Garrett: Linux kernel lockdown, integrity, and confidentiality
Garrett: Linux kernel lockdown, integrity, and confidentiality
Posted Apr 22, 2020 22:22 UTC (Wed) by NYKevin (subscriber, #129325)In reply to: Garrett: Linux kernel lockdown, integrity, and confidentiality by scientes
Parent article: Garrett: Linux kernel lockdown, integrity, and confidentiality
> I don't believe that at all.
We must be careful in disagreeing with each other, lest we talk past each other and learn nothing from it. This starts by being precise about the claims with which we disagree:
- The set of users whose devices are at serious risk of malware infection is much, much larger than the set of users who want to root their devices.
- Malware can do a lot more harm if the device can be rooted than if it cannot.
These claims are factual, not ethical. They may be subject to empirical refutation (and if you have citations, I would be very interested in seeing them), but they cannot be logically refuted by moral arguments.
To determine the morality which results from this set of facts, you would need to consider:
- Whether you are a consequentialist ("The needs of the many outweigh the needs of the few") or a deontologist ("We hold these truths to be self-evident, that all men [...] are endowed by their Creator with certain unalienable Rights[...]"). You can't be both, because they contradict each other. (There are other ethical positions as well, but for simplicity I omit them here.)
- If you are a consequentialist, the amount of harm that you believe is created by each instance of malware on average, and by each user denied the right to root their device. Then, you multiply by the number of users affected, and compare the two harms in aggregate.
- Factors such as the "fault" of nontechnical users for failing to secure their devices, or the "freedom" of technical users to root their devices, are out of scope and not evaluated, except to the extent that they can be framed in terms of consequences (e.g. Would nontechnical users have been infected anyway? Can we quantify the amount of additional harm caused by the infected device being unlocked, instead of the total harm?).
- If you are a deontologist, whether you consider rooting a device to be a fundamental right, and the extent (if any) to which you believe this right can be attenuated by your contractual agreement with the vendor or service provider, or by other considerations such as the availability of unlocked devices.
- Factors such as the number of users who will actually be subject to malware infections, and the likely consequences of those infections, are out of scope and not evaluated, except to the extent that they can be framed in terms of rights and responsibilities (e.g. Does the manufacturer owe a duty of care to its users? Will the malware cause harm to the public, for which the manufacturer would be responsible? Do the users themselves have responsibilities here?).
- Whether facts can give rise to morality in the first place. (This is mostly only of interest to philosophers, but it gives you a sense of just how complicated this whole problem is.)
Since all of these points are somewhat subjective and/or disputed, it should be unsurprising that reasonable people may disagree about them. But we must not lose sight of the underlying facts, or it will be impossible to have a constructive discussion about this question.
