13 ms·
>> "Can't you just make us a general-purpose computer that runs all the programs, except the ones that scare and anger us? Can't you just make us an Internet th
by pdkl95 5y ago
>> "Can't you just make us a general-purpose computer that runs all the programs, except the ones that scare and anger us? Can't you just make us an Internet that transmits any message over any protocol between any two points, unless it upsets us?"[1]
The War On General Purpose Computing continues. Far too many business models depend on selling general purpose computers as "appliances". They presume it is possible to sell a computer that isn't Turing complete.
[1] https://boingboing.net/2012/01/10/lockdown.html https://boingboing.net/2012/01/10/lockdown.html
- Aperocky 5y agoIt's inevitable, given the scale that has to happen before ASIC become remotely profitable and how cheap general purpose computers are today. Just buy some cheap SOC from the market and load the software, close it in a blackbox and call it a day. It's going to be the future now. God forbid they also talk to internet and runs an OS version from 2014 and never gets patched. It's a botnet paradise.
- ballenf 5y agoThe battle really parallels the larger right to repair debate. (Especially if we realize the latter is probably is better called the right to exercise control over purchased goods.)
- oneplane 5y agoDoes it? Everyone is quick to judge but coming up with an alternative is hard enough that nobody has done it so far. With scale comes scaling issues; general purpose computing and repairability need a different commercial model that doesn't match with the currently used models. This leaves two avenues: - Make it worse for everyone but keep it going - Make it worse for everyone in a different way and keep it going I don't know of a good solution here, but I do know that it's a sucky situation and the many "good ideas" to fix it aren't actually making it that much better. Current scenario: - Manufacturer on the hook for most things but also controls most things - End-users that fall within the 90% bell-curve are fine - End-users that fall outside of that are royally screwed and they don't even know it - Users that are not end-users are screwed, but they know they are So far all I have seen is: - Manufacturers still on the hook for everything but they get to control less - Everyone gets a little better but also a little screwed now - The 10% outside of the curve don't get as screwed as they did but they still don't really know that they are screwed - The non-users don't get screwed the way they used to but still get screwed To clarify: If I were to manufacture something, express what user experience comes with my 'thing' and warrant that experience to a certain degree, I don't want to be on the hook for any service or cost outside of that. The more I get to control, the smaller I can make the risk. That means I can also plan ahead better and reserve resources, but not so much that I don't have resources for something else left over. This also means that if someone wants a different experience (i.e. they are not my targeted audience) or if someone wants to do something I cannot verify, I really do not want to be on the hook for that. In total that means: - If what I want and what my customer wants is similar enough, we're both happy - If a small percentage wants something else, I cut my losses and simply don't serve their needs as soon as the cost of maintaining that deviation is bigger than what I would make off of it (short term and long term) - If someone does something I don't have control over, but they do come to me to fix their problem, I don't want to be responsible for that, and I don't want to do any research on the possibility that something I made happened to break at the same time the customer broke something else; I just want a blanket "I am the captain of my UX" rule and be done with it Now, I'm not saying this is ideal, or that I am an actual manufacturer, or that this is specifically what Google is doing (or Apple is doing for that matter), but I am saying that you can't have it both ways. Want something cheap and abundant? Gotta have scale. Can't have scale if you make a bunch of risk, add a lot of differences and support more than your middle-of-the-bell-curve. This sucks, but it's also not easy as saying "let me do what I want", because what happens to you and your device has side-effects, and I really don't want to get affected by something someone on the mobile network (or wifi network) I'm on did to their 'personal' and 'owned' and 'freedom' and 'muh righz' device. Or in a high contrast (black-and-white/good-or-evil) line: If you want to be on a shared service, play by the rules or get out. (reality isn't that high of a contrast obviously, but it drives the point of externalities home a lot quicker)
- ShroudedNight 5y agoYour primary alternative already sounds materially better than the 'Current Scenario' you describe: 1 - I'm not sure I've encountered anybody that universally falls within the 90% 'ideal' coverage. The more hostile things are to outliers, the more difficult everyone's life becomes. 2 - As far as I can tell, the slack that allows the bottom and top vigesimile (? 1/20th) to survive is also what allows the flexibility to foster the discovery of novel technical and societal configurations that are materially better than the status quo. That's how a kid from a family of coal miners has a path to making significant contributions to NASA.
- oneplane 5y agoAs for point 1: that depends; if your business operates on keeping the center of the bell curve happy, and you don't like to risk that, than implementing something that degrades that doesn't seem like a sound business decision. Keep in mind that this is from the 'producer' perspective. As for point 2: that should indeed be how it works, but the circumstances have changed, especially for large scale general purpose computing, and for various reasons and stakeholders as well. This is also the (wrong) fuel on the (wrong) fires in the current discussions on ownership, repairability and shared systems; it often tries to compare the "now" with a chosen "back then", and leaves out externalities causing the whole comparison to be useless. For example: it used to be that you could run whatever code you wanted and you didn't need anyones permissions and nobody could stop you. Now, at scale, that means everyone from teenagers at schools circumventing the implementation of a usage policy to state-level actors extracting information would run whatever they want. They are of course already doing that to some degree, but this would be so much bigger and so much easier when you just 'run whatever code appears at the JMP', we might as well not have an internet. This, in turn, means that you have to have some form of control, and some form of distribution or supply of such control as neither the will, nor the skill exists at the required scale to have everyone do this individually. How does one assert such control? Cryptographically. And now you're in PKI hell, or you're in DRM hell with DRM servers that go offline and render systems unusable. Oh, and you get DMCA and Legal requirements for free too. It would be amazing if we could figure out a way to operate shared systems, and have some form of delegated control without having a PKI-like authority as the only way to ensure it. But I haven't seen it yet :-( And this is just one of the many issues. Take hardware for example; you can do plenty of nefarious things with hardware, and the user would never know about it. Want to backdoor an audio module so it constantly streams what the microphone picks up to an actor of choice (a social media company, advertising company, your abusive spouse, the government of a state that will hurt you on detection of dissent), you can do that and no normal user would ever notice. How would you then prevent such modification? Well, you could make hardware hard to access or hard to modify without visible marks. That's one area (slightly) covered, but then there is the software, imagine hacking that remotely. So how would you do something about that? Perhaps signing the software and checking the signature. Bam, back in PKI hell. And if you were to make hardware hard to access, now you have a bad UX when someone comes to your service department and gets presented with a huge bill because your device had to be rebuilt because your kid put puke in the microphone hole. But if you make it unsafe you have the other problems again. No winning deal there. Or what if you use seals, now you have no idea why the seals are broken. Did someone tamper with it? Was it just a service call that's not registered in your system because it was done elsewhere? Who can you trust? What if you fix the reported issue but now something else breaks and you don't know if you did it or the previous tech did it? Guesses everywhere, everyone is sad, nothing works. yay. Again, no real solution here. Say you do the (not very often implemented) secure boot method where you insert your own CA; that's great for yourself, not great for a shared system, because now everything else that requires you to be securely booted needs to trust that CA too. This, hoever, is an area where you can do a partial fix: if you just want local verification and you have the CA and CT you can at least know for yourself. But that doesn't work at scale. We can't expect billions of people to be PKI experts. And we can't expect them to understand the ramifications of the lack of verification either. (which includes effects on them, but also effects on everyone else they are in contact with by proxy) So now you still need that 'magic' central authority making a policy and a verification for that policy and enforcement. PKI hell all over again! (keep in mind, I don't name PKI hell a hell because PKI is bad, I think it's great and I love me some hashing, public-key cryptography and root-of-trust chains -- it's just that there is no solution right now where you don't end up having an authority that can use it for good and bad at the same time) There are a lot of scenarios where we could mitigate 'some' of it: - Authenticated core but leave peripherals alone (your mainboard and CPU and AV chain would be on its own, but your keyboard can be key logging you as much as you want) - Unauthenticated mode but no interaction with shared systems (would work great for things like farming equipment) - Offline or do-it-yourself mode (again, no interaction, but you'd be offline anyway) But then you're still in the realm of real-world abuse (want to know your ex'es password? backdoor the keyboard! steal your boss's documents? backdoor the printer!). I don't know how to fix all of this, but removing all forms of authentication and still having shared systems isn't the way.
- MayeulC 5y agoThe right to purchase. It's become an issue of defining "purchasing". But companies don't want us to purchase appliances, they would be much happier if we could rent them.
- ticviking 5y agoAnd I would. At much much much lower prices
- throwaway_4747 5y agoSoon you will own nothing and be happy! According to the great reset and the WEF.
- Loughla 5y agoI have had my same fridge for 10 years, with no signs of failure. Unless the monthly payment was $3.00 or less, I would be paying more than I should starting in June. The rental/do not own anything model is just awful, in my opinion.
- brobdingnagians 5y agoTotally agree. The more time passes, the more I realize that I want to own what I have. I've grown more selective about what I purchase in general and I've become more minimalistic; but if I want to have it at all, then I want it to be mine free and clear. Especially when it comes to tools, land, and personal items. I want Good Quality and paid for with cash. I tend to use things until they completely wear out, and I get really good life out of them. This makes them very cheap compared to the usage pattern of upgrading all of the time. Renting would be very expensive lifestyle; and my usage pattern is more environmentally friendly to boot.
- spicybright 5y agoCouldn't agree more. Anything you don't own 100% can be put in jeopardy totally at randomly. If it's something important that can be incredibly stressful.
- wwarner 5y agoAgreed. I would feel better about this if I didn't think apps and local computing were really important. The alternative to phone apps is the web, but the web will never be fast (imo) and is simultaneously getting less open every day as well.
- bakatubas 5y agoThe web is the way for universal exposure. Regardless of speed it’s the only standardized, universal and widely used interface. WebAssembly will be the ticket there—once it’s developed a bit more. That being said, nothing compares to native. You could have shitty hardware by today’s standard with amazingly performant software if there weren’t so many damn layers in-between. People are fickle with hardware though and we devs need things to slow down a bit to appreciate the nuances of each device!
- echelon 5y agoApple is guilty of this too. No general computing company should be the single ingress point to running on their platform. For platforms with significant penetration, this is a market monopoly. [1] For Apple, it's iOS and, increasingly, MacOS. For Google, it's Android, and as has become glaringly obvious, Chrome. They shouldn't be allowed to run a browser. The DOJ needs to stamp out this anti-competitive, anti-consumer behavior. You can "protect" consumers with a permissions model and malware signature warnlist regardless of whether you enforce a store. Microsoft does it. Microsoft is the only company playing fairly. ([1] And no, this doesn't apply to game consoles. They're toys with lots of alternatives. You don't do business, banking, dating, note taking, drawing, stock trading, etc. on them.)
- lotsofpulp 5y ago> You can "protect" consumers with a permissions model and malware signature warnlist regardless of whether you enforce a store. I’ll believe it when I see an alternative to iOS devices that my dad can’t get malware on and only need a few seconds to fix by uninstalling an app or power cycling the device.
- anoncake 5y ago> You don't do business, banking, dating, note taking, drawing, stock trading, etc. on them.) Because it's artificially made impossible. No computer should be artificially restricted – let's not keep any loopholes open for no reason.
- FredFS456 5y agoThere's nothing wrong with the appliance business model - embedded devices that use microcontrollers are Turing complete and yet no one complains about those. It's only when devices are marketed as general-purpose (i.e. smartphones, PCs) but are locked down to prevent running arbitrary user-loaded code that it becomes a problem.
- horsawlarway 5y agoI disagree. I also mind when things like my tractor or my car are locked down to prevent my ability to use a 3rd party repair shop, repair it myself, or make changes so the item better suits me: The person who fucking owns that computer. I think there's a very real risk that the concept of "ownership" is going to die if we continue in this fashion. Do you own a thing if you're prohibited, intentionally - by the manufacturer - from making any changes? I'd say no. Do you own a thing if it has to check in to an online service controlled by someone else before it works? I'd say no. Instead you're just renting, and these companies are intentionally rent-seeking (in the worst possible way).
- Grimm1 5y agoAdd that on to the fact that almost everything is rent to buy with "incentives" shoved in your face for never actually finishing out the contract to own something, like your phone. I think ownership for everyone outside of some select few is in very real danger and I've thought so for some time.
- adreamingsoul 5y agoI agree.
- kube-system 5y agoI still like my car to have an immobilizer, and locks on the ignition and doors. There is certainly some level of access controls that most people definitely want.
- kelnos 5y ago
- viro 5y agothe issue is we as a market expect them to be responsible for the security of the OS and its apps. Its very difficult to manage security without control.
- kelnos 5y agoOnly from certain perspectives. If I'm a network engineer at a company, I need full control of the network to ensure security. As just a user of that network, I would have to understand that I don't have full control for security reasons. But it's not my network. When it comes to consumer devices, there's no reason why security requires locked down devices that the so-called "owner" of the device can't control. The end-user should always be in charge. If the manufacturer chooses to put escape hatches in front of features that could lead to security compromise, then that's fine. But those escape hatches should exist, and I refuse to buy a general-purpose computing device that doesn't have them. The Google vs. Apple argument here is specious; the locked-down nature of Apple's devices is not necessary for their better (but honestly still not great) security, and the less-locked-down nature of Android is not what makes it a security minefield.
- ncann 5y agoEven as a casual Android dev I've noticed it becoming more and more restrictive over the years, from restricting apps from reading storage, to restring apps from accessing clipboard, to restring apps from running in background, and a ton of other things all in the name of protecting customer. Every time I update to a new phone with a new Android version my hobby apps (which only I use, not published anywhere) are broken in some ways because of this. The end goal of Android seems to be a closed system like iOS and that makes me sad. You can make things harder or hard by default but at least give the power user some choices damn it.
- jabroni_salad 5y agoYou can still do things, its just that now the user has to approve it. Maybe a 'let every app have every permission by default' checkbox would make you happy but I'm not going to advocate for it. And you can still sideload an APK without even having to jailbreak the device.
- mattowen_uk 5y agoRe read the parent post. They write hobby apps that they clearly sideload themselves. They are also right, each iteration of the SDK takes away another feature of the device the app can access, regardless of whether you ask the user, in this instance the author of the app, for permission. The end state is for apps on Android to be either pointless fluff that basically do nothing useful, or mega apps written by big corps where the rules don't apply. Hobbiest coders are not wanted, or accommodated.
- ncann 5y agoExactly. To give an example, I have a dictionary app that I wrote to facilitate my French learning that runs in the background and automatically looks up word copied to the clipboard (e.g. from Play Books or Chrome) and brings up the definition. Starting with Android 10 or so they disabled clipboard listener for apps in the background so the whole functionality is toasted. There is no permission to enable this "clipboard listener in background"
- dalbasal 5y agoIt's useful to see through a principles/fundamentals lens. General Purpose Computing that isn't Turing complete, or whatnot. Genuinely useful. But, the "freedom is indivisible" take is not always useful, particularly not on its own. There are practical realities to contend with and the world of appliance-computing is big and complicated. A lot of issues relate to back competition, or lack thereof, for example. >> an Internet that transmits any message over any protocol between any two points, unless it upsets us? Look... The problems coming to fruition today have been talked about on HN/etc. for decades. They're hitting the political stage, and all those discussions have near zero impact. The ideas were never translated to general consumption form. We always prefered to be right over effective. The average politician has never stops to think about how www, linux, email, gnu, wikipedia and such are possible, what that means. If they did, they don't have the vocabulary for it. We didn't give it to them. Just let them read "cathedral & bazaar" or somesuch. Instead of working we snarked our incomprensible principled platitudes. Worse, we arrogantly assumed we'd win anyway. The internet couldn't be locked down. A country who tried to make Great Firewall would fail. Property rights would be redefined^ because digital copyright is impossible and the internet is more important than Beatles royalties. How wrong we were. How seldom we remember it. Classic ideologies like Marx, Rand & such tend to fall into this exact arrogant trope. I am so right about everything that it's all inevitable. History will conspire. The arrogant fools. Us too. Think of all the pull that Disney, EMI, etc have. Every politician can recite the case for copyright verbatim, along with the other talking points. Protecting their interests is literally one of the main things the US uses its might for. It's always a non negotiable demand in trade relations. Every politician or hack commentator knows to cite "stealing intellectual property" as a complaints against china or whatnot. Major digital legislation (eg DMCA) was written by and for them, along with other laws. Conversely, very few politicians or hack commentators could articulate a digital freedom case, a case against copyright militancy, or a case the against software patents. Those that can will be freestyling it. No "talking point" sheets. No consistency. No real lobby. No solidarity. No effectiveness. How the f##k do EMI & Disney have much more influence than us, or at least Google & such? We are arrogant fools. That's how. They're entertainment industries. We're the engine of modern economies. DMCA affected the tech business just as much as Disney. We even had status quo on our side, so all we needed was a hung jury. How did we lose this? It's a joke. Like Mike Tyson losing to McBride. Right to Repair should have been long won. We should be battling for OS mandates on the back of it by this point. So... where are we now? Politicians and journalist-types are literally starting to think of regulating social media as a "common carrier." Concepts recycled from early 20th century Telcom sagas. Not "neutral" carriers. Not "open" networks. No "free as in freedom." In fact, it seems like no idea from the personal computing age has influenced anything. No one who understands FOSS or how the www works is even in the room... the room where decentralising an internet-based communications network is being strategized. Do we realize how big a failure this is? ^No shade intended. I agreed ATT. I still do in the abstract. But, the lack of "what we need to do" was a mistake, IMO. History does not drive itself: http://www.paulgraham.com/property.html http://www.paulgraham.com/property.html
- leowbattle 5y agoFrom the article parent linked: "It doesn't take a science fiction writer to understand why regulators might be nervous about the user-modifiable firmware on self-driving cars" It's not just regulators who are nervous! What if someone modifies the firmware in their self-driving car and introduces a bug that causes the car to crash and kill someone?
- therealjumbo 5y agoI think the more interesting cases are 3D printing of weapons, and in the future programmable biological material. One of his statements is that he himself, may not like the applications enabled by general purpose computing, but that even if he personally doesn't like them they shouldn't be outlawed or banned. Google messing around with their app store is peanuts compared to the government banning or restricting 3D printers because they could be used to evade gun control for example.