4 ms·
> In the security world, the default should be off and only upon request should an app allowed to talk over the network. I'd argue that reasonable defaults are
by Denvercoder9 5y ago
> In the security world, the default should be off and only upon request should an app allowed to talk over the network.
I'd argue that reasonable defaults are better. Asking permission for everything, including features most to all people would find necessary, just creates decision fatigue and results in people clicking "allow" on every popup.
- JohnFen 5y agoI think the only reasonable default is to not talk unless I've given permission for it to do so. But I recognize that I'm in the minority. So much so that I can't trust software to behave itself, so I've had to use my firewall to disable all outbound traffic by default, so I can add exceptions as needed. It's amazing how rarely such exceptions are actually needed.
- __MatrixMan__ 5y agoI'm with you. Paranoid defaults should be the default defaults Although I'd still like to be able to opt-in to reasonable defaults if I trust that my OS's non-default default decisions are indeed reasonable.
- AnIdiotOnTheNet 5y agoI agree and I think mobile got that part of sandboxing wrong. I think a better solution is to sandbox by default, give the application no way of being able to tell if it has permissions or not, and making the user manually go in and grant it permissions as they find they actually need them. This would incentivise application developers to try and use as few permissions as they could possibly get away with. However, it would also require a really good, understandable interface for granting permissions to applications. Files are relatively straight forward, as the file open/save dialog can be handled by the OS and anything the user does with it can be considered explicit permission. For other resources something similar might work, or might need a completely different abstraction.
- binkHN 5y ago> I think a better solution is to ... give the application no way of being able to tell if it has permissions or not... As an Android developer, I strongly disagree with this. Even if I never prompted for permissions, giving me the ability to determine what permissions I have allows me to make certain the application behaves properly with the permissions it does have.
- AnIdiotOnTheNet 5y agoUnfortunately it also allows you to pester the user to change them and, as we've learned, we can't trust applications not to act like they need permissions when they really don't. Ok, how about a compromise: We'll let the application be able to tell by default, but the user can can choose to lie to it.
- binkHN 5y agoWhile it's taken Android some time, on newer APIs the system will simply prevent an app from requesting permissions if a user has denied it more than once. From https://developer.android.com/training/permissions/requesting https://developer.android.com/training/permissions/requestin...: "At the same time, your app should respect the user's decision to deny a permission. Starting in Android 11 (API level 30), if the user taps Deny for a specific permission more than once during your app's lifetime of installation on a device, the user doesn't see the system permissions dialog if your app requests that permission again."
- rootusrootus 5y agoMaybe something in the middle. One time, during initial setup, the OS should have a single question with all of the reasonable defaults displayed (and uncheckable). Tell people why these are reasonable, give them an opportunity to opt-out, make it easy to move forward quickly.
- adamc 5y ago"Decision fatigue" is an apt phrase. Reminds me of Joel Spolsky's old essay on classic Windows help asking what kind of help db install I wanted ("compact", etc.) -- to which no normal user ever had an answer. Don't ask people questions that they are going to answer one way 95% or more of the time, or for which they haven't the context to answer. Just make it easy to change later if you need to.
- fnord77 5y agoreasonable defaults are way better, or you'd end up with something like SELinux where nothing works out of the box