Hardware Security

Right to Repair and the Security Trade-Off Nobody Advertises

August 12, 2026 8 min read Haven Team

Right to repair laws are winning, state by state and country by country, and the case for them is strong: a phone with a cracked screen shouldn't be landfill because only one authorized shop can legally source the part. But the debate rarely gets past the economics. Every mechanism that makes a device repairable by a third party is also a mechanism that could let an attacker, or a previous owner, or a repair tech with bad intentions, do the same thing.


Manufacturers didn't lock down repair purely to protect margins, even if margin protection was the loudest motive. Parts pairing, serialized components, and diagnostic authentication all trace back to real security features: a stolen phone's screen shouldn't be swappable into a clean device to defeat activation lock, and a replacement fingerprint sensor shouldn't be trustable by the secure enclave without some way to verify it hasn't been tampered with. Right to repair legislation forces manufacturers to open those mechanisms to third parties. What it can't do is make the underlying security problem disappear. It relocates it.

What "locked down" was actually doing

Modern phones don't just check that a replacement part physically fits. Apple's parts-pairing system, and Samsung's and Google's less aggressive equivalents, cryptographically bind specific components (screens, batteries, biometric sensors, cameras) to the specific device's logic board via a serial number exchanged at manufacture time. Swap the screen without going through an authorized pairing process and you can lose Face ID, get persistent warning banners, or in some configurations lose True Tone color calibration entirely.

The security argument for this is real: a fingerprint or face sensor is part of the device's trusted hardware chain. If any sensor could be swapped in from an unknown source and accepted without verification, an attacker with brief physical access to a locked device could replace the sensor with one that always reports a match. Parts pairing closes that door by requiring the new component's identity to be cryptographically attested before the secure enclave trusts it.

The economic argument is also real, and it's the one right to repair advocates focus on: the same mechanism that stops a malicious sensor swap also stops a legitimate independent shop from installing a genuine Apple-manufactured screen pulled from a donor device, unless that shop has access to the manufacturer's pairing tool. For years, most didn't.

What the laws actually require

Requirement What it opens
Parts availability Manufacturers must sell individual components, not just complete assemblies, to independent shops and consumers
Diagnostic tool access The same software authorized dealers use to read error codes and calibrate sensors becomes purchasable or licensable
Documentation Service manuals and schematics that were previously internal-only become available on request
Software locks (varies by jurisdiction) Some laws (Oregon's is the strictest currently in the US) explicitly ban parts pairing that degrades functionality after a genuine part swap

That last row is where the security debate actually lives. A law that bans parts pairing outright removes the manufacturer's ability to distinguish "this is a legitimate replacement sensor" from "this is a sensor of unknown provenance," full stop, for every device sold in that jurisdiction. Oregon's law took this position deliberately, and manufacturers pushed back hard, arguing it forces a regression in the trusted hardware chain across their entire product line, not just for the repair use case it was written to serve.

The trade-off, stated plainly

A cryptographic pairing check that verifies component authenticity cannot distinguish "an independent repair shop with a legitimate part" from "an attacker with a compromised part," because both present a component the manufacturer didn't originally install. The only way to tell them apart is a trust decision made somewhere in the supply chain, and every version of right to repair legislation is really an argument about where that decision should sit.

The used-device and stolen-device angle

There's a second security dimension that gets less attention: activation lock and its equivalents exist specifically to make stolen devices worthless by binding them permanently to the original owner's account, verifiable independent of any single component. Right to repair doesn't touch activation lock directly, but easier access to replacement parts and unlock tools does lower the cost of the parts-out market for stolen devices, where a phone is broken down and its individual (still-genuine, still-traceable-by-serial) components are resold rather than the whole unit resold and immediately bricked by the owner's remote lock.

This is a genuine tension without a clean resolution. Requiring every replacement part to carry a serial number that ties back to a specific stolen device would help law enforcement and hurt legitimate reuse of parts salvaged from devices that were destroyed rather than stolen. Most current legislation doesn't attempt to solve this and leaves component-level provenance tracking as a manufacturer choice rather than a legal requirement.

What to actually watch for as a consumer

None of this argues against right to repair. A repairable device that lasts twice as long has a real security benefit of its own: fewer devices means fewer opportunities for supply-chain interference, and a device you can inspect and repair yourself is one you don't have to hand to an unknown third party and trust blindly. The point worth making plainly is that "more open" and "more secure" don't move together automatically, and any honest account of this debate has to hold both at once rather than picking whichever framing fits the argument already being made.

What manufacturers could do that neither side is asking for yet

The current fight is largely binary: parts pairing on, or parts pairing off. There's a middle design that gets little attention in the legislative debate but would satisfy more of both sides' actual concerns. A manufacturer could publish a verifiable, revocable certificate program: any repair shop, independent or authorized, could register a replacement part's serial number against the manufacturer's public log before installation, producing the same cryptographic attestation an authorized dealer's tool produces today, without requiring that shop to be under contract with the manufacturer at all. Component provenance stays checkable. Consumers keep the choice of who repairs their device. The barrier isn't cryptographic, it's that manufacturers have had little commercial incentive to build a system that makes independent repair easier, and until legislation or market pressure changes that calculus, most of them won't.

Some progress exists here already. iFixit's parts partnerships with Samsung and Google, and Apple's Self Service Repair program, are early, imperfect versions of exactly this idea: a manufacturer-sanctioned path to genuine parts and pairing tools for anyone willing to do the work, not just an authorized dealer network. None of the current programs are frictionless, and pricing on individual components is often close enough to the cost of a full replacement device that the economic case for using them is weaker than the security case. Whether that gap closes over the next few years will say more about the direction right to repair actually takes than any single state law will.

Try Haven free for 15 days

Encrypted email and chat in one app. No credit card required.

Get Started →