Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't think the average user would understand what "unlocked bootloader" means, and may even mistake it for a feature or enhancement.

It is a supply chain risk. The Android & Pixel teams walk a fine line here: they risk upsetting an important (but small) user group if they change the language and defaults to "THE BOOTLOADER IS UNLOCKED: USE AT YOUR OWN RISK" or even stronger language and shipping these devices to end users.



The unlocked bootloader warning screen isn't very different from what you described [1]. It says:

> The bootloader is unlocked and software integrity cannot be guaranteed. Any data stored on the device may be available to attackers. Do not store any sensitive data on the device. Visit this link on another device: g.co/ABH

It's already pretty strong language (and very accurate! which is a rare combination).

[1] https://www.androidauthority.com/wp-content/uploads/2018/10/...


Ah, that's much better than the thread had me believe!

Kudos to the security folks at Google.


That's actually not exclusive to Pixel phones. The custom signing key part probably is, just because no other phone allows you to lock the bootloader with a custom key. But the "bootloader is unlocked" screen is built into AOSP




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: