logoalt Hacker News

judge2020yesterday at 2:40 AM1 replyview on HN

> Make it require a difficult/obvious factory reset to enable, if you are concerned about someone being "tricked" into turning off the lockdown.

Is there also a way to make it obvious to the user that a device is running non-OEM software? For example, imagine someone intercepts a new device parcel, flashes spyware on it, then delivers it in similar/the same packaging unbeknownst to the end user. The same could be said for second-hand/used devices.

It's potentially possible the bootrom/uefi/etc bootup process shows some warning for x seconds on each boot that non-OEM software is loaded, but for that to happen you need to be locked out of being able to flash your own bootrom to the device.


Replies

nik282000yesterday at 6:11 AM

Pixel phones do this. Flashing a non-oem rom causes it to show a very "your device is broken" looking screen every time you boot.