logoalt Hacker News

Skwid • today at 12:00 PM • 0 replies • view on HN

I appreciate what you're saying. Commercial realities are very different to theoretical ideals, and of course you have to draw the boundary of trust somewhere to get anything done.

I don't think anyone is saying it's an app developers responsibility to ensure the user's bootloader is securely implemented.

There is a lot of space between verify everything and trust nothing, and I don't think it's unreasonable to question whether that trust boundary is in the right place.

I also think that the code compiled to produce the binary you ship is a perfectly reasonable place to put that boundary, would you disagree?

I'm sure that within the mobile dev world it is normal, accepted practice to include lots of unseen code. I don't begrudge anyone involve for taking the money and doing what's expected.

But I still think it's a mad way to run a business or community project, and it's worth considering how we got here and whether it really has to be this way.