Over the past few years, almost all major OEMs, one after another, terminated their bootloader unlocking mechanisms and locked down our devices permanently.
Meanwhile, Google is rolling out the Android developer verification program which will impose significant restrictions to sideloading.
The era of a free and open Android is coming close to the end.
So we must take action, right now, before we lose our last resort.
But as we all know, our Android tinkering community is only a microscopically small, "nerdy and suspicious" subset of the massive population of smartphone users.
So the only way for us to gain the attention and respect from the Big Techs, is to ally with a much larger group of people.
And here comes our Right to Tinker Initiative: https://right2tinker.org
(and we have a subrredit: r/right2tinker)
It is inspired by the Right to Repair and the Keep Android Open movements, such that we explain what is going on, reframe the locked down bootloader issue from a "geek-only concern" to a major security and privacy threat that affects every single smartphone user (as it really is), and therefore convince a much larger group from the general public to advocate with us for what we call the "Right to Tinker":
Right to Tinker: Anyone who lawfully and fully possesses a smart mobile device must be eligible to disarm all enabled-by-default lockdown mechanisms and restore full control of their device.
This means:
- Full read and write access to every bit on the device’s internal storage intended for general-purpose programming.
- The ability to boot any operating system — whether the original Android, a custom ROM like LineageOS, or any other system the user chooses.
We propose two additional demands to ensure a fear-free tinkering experience for enthusiasts and security researchers:
- Mandatory Recovery Mechanism: Manufacturers must not void warranty solely because a user exercises full device control — unless they can prove that a specific malfunction is a direct result of the user’s operations. Furthermore, manufacturers must provide accessible tools or services for restoring a device to the factory system image (i.e. unbricking).
- Breaking the Monopoly of Device Attestation: Critical digital infrastructure — banking apps, messaging services, government portals — increasingly require a “trusted device environment.” In practice, the only accepted proofs are provided by two US companies: Apple and Google (through Play Integrity API on Android).
With this topic, we want to clarify several misconceptions behind the reason why the OEMs are so obsessed in locking us out of our own devices. While the actual reason remains a mystery, we can eliminate some of the non-reasons:
0. Is it mandated by the EU RED Act (2014/53/EU)?
This is the most common misconception. lot of people cite the Article 3(3)(i) of the RED Act as the reason why OEMs have to lock down the bootloader permanently. But this is entirely inaccurate. The Article states:
radio equipment supports certain features in order to ensure that software can only be loaded into the radio equipment where the compliance of the combination of the radio equipment and software has been demonstrated.
In the context of a smart mobile device, the “radio equipment” refers to the baseband. This Article effectively requires cryptographical measurements to ensure only authentic baseband firmware signed by the chip manufacturer can be loaded — which has been universally implemented for years without relying on the OEM lock at all.
The true intention of the act is to make sure devices do not interfere with public emergency frequencies, cellular networks, or aircraft communications.
In fact, the EU regulators explicitly foresaw that greedy manufacturers might try to use this directive as a weapon to lock down their devices and kill competition. To prevent this, they wrote Recital 19 directly into the directive:
Verification by radio equipment of the compliance of its combination with software should not be abused in order to prevent its use with software provided by independent parties. The availability to public authorities, manufacturers and users of information on the compliance of intended combinations of radio equipment and software should contribute to facilitate competition. In order to achieve those objectives, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission in respect of the specification of categories or classes of radio equipment for which manufacturers have to provide information on the compliance of intended combinations of radio equipment and software with the essential requirements set out in this Directive.
1. Is it for Anti-theft?
All devices already ship in a locked state, and the current security mechanisms are already good enough to make it practically impossible for a theft to unlock it without the device owner's credentials.
And even with an entirely locked down devices, thefts can sell them for parts.
2. Is it for preventing attackers to inject trojans that hide deeply in the system?
This can happen only in two ways: supply chain attach, or someone physically takes away your phone, unlocks the bootloader (which wipes your data, and adds a warning screen on every reboot), injects the trojan without being you ever noticing.
The former can be avoided by making bootloader unlock only possible after the device is activated by a customer (and in fact, an unlockable bootloader makes it easier for security researchers to find such trojans); the latter sounds more like sci-fi plot.
3. Is it for cutting customer support cost?
The tinkering community is probably < 1% of the entire smartphone users population, and the extra cost for customer support is probably negligible.
Then what are some rationally possible reasons for the OEMs to do so?
Well, we probably all know it already.
They degrade the performance, and intentionally block technically compatible OS features for the older devices, for forced obsolescence.
And with the permanently locked down bootloader, they hold the dictatorship of our devices. They can embed telemetry or even malware directly into the stock ROM -- and we have no way to even know if they are doing so, let along stopping them.
The bottom line:
A permanently locked down bootloader never protects the consumer from attackers.
It protects the OEM from the consumers.