• 0 Posts
  • 246 Comments
Joined 2 years ago
cake
Cake day: July 11th, 2023

help-circle
  • If you change the bootloader to some other software, how could the software company be expected to provide support for something they may have no knowledge of?

    like xiaomi did, in the past at least. if you can reinstall the official software, you can receive service under warranty

    My point here is that I don’t think it’s reasonable to legally require a software company to

    phone manufacturers are hardware companies first and foremost






  • there is no way to verify the downloaded package before installation.

    also I generally deem both webusb, and chrome’s broader filesystem access apis dangerous, partly because a vulnerability in the website permission checking code with this permission is much worse than with e.g. the camera.
    but the more realirealistic problem is that its just too easy to grant a random website so deep permissions to your device, either by accident, by habit or because the user does not understand what is happening. just a click or two and you have just granted a ransom website full access to your drive. with webusb, they can even write a bootable anything to your pendrive.

    my concern here is not that you cannot make sure that the graphene website will only do what it needs to, but that the feature exists at all, because of all the other websites. I sincerely bless mozilla for not implementing these.