• @pimterry@lemmy.worldOP
    link
    fedilink
    English
    151 year ago

    Fully managed corporate devices can do this, there’s a separate mechanism for that: https://developers.google.com/android/work/requirements/fully-managed-device

    This only works when the corporation fully manages the device though - not for normal work profiles. It’s only possible to enable that setup when the device OS is initially installed, and the resulting device is controlled 100% by an IT administrator. It’s not something you can do for your own device, and even for small companies it’s quite complicated and expensive.

    • deweydecibel
      link
      fedilink
      English
      15
      edit-2
      1 year ago

      This is exactly what’s happening with Windows, too. Unless you’re a business with an Enterprise version, control is being ripped away from you. We’re getting to the place now where individuals are no longer permitted to be admins of their own devices unless they’re corporations that pay for the privilege. I said it years ago when they took GroupPolicy out of Home edition: it was normalizing admin control as a premium feature, that one day average people will be priced out of.

      Combine that with a lot of the other environment integrity/hardware attestation bullshit Google and Microsoft are pushing more and more, so that even if you do manage to wrangle admin control back from them, you can be prevented from participating in the larger internet ecosystem for having the audacity to do so. Even Linux won’t be a meaningful retreat when the largest and most popular websites and apps collectively decide you have to use what is effectively a corporate approved kiosk to access them.

      This shit should be illegal.

      • Big P
        link
        fedilink
        English
        51 year ago

        The day windows takes away my administrator power is the day I switch to Linux

          • Big P
            link
            fedilink
            English
            11 year ago

            You can uninstall it, it just breaks some things. Internet explorer was worse

            • @Darkassassin07@lemmy.ca
              link
              fedilink
              English
              2
              edit-2
              1 year ago

              Not through any of the conventional means.

              You’ve gotta find and manually take ownership of all its files then delete them all. You also have to remove it’s updater service first (the same way) or it’ll re-install itself immediately.

              Even then, it’ll re-install with system updates.

              The only reason it breaks anything is several system services like the general help dialog and news+weather are permanently hard-coded to ignore the default browser setting and use Edge exclusively. There’s no good reason for this.

              • Big P
                link
                fedilink
                English
                31 year ago

                Yeah, it is rediculous that they do that and I’m surprised they haven’t faced another antitrust suit for it.

      • @j4k3@lemmy.world
        link
        fedilink
        English
        31 year ago

        This guide, in the third section at the bottom talks about using KeyTool to boot into UEFI and is how you get around this issue: https://wiki.gentoo.org/wiki/User:Sakaki/Sakaki's_EFI_Install_Guide/Configuring_Secure_Boot

        Firmware bootkit vulnerabilities are one of the largest attack surfaces available right now. There are ways to deal with this, it is just added complexity. The intellectual barrier is becoming harder. Secure boot is important though.

      • slazer2au
        link
        fedilink
        English
        01 year ago

        I don’t think it should be illegal, there are people who are not technically capable and can give permissions when they shouldn’t. I believe there should also be an an option where as a power user you are given those controls again because you have the technical understanding of what you are doing.

    • @sirfancy@lemmy.world
      link
      fedilink
      English
      4
      edit-2
      1 year ago

      Correct me if I’m wrong, but I have a work profile with a cert authority installed in a work profile managed by Intune. If I update to Android 14, I’ll lose this?

      • @pimterry@lemmy.worldOP
        link
        fedilink
        English
        51 year ago

        Unless it’s a fully managed device (different to a work profile - this has to be configured when the device first boots, it’s for phones that are fully corporately owned & managed) then I think that has to be acting as a user-level CA certificate (trusted only by apps who opt in to trust it, which notably includes Chrome) not a system-level CA certificate (trusted by all apps by default). That will keep working just fine.

      • Skull giver
        link
        fedilink
        English
        4
        edit-2
        1 year ago

        [This comment has been deleted by an automated system]