyists who understand how the systems work and take care not to break things for everyone else.

The kinds of outage that can be caused by rogue transmitters are rare. Often it's a hardware failure that is to blame when they do happen. Hardware failures are also rare but when you might have millions of transmitters within a small city, sometimes you discover that rare is not the same as never!

There is always the possibility of malicious or negligent interference if an operator has the ability to modify their transmitter's behaviour sufficiently though. I would personally be OK with limiting the sale or use of equipment with those capabilities to only people who have shown they are competent, for much the same reasons that I am personally OK with restricting the use of cars to people who have passed a test. It obviously doesn't prevent all failures but it certainly lowers the risk of failures that could endanger many other people.


People do this all the time with routers. The FCC has been trying to require firmware signing but it has been pushed off for now because there is very little demonstrable harm.

I can go buy a bunch of passives off of ebay and make a noisy oscillator that will kill everything for a couple blocks but nobody seems to do it.


I have seen the "very little demonstrable harm" you mentioned with my own eyes in real time. It was little more than serendipity that saved lives that day. If someone did do what you described then IMHO they would be recklessly endangering the lives of others and should be treated accordingly.


This isn't a tenable argument for two reasons:

1. How far off the bell curve do we need to go? Do we trade all rights to do anything for diminishing returns in safety?

2. These modifications are happening right now. Bad instances are usually caught by EMS system tests or by people reporting gaps in cell coverage, etc, and are generally purpose build jammers. There are not many instances of frequency overlap. For most goods, especially consumer telecommunications equipment, other bands are protected by the fact the equipment is given a specific range to operate in anyway.


I am having difficulty working out what your position is here. Before you were talking about taking out multi block areas. Now you're talking about consumer equipment that is prevented from interfering with other frequencies. I was objecting to the former -- wherever you choose to draw your line, clearly interfering with safety-critical communications over a wide area should be well past it. The latter is a prudent step for mass market consumer goods.


What proof do you have? If you can't give a specific example, your argument might as well be corporate PR.


You're new here, so I will gently point out that this isn't Reddit and it certainly isn't Slashdot. Asking everyone for proof of everything or implying that they are shilling is boring and unconstructive.

I've been on HN for more than a decade. You can check my comment history to see that I contribute sensibly. I have no reason to make anything about this up, but I'm obviously not going to doxx myself by providing the kind of proof that would be convincing. You're free to take me at my word or to disbelieve me, but if you aren't interested in substantial discussion in good faith, please consider simply ignoring a comment and moving on to something that interests you more.


I'm just interested in substantial discussion by wanting to know what exactly happened with modification of some radio device.


OK. You might like to consider adopting a less confrontational tone when commenting on HN in that case, as it generally doesn't go down well here.

The answer to your question is that I once spent some time working with a network operator and on a day when I happened to be around their operations centre there was an active incident like this.

If memory serves, it turned out that the rogue device was a relatively new model that a customer had bought and was trying to use normally but something wasn't reliably operating within spec. That model would have had to pass certification to be permitted on the network but apparently this specific unit had drifted and as a result it was dumping bad data all over a control channel that was in use across a large geographical area, causing severe disruption to connectivity for everyone.

At that time some safety-critical services were using this network for communications in the field so this kind of outage was a very big deal. There were multiple vehicles with detection equipment on the road, systematically trying to narrow down the source of the interference, but of course they had trouble coordinating with the operations centre themselves because of the same disruption. I don't know everything that was going on, but I did learn that in my country there is a legal power to gain access to premises in this kind of situation and it sounded like the required formalities and officials were being arranged just in case.

As I recall, it took most of an afternoon to track down the source of the interference and get it switched off. In the end it was mostly dumb luck that it was found. I didn't quite follow what happened but possibly a detection vehicle that was out of contact with the operations centre had decided to patrol in its area until it could find another way to call in and while it was doing that it drove right past the building where the rogue unit was located and its detection equipment lit up like a Christmas tree.

The customer was entirely innocent and had no idea it was their unit causing all the trouble nor any reason they should have known. I don't know exactly what happened to that model, the manufacturer or the certification process it had managed to pass despite the defect. For sure there were serious repercussions.

This all happened some time ago and the protocols and networks have since changed but the physics hasn't. That's why I have such strong views about regulation and only allowing people who know what they're doing to have full control over transmission equipment. As the above incident shows, things can still go badly wrong even without that. If there had been a major incident requiring coordination between first responders in the field during that downtime it could have been disastrous. Minimising the risk of similar failures due to carelessness by someone who didn't fully understand their equipment and the systems and protocols they were working with just seems like common sense to me.


It sounds like the device was defective, not modified. This is a poor example for your assertion.


Which assertion is that? My contention since my very first comment has always been that messing around with radio transmission when you don't know what you're doing is dangerous. My anecdote was an illustration of what actually happened when incorrect transmission broke a system for real, how dangerous the situation became, and how difficult it was to fix.

Maybe you disagree but I think the fact that the cause of the incorrect transmission was a hardware fault in that particular anecdote is relevant only if we don't think a user with the ability to freely modify firmware as we were discussing could cause exactly the same effect either negligently or maliciously. Otherwise, the argument being made is merely that not many people actually modify firmware in dangerous ways, in which case I refer you to the nuclear analogy in my original comment.


The problem is, the kinds of problems caused by modification of the radio and a manufacturing mistake can be totally different and so things that you encountered you wouldn't see if someone simply modified it to operate on a different frequency. Therefore, your story which hinges on this difference not existing doesn't hold up.


Actually, if you had reconfigured a device badly and it had ended up signalling incorrectly on a network's control channel as a result, the situation I encountered is exactly what you would have seen on that day. Do you understand what a control channel is and why it is relevant here?


I'm thinking of if the radio had a component failure/missing and the wave it produced was either amplified or modified to be something like a square wave. It would be hard to do the latter with a simple software mod but easy with hardware.


That's not intentional modification, just bad quality control from the manufacturer.


The point is that exactly the same outcome could be caused by intentional modification. As I said in my reply to bluGill earlier, the goal is not to eliminate all risk of interference, but to reduce the risk as much as reasonably possible by controlling the potential sources where you can. Given that interference potentially causes catastrophic loss of life in this scenario, not to mention inconvenience to huge numbers of people, that seems like a good idea.

Put another way, you're not trying to prevent people who know what they're doing and follow robust processes from developing radio transmitters, even though in extreme cases such as my anecdote that might still not be enough to prevent a system failure. Nor can you realistically stop a sufficiently resourceful adversary from using radio interference as a form of attack. What you can do is stop an enthusiastic newbie who read an article about radio once from accidentally causing people to die because their experiment meant emergency responders at an incident down the street couldn't talk to each other except face to face.


You say all this as if the megacorps with signed firmware can't make mistakes.


Of course they can. But usually they don't, not for something like this.

I have been witness to the kind of search I mentioned. Usually it happens because of a freak hardware failure, not a malicious act or negligence. Unfortunately the innocence of all involved does not reduce the severity of the potential consequences. As I said, this stuff is not a game.


I don't think that is the case of any smartphone SOC. Even for questions about power management you tend to implement radio function with a dedicated hardware, so that for example the CPU can go to sleep and be waked up when a phone call arrives (for examaple). It would be too expensive to have the main CPU implement the 4G radio in software, they don't do so, it would also require precise timing that a non real time OS cannot provide.

Typically you have the modem that has its own microcontroller inside that runs its own firmware, that is encrypted. On Android phones you have a partition for the radio firmware, that you should really never touch (since doing so you can brick your device). Of course there will be a shared memory area between the radio and the main CPU to talk, but that is only for communication, then the radio microcontroller has its own RAM to implements its functions.


The MT6737 is a chip that works as I have described. The baseband is fully accessible. Even for other more common chips, like the Qualcomm ones, the AT command set is actually synthesized with shared memory as I detailed. These coprocessors are not microcontrollers, they are realtime application processors and may have MMUs.


Android phones triggers wipe on unlock. So use unlock bootloader to stole data simply don't work.

Besides that, some phone will add a unremovble giant red exclamation mark on boot screen to notate the phone being unlocked to warn you `the phone is already unlocked, don't trust it unless it is done by you.`


Would be nice if they provided a way to backup your phone before unlocking the bootloader, or at least put a warning that your phone is about to be wiped. I have personally lost data because of this, and there really is no way to backup an android device without having unlocked the bootloader first.


`adb backup` works with the bootloader locked. Unlock, wipe, then restore the backup. It's not perfect, but it gets most of the way there.

On the phones I've used (Pixel), there is a warning that unlocking will wipe all data.


"adb backup" doesn't work for apps that have opted out of backups, though.


Don't all modern phones encrypt user data on disk anyway?


The wipe on unlock thing is not about preventing others from getting your data, it's about preventing you from getting app data.


I though either way it true? There are some apps designed not to being backup without a trace. For example: some 2FA apps are designed to stay exactly on one machine for security reasons (They are meant to replace traditional 2fa device). Being backup easily compromises the requirements.


People start their phones rarely.


Are you missing an /s or are you saying that it shouldn't be done because it would enable e.g. use of radio hardware that goes against radio regulation?

If you're really expressing concern, what do you think of e.g. modem modules for regular computers or SDR hardware?


No, even if this is not the optimal response to the issue it's at least a popular concern to cite.

Our ubiquitous radio devices only work because the invisible commons that is the radio spectrum noise floor is aggressively and totally managed. Intentional emitters can only be sold after testing to ensure that their output is within regulated power levels and frequencies. It is trivial for an end user with a high-power transmit-capable SDR or amateur radio to unintentionally, unknowingly, and invisibly pollute this resource, denying nearby devices (scaled to your transmit power and depending on the frequency/bandwidth) the ability to communicate. This could be some noise on your neighbor's FM car radio, or it could be the communicators used by emergency services.

Honestly, I think radio spectrum management is one of the greatest success stories of the 20th century - if air or water pollution were as effectively regulated the world would be a very different place! To be clear, I don't think that smartphones with unlockable bootloaders, likely reusing the stock radio binary blob, are actually going to bring about the apocalypse and set us back to the telegraph era.

There was a process where Apple or Samsung or whoever brought that device with their bootloader to an expensive laboratory to get their CE mark, and that process proved that combination of hardware and software to be compliant with regulations. That process may have involved modifying some hardware filters and EMI shields, and almost certainly involved adjusting parameters in radio firmware/software, which are subsequently fixed for the lifetime of the product. If you give end users the ability to modify these parameters, you're inviting them to break the law. While enforcement is currently highly effective by requiring this certification process for OEMs, it wouldn't scale if you give everyone the ability to modify their certified emitters. You at least have to consider the possibility that someone could create a "High Power Radio" app or OS that would make smartphones running it have higher-power, faster access to cell towers and cause nearby devices to lose connection; no one wants that outcome.

Personally, I think the harm caused by preventing this through locked bootloaders and disposable smartphones is a tragedy. However, I don't know what a comparably effective alternative would look like, and the current state of affairs has both inertia and the backing of major institutions with strong conflicts of interest, and will continue to be very hard to advocate against.


> However, I don't know what a comparably effective alternative would look like

I don't know what the current state of affairs is with regards to radio modem firmware, but I would think that if radio-controlling software should be certified (as following regulation), that should be limited to the firmware, and the modem should only accept firmware updates cryptographically signed by the manufacturer (and possibly the regulator). The firmware should provide an interface that only permits legal use through technical means. IOW, regulation should be limited to the hardware module and the software running inside it. It shouldn't be possible for software residing on any other part of the device to run afoul.

If that's impossible for some reason (which I don't think it should be), then I would argue that other alternatives like focusing on prosecuting violations (like the app and OS you mentioned) or modifying the regulations so they can be contained within the firmware while still meeting goals should come before any idea of locking down whole devices for the regulation of a specific module.

Also,

> You at least have to consider the possibility that someone could create a "High Power Radio" app or OS that would ...

If that's possible then, it's possible now. I mean, you don't even have to consider phones. Bootloaders and OSes in regular computers are open source and unlocked. If that's a problem that can arise from unlocked devices, then it already would have been a problem since long ago.

Additionally, the discussion was not whether there should be unlocked devices, which there already are. The discussion was whether locking should be illegal.


I own a radio that I can turn to an illegal transmit power and has the ability to transmit on many forbidden channels... But I don't do it. Simple.


Yet people frequently aim laser pointers at aircraft.

If it ever seeped into the public consciousness how easy it is to disrupt RF communications, you can bet your callsign that some group of clowns would start doing it for their own amusement.


> Are you missing an /s or are you saying that it shouldn't be done because it would enable e.g. use of radio hardware that goes against radio regulation

Great question. I'm intentionally not answering it because I am not sure what I think. There are valid points on both sides. In part what I think depends on how evil evil people get.


AFAIK, anything phones can do on a hardware level can be done on more open platforms. What could unlocking phones enable evil people to do? What's one of these valid points of the other side?


Phones are ubiquitous. A phone sitting on a desk is invisible, in a way a random enclosure with a fire wires sticking out of it isn’t.


On the other hand, a Pi/ESP32/whatever shoved into a plastic case instantly becomes almost as inconspicuous once again.


A WiFi pineapple in a backpack is pretty innocuous


Or run it on an actual wifi router or usb stick in plain sight.


Im imagining kids watching "turn youe phone into a jammer prank your friends" videos... I still support full freedom though. The problem can be handled via prosecution of offenders.


However evil you expect people to be, someone will exceed it. That's why we can't have nice things.


Most phones secured bootloaders are hacked in less than 6 months if there is sufficient interest in the model. So if treatment of this as a huge security threat that makes other rights moot is valid then most of us should be able to return our improperly secured phones before their warranty is up.


Not the case, it takes significantly longer... if it happens at all.

Much longer. It took until 2019 for checkra1n to become a thing to unlock Apple A7 to A11 devices. Apple A11 is a 2017 SoC.

A12, A13, A14 remain uncracked today.

In Android lands, bootloaders starting from quite some years ago are quite solid too, with no bypasses except when the device maker provides you the possibility to unlock it.


None of which is relevant to the premise that someone is going to do [insert something evil here - perhaps involving the radio]. Because if any device is cracked after any period of time then someone wanting to do [insert something evil] will just buy that device in order to do it.


The radio is a completely separate sub system that is not affected by unlocking the boot loader of the main computer.


That's not always true. If it's possible to shave pennies off the BOM by having the radio driven by, or sharing memory with, the main CPU -- and it is possible -- there will be phones in the wild with that configuration.


Yes the radio can be on the same physical chip, but still they are two different systems. Unlocking the bootloader you get the ability to run an unsigned kernel on the main CPU, but still it doesn't give you access to the radio part, that has a completely different firmware (stored on a partition of the same flash memory, yes, but you see it as a black box) that is signed and checked and you cannot modify it. See it as the microcode of the CPU, something that is loaded at boot time but you cannot alter, patch, or even see what it does.

The kernel can only talk to the modem trough AT commands, the same commands that you would use with a 4G USB modem that you plug into any computer. The fact that are physically on the same SOC doesn't implicate nothing in terms of security.

In fact there are no security implication on unlocking a bootloader, if there were, well we would be in trouble since it's a relatively easy operation, that in most cases it's a matter of running a command from a CLI tool, and the only drawback is voiding the warranty.


There are very low cost devices such as those Allwinner or Mediatek produce that are more popular in non-US, non-EU markets that do not have the barriers you are describing.


While it is certainly possible, it isn't true for any modern phone with an app store.


Many SoCs let you burn a hash for the second stage bootloader. If your threat model includes this then build a copy of uboot that will only load kernels signed with your keys and burn the hash into the fuses of your device.


Make it require a connection to a computer and disallow the stock OS from running at all when the bootloader is unlocked. I think those two hurdles should be more than enough to satisfy security concerns.


[abuse children and drugs, or be racist.]


That are the current choices. That could change in the future, it has changed in the past. At one time not of the right Christian sect was in the list, today nobody cares - just one example that I won't get into trouble for mentioning.


This policy of smartphones has felt like a knife in my back for years.

I hope someday for the widespread return of real computers. Goodbye to consumer media/tracking nodes branded as computers.


Thank you for your work.

I absolutely agree with you on bootloader. I wanted to try PostmarketOS and found several Moto G4 play (well supported by pmOS) in the used market but alas Motorola has arbitrarily removed unlock codes for older devices from their website! Since Motorola was giving unlock codes by revoking warranty officially, there were no attempts to unlock it elsewhere and so all older Motorola phones which haven't been unlocked earlier are useless for any aftermarket use.

As for this law,

Considering repairability is the easiest and most accessible way to address e-waste and that phones, computers are a major contributor, There doesn't seem to be a rational explanation behind their exclusion other than briefcases exchanged courtesy of Trillion dollar fruit company.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: