4 ms·
There is an easy solution to this: Allow the user to decide whether they want to allow for apps from outside a particular ecosystem. Then Johnny can set up Gran
by MostlyStable 2mo ago
There is an easy solution to this: Allow the user to decide whether they want to allow for apps from outside a particular ecosystem. Then Johnny can set up Grandma's phone and (in a deep byzantine menu where she will never accidentally stumble on it, maybe locked behind a pin), Johnny can set it so that Granny's phone can only install software from "Super premium, high class, curated, guaranteed not to hack your phone" walled garden app store. And Johnny, on his own phone, can choose what to download himself, including from the "Buyer Beware, half our shit is malware" dark web app store.
In my opinion, the Apple app store should actually be FAR more curated than it is, and far less curated options should be equally available. The Apple App store (and the Google app store for that matter), should be a relatively small list of apps that have extremely high standards and guarantees. It should essentially be impossible for spammy bullshit to get into these places. User-controlled, parental control like options should determine whether or not other app sources can be installed from (including allowing for specific other sources, so that app source control can be granular and detailed. I should be allowed to add FDroid but nothing else for example).
Done. Problem solved. Everyone is happy. Grandma is safe and Johnny has control over his phone.
But of course, that assumes that keeping Granny safe is actually the reason. Facially obviously, it is not, and is in fact entirely pretextual.
- zbentley 2mo agoThere are two big problems with this (not that Apple’s caprice is the only alternative): 1. The vast majority of people are Grandma, and they do not have a Johnny available to administer their tech. Most people are not technical. 2. The vast majority of Grandmas will follow instructions on a “how do I share cute photo” website even when that website directs them to dig deep into configuration settings and ignore six “are you sure you want to allow this app to fully remotely control your device?” warnings. Even if Grandma has a healthy suspicion of scams, when she is instead trying to accomplish a goal she will suddenly prove quite adept at giving software with questionable provenance root access to her life.
- CamperBob2 2mo agoAnd what if my grandma is Admiral Hopper. I wonder if there's a way to argue for or against paternalistic corporate gatekeepers without invoking sexism, ageism, or both?
- zbentley 2mo agoI used the terms from the grandparent post with tongue firmly in cheek. I didn’t intend to be sexist or ageist and agree with your criticism.
- preg_match 2mo agoI think the bigger question is whether this is even worth solving. If people really want to give someone root access and do it willingly, maybe we just say this is out of our purview and allow it. And then, slowly, people will learn. They will be hard lessons but evidently baby proofing the entire world is not really working, so we might just abandon ship on that idea.
- zbentley 2mo ago> And then, slowly, people will learn I hope you're right, but I'm not sure they will. The less locked-down WinXP and early Android era was ... really really bad in terms of nontechnical people getting hacked/scammed. And bad actors are also innovating, so the target of what people have to learn is moving: now we have synthetic AI voice scams, easy-to-create full clones of popular websites that harvest credentials, an explosion of 0days that let people run RATs that hassle elders for their MFA codes, and so on. Like, I'm 100% with you that baby-proofing the world is an unattainable, patronizing, and negative-externality-laden goal. We shouldn't do that. But we shouldn't go full libertarian "you're on your own; toughen up" either; I think we have a lot of data that indicates that the harms of that approach are both high-magnitude and high-volume.
- preg_match 2mo agoOn the sliding scale here where the left is "full anarchy" and the right is "goo goo ga ga baby proof the world", Apple is about 95% to the left. Here's how that looks: Anarchy |--------O-| Goo Goo Ga Ga And people are arguing we should be moving further right. It's ridiculous, we all need to be candid and recognize this will not work
- zbentley 2mo agoFortunately, it's not a linear scale. All sorts of technical and political options exist which don't fall cleanly into the anarchy or baby-proofing spectrum. Random incomplete examples, in no particular order and off the top of my head: GGP's idea of making it more commonplace to have a "Johnny" helping people with their tech needs to prevent accidents could work socially, if there are ways for communities to create more people willing to do that. Worldwide legal penalties for spamming/scamming could grow more teeth, increasing the likelihood of bad outcomes for people that make malware or questionable apps. Software distribution systems could standardize on better systems of provenance and ownership handoff to further technically harden against "good extension sold out to an evil maintainer" or "github credential leak let a bad guy publish an artifact"-type attacks. Cooldown periods for users trying to grant questionable access patterns could be imposed, though that might feel too baby-proof for some. On-device permission boundaries could be modeled in an "XOR" way: apps distributed from Apple's walled garden could be disallowed from approving data sharing with apps users install from other repositories. That's Apple's prerogative (they own the distribution and vouch for at least some of the quality of the app store apps), but doesn't prevent users from installing parallel ecosystems if they want. Something that's very paternalistic, but doesn't involve baby-proofing what's possible, is the idea of credentialing users. You need a driver's license to operate a car. In the US, you need a (much easier to get) food handling license to commercially process food. The latter's a short briefing and test of comparable effort to those mandatory corporate anti-phishing trainings that already-technical people hate. Perhaps some users could benefit from that as a prerequisite to installing non-trusted software. For vetted walled gardens like the App Store, further improving the granularity of and required justifications for permission requests as providers have been doing might help. "This poker app wants to access all of your saved contacts and photos" becomes "this poker app wants you to select a single profile photo and up to 5 contacts a day to add as opponents, after which access is revoked" or whatnot. This only works if App Store reviewers get serious about rejecting apps for overbroad permissions requests and explain their rationale to app developers, which would require Apple and friends to spend a lot of money to enable. Fortunately, they have insane margins. Less fortunately, their shareholders wouldn't go for this unless forced by regulation or similar. Anything that helps with threat attribution. If Grandma can install an app from a random URL, and then gets hacked 6 months later, it'd be great if something got in her face that loudly indicated that the decision to install the untrusted app was the root cause of her compromise and some "do you want to disable the ability to do this in the future/require a phonecall to $provider to turn it back on?"-type hint. For apps that spend money, further integrating pattern-aware anti-fraud and spend caps with payment APIs so that e.g. a microtransaction app that got hacked can't suddenly spend $100 where the user typically spent $5/month. Banks are already starting to get proactive/argumentative about unexpected transaction patterns a la "sir, are you sure you want to send $5000 in your first overseas money wire? Can you tell us more about that transaction? Are you aware of this common fraud?" ...and so on.