18 ms·
Unrestrained webservers on phones is an edge case that would certainly be abused by all sorts of crapware while being a very uncommon usecase for mobile devices
by FireInsight 3y ago
Unrestrained webservers on phones is an edge case that would certainly be abused by all sorts of crapware while being a very uncommon usecase for mobile devices at all.
- nulld3v 3y agoApps can already do this mostly and it's caused absolutely no issues. In fact, it's often used for ad-blocking. You just can't bind to port 80/443.
- MichaelZuo 3y agoIt's true that there will always be unscrupulous actors but there are many ways to restrict or punish them already, I don't see why they would necessarily overwhelm existing methods.
- jeroenhd 3y agoApps can already open ports and with the HTTP DNS record arbitrary ports can be used to serve http/3 content. Services like RDP and several types of VPN server all connect to unprivileged ports any app can listen on. There should be a separate permission for listening on standard, reserved ports (anything in the IANA docs for all I care) that should require manual consent, like with location access. In fact, I think there should be a retractable permission for any kind of remotely accessible port binding. The fact any calculator app can start a VPN server on my phone without my knowledge isn't good! That doesn't mean providing any type of service is inherently bad, though. For instance, there are tons of phone <=> desktop sync apps (My Phone on Windows, KDE Connect on Linux/Windows/Mac) that constantly communicate between each other. Why should your phone always be the one to initiate that direct connection? Why should we rely on cloud servers when mutually authenticated SSH is already doing every bit of protection we could possibly need? My phone is half a meter away from my computer, it shouldn't need to be this difficult!
- theamk 3y agoYou don't need reserved ports for the custom protocos.. And most of them, like sync apps, use high port anyway.
- kroltan 3y ago> HTTP DNS record Can you tell me more about that? I know about SRV records from Minecraft (of all things!) for a similar purpose, can you point me towards a reference of what is this about? Wikipedia fails me.
- quectophoton 3y agoYou can check this post from Cloudflare[1], and from there you can reach the IETF draft[2]. [1]: https://blog.cloudflare.com/speeding-up-https-and-http-3-negotiation-with-dns/ https://blog.cloudflare.com/speeding-up-https-and-http-3-neg... [2]: Current version is https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-svcb-https-12 https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-svcb-...
- yjftsjthsd-h 3y agoFor anyone else looking: I don't think the cloudflare post says so, but the IETF draft does include "port" as an optional thing that SRVB records can include so we might finally get support for that in browsers:)
- yjftsjthsd-h 3y ago> My phone is half a meter away from my computer, it shouldn't need to be this difficult! FWIW, that's possible today on Android (not necessarily tomorrow, not necessarily on iOS) - I can and do regularly move files around with rsync/scp courtesy of termux, either by running the command on the phone or just running sshd on the phone (which does, in my setup, need to be manually started; I don't know if that's inherent or could be changed) and then running the transfer from another machine.
- deleted 3y ago[deleted]
- flangola7 3y agoSo? That's up to the user to decide.
- duggan 3y agoSure, if the user can build their own phone. Otherwise they're competing with a lot of other people interested in what the phone should and should not do. If they own a hammer, they can do what they like with a hammer, but a phone is not a hammer. It's a complex arrangement of molecules, licenses and competing group interests.
- convolvatron 3y agothere is nothing fundamental to differentiate a hammer from a phone except complexity. I'm sure if someone found a way to shove ads and place restrictions on the use of your hammer they would.
- duggan 3y agoYeah, it’s the complexity that makes the difference. There’s nothing but that to differentiate anything. You, a phone, a G class star, a comedy special on DVD. All “just” complex arrangements of matter. People make a big deal out of those differences though, go figure!
- flangola7 3y agoA phone is physical tool owned by a person that fits in their hands. It's not as dissimilar from a hammer as you have tried to portray.
- duggan 3y agoWordplay. I can hold your hand in my hand, is it similar to a phone? Otherwise your line of reasoning boils down to “it exists.”
- soulofmischief 3y agoI'm assuming the best intentions from you but I'd like to point out two things: 1. When discussing human rights (which apply to technological freedoms) reducing a need to "an edge case" is the basis of marginalization, defined as "treatment of a person, group, or concept as insignificant or peripheral". Therefore, it is never appropriate to rely on such language to prove a point, especially when we are discussing software which had to go out of its way to restrict freedoms. 2. It's an incredibly slippery slope to use "crapware" as a justification for reducing the freedoms of the individual. Criminals will find a way, do not create a hostile user experience.
- _Algernon_ 3y agoIs the right of a handful of people to run a web server on their phone more important than the right of millions of "unsophisticated" users to not be scammed / abused by malware? Since it's inception smart phones have been a consumer platform, used for consuming content. The platform for tinkerers already exists. It's called a PC with Linux installed. Every platform does not need to cater to your needs.
- froggit 3y agoPC is overkill for this case. A raspberry pi would get the job done while saving energy and equipment costs.
- _Algernon_ 3y agoA raspberry pi certainly fits the definition of a "Personal Computer".
- hunter2_ 3y agoThe whole "Mac versus PC" thing somewhat solidified the notion that PC refers to x86. Raspberry Pi uses ARM.
- 3y ago