5 ms·
Heavily sandboxing apps by default is fine, and some Linux distros are, slowly, moving to do this - see e.g. AppArmor and Snap. Even giving warnings by default
by mpartel 6y ago
Heavily sandboxing apps by default is fine, and some Linux distros are, slowly, moving to do this - see e.g. AppArmor and Snap.
Even giving warnings by default about unsigned apps requesting high privileges would be fine if the implied message weren't basically "everything we haven't checked is malware". Something like "We nor any other provider you've chosen to trust have no idea who made this and we haven't checked if it contains malware. This program may steal and delete all your files. Be really sure you trust the author before running this." would be much more honest.
Good security does not require a single entity becoming the sole gatekeeper and taxman for a huge fraction of users.
> Why must everyone constantly have to risk their own neck to defend someone else’s perception of freedom. Why should they all pay (in terms of risk and time mitigating against it) for something that benefits someone else alone?
I'm not advocating for Windows-levels of "install anything with access to everything with barely any warnings". And I wouldn't say you're "constantly risking your own neck" if you deliberately ignore warnings.
In computing as in society, I don't see how we can remove all possibility of getting cheated into hurting yourself (by installing malware in this case) without essentially submitting to some form of autocracy. And I think freedom benefits almost everyone, at least indirectly. As a concrete example, in the Apple/Epic case, an alternative game store would likely result in healthier competition i.e. lower prices. As another example, Hong Kong protesters with iPhones would have had an alternative way to coordinate: https://www.bbc.com/news/technology-49919459 https://www.bbc.com/news/technology-49919459
- eecc 6y ago> Even giving warnings by default about unsigned apps requesting high privileges would be fine if the implied message weren't basically "everything we haven't checked is malware". Something like "We nor any other provider you've chosen to trust have no idea who made this and we haven't checked if it contains malware. This program may steal and delete all your files. Be really sure you trust the author before running this." would be much more honest. Well, what you ask is what's written in the very first prompt screenshotted in the blog post; it says "the developer cannot be verified", "macOS cannot verify that this app is free from malware." I don't see how this choice of words is much different from your proposal. I don't want to go too deep into the "alternative store" discussion, it's much broader than this, but let me just say Adobe Flash. I don't think Apple will ever relinquish the strategic power to force developers to adopt APIs and track their lifecycle, and never again have to deal with the Flash scenario. If they let the door open to "alternative stores" good luck explaining to the general public how it's not their fault if <insert major app> works like shite and kills hardware performance. As an example, to this day, people still rant about Apple's "proprietary music file formats" when really it's just bog standard mp4 (it's even unencrypted... you can copy it over to any industry-standard decoder and you're good to go. Good luck with WMA (if they're still around) or whatever madness Sony came up with. The moment they would decide a major overhaul, you'd see "alternative app stores" advertising "backward compatibility", "freedom from Apple's treadmill", fragmenting user experience in an endless passing of blame about who's fault it is for the rot.
- mpartel 6y ago> Well, what you ask is what's written in the very first prompt screenshotted in the blog post; [..] I don't see how this choice of words is much different from your proposal. There are nuances about the UI and wording as discussed elsewhere in this thread, but my main objection is about Apple positioning themselves as the only one who decides which apps don't get that warning. > [..] I don't think Apple will ever relinquish the strategic power to force developers to adopt APIs and track their lifecycle, and never again have to deal with the Flash scenario. I don't see how alternative stores would prevent Apple from breaking backwards-compatibility on an OS they would still control. Even open source projects do BC breaks as they see fit. And I think Microsoft demonstrates that proper BC is something a company the size of Apple could well afford to do if they cared to. The Flash case could be seen to support my position as well. Wasn't it a case of Adobe getting into a dominant position (for their particular niche) and then "abusing" it by letting Flash stagnate with awful security? It's good that we eventually got rid of Flash, but wouldn't it have all been much easier if Adobe had never become that dominant in the first place? You can of course say Apple would never let something stagnate in that way, but all companies have their (sometimes shifting) priorities and interests. Often they'll align with you as the user - that's the nice thing about capitalism - but there's no guarantee that they always will (e.g. that Hong Kong example), and a dominant player in the absence of healty competition is always incentivized to charge as much as the market will bear. > If they let the door open to "alternative stores" good luck explaining to the general public how it's not their fault if <insert major app> works like shite and kills hardware performance. Is this really that big of a problem? Seems like something platforms already deal with by surfacing and by default restricting apps' energy use etc, though this too can be a double-edged sword. I have a few apps on Android that need to constantly show a pointless notification just so they can run in the background, and they have legit reasons to do so, and I'm OK with the battery drain. Again I'm compelled to draw an analogy to society: freedom indeed requires some degree of responsibility and understanding from everyone. Benevolent dictators are a great place to "outsource" all that. The trouble is that they (or their successors) rarely stay benevolent for long, especially if you're not in their ingroup. I've yet to see power accumulation have good long-term consequences in history.