3 ms·
> That's the hard part for all of this: if you are building an unlock mechanism the first question you need to ask is how you build a UI which clearly communica
by deeblering4 5y ago
> That's the hard part for all of this: if you are building an unlock mechanism the first question you need to ask is how you build a UI which clearly communicates to a user that they are likely giving control of all of their data, location/camera/microphone, etc. to whatever they're installing.
Nah, thats a win2k era cop-out. The hard part is balancing secure by default and granting privs only when absolutely necessary (and authenticated)
- acdha 5y agoIt’s recognizing that giving up control of the trusted base means giving up control of the device. If that option is available, people will be tricked or coerced into using it, or it will be done without their knowledge – as evidenced by all of that being done not uncommonly on desktops. I think a better angle is pushing for relaxing software distribution: keep the trust chain but let people run apps in the normal sandbox even if those haven’t gone through the current process. Exploits are still possible, of course, but the normal controls allowing user awareness of the device’s status would be intact.