6 ms·
And what should we do about apps' getting hacked, sending out malicious updates that get auto-updated and thereby infecting tens of millions or billions of phon
by setgree 15d ago
And what should we do about apps' getting hacked, sending out malicious updates that get auto-updated and thereby infecting tens of millions or billions of phones simultaneously?
I'm not saying we have the perfect system but anything that slants the system towards "easier downloads" or "less gatekeeping" brings large, obvious risks. I don't see how regulation would address them.
- post-it 15d agoHow would a reviewer catch that?
- Maskawanian 15d agoHow about treating people like adults for a start? How about starting public awareness campaigns about proper digital hygiene. Not everything has to be nanny state garbage.
- pjmlp 15d agoMany of us have routinely cleaned computers from adults that installed several Ask Jeeves and Yahoo toolbars.
- compass_copium 15d agoAt some point computers need to stop being treated as magical boxes that no reasonable person can learn how to use safely. We expect people who use cars to learn how to use them safely, we expect people who use lawnmowers to not stick their fingers in them. Computers have been a part of daily life for normies for decades at this point, it's infantilizing to suggest that average, non-tech savvy people can't learn to use (not necessarily build, repair, etc.) them properly and need to be protected from them.
- pjmlp 15d agoPeople have to successfully get through a state exam in order to drive cars in first place, can be jailed, get fined when not driving them safely, or forbidden for life to ever drive again. People that accidentality cut their fingers in lawnmowers due to lack of safety features are allowed to sue the lawnmower company. What I would agree is that it is about time computing gets the same liability laws that the rest of the world already has in place and no EULAs that work around local laws should be considered valid in any form or shape.
- voakbasda 15d agoDo you hate open source and want only projects where their authors can afford liability insurance and are willing to put themselves in the firing line of a legal system that can be both arbitrary and capricious? Because that’s what you seem to want.
- pjmlp 15d agoEven people selling on the street or doing charity work have to account for liability of their actions. Lets stop talking about open source as special snowflakes where everything is excused.
- voakbasda 15d agoAnd that’s how you prevent bake sales, lemonade stands, and more. You create a barrier to entry that gets raised little by little until only the biggest players can afford the game. Software liability would end all small open source projects.
- pjmlp 15d agoBake sales and lemonade stands are perfectly fine as long as people don't land on hospital urgency, due to careless work on preparing them with spoiled ingredients or lack of hygiene. Lets strive for quality in software.
- marcosdumay 15d agoWell, computers first stop being magical machines that no person can learn how to use safely, then. And, honestly, if you think the endpoint safety problem doesn't apply to you, you are part of the problem.
- compass_copium 13d agoThe endpoint safety problem obviously applies to me and every person connected to the World Wide Web, but the grandparent was talking about The Olds who install the AskJeeves and the Yahoo! toolbars and Bonzi Buddy and... If computers aren't safe enough that a reasonably competent user, who doesn't open random files they found online and obvious spear-phishing emails, can't use one without losing their 401k, then maybe we need to just reevaluate modern life and go back to bank tellers.
- misnome 15d agoUsing a computer wrong doesn't kill people.
- pjmlp 15d agoDepends on what those computers are responsible for.
- jprjr_ 15d agoYes and no. The computer itself won't really do anything. But I'm sure suicides go up when people lose all their money, or get personal private details leaked, and so on.
- m4rtink 15d agoehm: https://en.wikipedia.org/wiki/Therac-25 https://en.wikipedia.org/wiki/Therac-25
- anonymars 15d ago> "One [software fault] was when the operator incorrectly selected X-ray mode then in 8 seconds quickly changing to electron mode, which allowed the electron beam to be set for X-ray mode without the X-ray target being in place" Therac-25 is an important software-development case study but a torturous stretch of "Using a computer wrong"
- deleted 15d ago[deleted]
- misnome 15d agoYou are right! Computer use should be taught, tested and licensed exactly the same way of steering several tons of metal at 70mph are!
- deleted 15d ago[deleted]
- esikich 15d ago
- sunaookami 15d agoAnd e.g. browsers cracked down on it, removed toolbar support and powerful add-on support AND enforced signing meaning everything goes through their gatekept extension store and these problems still persist (e.g. addons changing the search provider, new tab page or homepage). Locking everything down does not help.
- pjmlp 15d agoMore a problem of those stores still not being properly validated rather a dumping ground for extensions, than anything else.
- sunaookami 15d agoA problem that can't be solved, you can't check every single program out there much like you can't check every single human ever even with cameras installed everywhere.
- pjmlp 14d agoJust because some people still die with seatbelts, does not mean they aren't safer without them. Yes you can check every single program out there, when digital stores are the only acquisition mechanism. Or as alternative, signed binaries. Coupled with liability like anything else in our societies.
- no-name-here 15d ago> does not help Is that true - do you not see significantly fewer of those installs on random PCs now than you did years ago? And that's even with the current situation not being what I'd call fully locked down.
- sunaookami 15d agoNope.
- bigfishrunning 15d ago20 years of being tech support for countless family members and acquaintances says that nothing can possibly make people care about "digital hygiene". An iPad, Chromebook, or similar inflexible device is perfect for most people, and marketing more flexible devices to them has been a mistake since the beginning.
- NorthSouthNorth 15d agoI don't know. Literally every single person I help with tech support makes me doubt this is possible. People do not care in the slightest and treat suggestions to learn basic digital hygiene as if you've asked them to a computer science degree in its entirety. Even super basic stuff like remembering a single secure password instead of reusing the same 2 or 3 basic initials-dob-symbol permutations that were probably pwned 10 years ago seems insurmountable.
- osmukka 15d agoIMO in that case its their own fault. After all they have free will and can use it against their own good if they so choose. Let them get pwned a few times and see if they learn.
- diegolas 15d agothat's so dumb on so many levels... should we strip cars from active safety measures and let drivers who are not super good at driving just kill themselves on the road?
- myaccountonhn 15d agoMaybe a drivers license should be needed to have a phone.
- diegolas 14d agomaybe there should be alternatives to using the smartphone for everything, personal finances included. my bank stopped offering a home banking service for example (yes, of course the mobile app still sucks), and it's a trend.
- preg_match 15d agoWell cars kill people, granny using the password “password” does not. We can’t prevent all levels of stupidity and carelessness. If people want to have dumb passwords and download malware, then so be it. You think they can’t do that today with the google play store? Of course they can. Most malware on android comes from the Google play store.
- nik282000 15d agoYou expect people to treat devices with respect and responsibility? The VAST majority of people use their phones to stream an infinite sequence of clickbait, ai slop, and conspiracies for 6 to 8 hours a day.
- esikich 15d agoI've worked with dozens of businesses over the years and you can't even get businesses with real money and consequences on the line to follow basic security practices. My current project is updating dozens of windows domain controllers that are still on 2012 R2. Aka critical infrastructure that hasn't been getting updates for years.
- gmueckl 15d agoRegulation is already addressing that. I encourage you to read up on the Cyber Resilience Act.
- lovasoa 15d agoWe could force Google to operate its app review service independently. Users could use it and pay for it, or alternatives. Currently Google forces everyone to use their own mediocre service and pay for it without knowing exactly where and how much you pay.
- yosef123 15d agoAnd what do windows / linux / macos do about apps getting hacked to billions of pc's simultaneously? How is that a new problem?
- Frieren 15d agoIf libraries didn't exist could not be created today. People tend to say that "it is impossible" when it actually only needs to be well organized. Splitting git tech-monopolies it is a survival need. Or we do it, or we will end up with a collapsed society. Entities that spy on all citizens and gatekeep access to news and services are contrary to basic human rights and democracy.
- no-name-here 15d ago> macos MacOS has been moving to a more locked down model over the years - increasingly difficult to install unsigned applications, SIP, etc. > Windows I think Windows is incredibly impressive for its ability to run binaries from many years ago, but I don't think there's much people would point to as a positive regarding Windows’ approach to app security.
- oblio 15d ago> but I don't think there's much people would point to as a positive regarding Windows’ approach to app security. Yet life in Windows land is perfectly fine in 2026 and has been for at least 2 decades. If Windows, which started at the bottom of the barrel security wise can make it, surely we can have more modern OSes that make freedom bearable?
- pjc50 15d agoI wonder if people would be happy replacing the "Google approves developers" system with a "government requires your ID and address on file so you can be held liable for your apps" system. I suspect not.
- drdexebtjl 15d agoWhat for? Malicious actors have no shortage of stolen identities.
- Frieren 15d agoThat is already a requirement in any civilized country. You cannot run a business without a registered ID, address, etc. for tax purposes. For free (like for real no microtransactions) that is different. For the rest, they already have that.
- BiteCode_dev 15d agoIt's virtually the case, google and apple accounts require ID verification, which in turn can be requested by the gov in case of an investigation.
- zzril 15d agoIf you don't agree with a decision made by your government, you can vote for someone else next time. If you don't agree with a decision made by Google, what do you do?
- freedomben 15d agoThe people I vote for never win. Am I really any more empowered with the government than I am with Google? At least with Google I can de-google my life (with some significant losses of convenience, but it is doable)
- zzril 15d agoPersonally, I find it easier to live with a decision I don't support if I was simply out-numbered in a fair vote, rather than out-powered by some random company on some random continent. As for doing without Google, I'm kinda doing that myself (using a Linux phone even). But tbh, I think that nowadays moving to another country to escape a government you fundamentally disagree with is easier than moving away from Google.
- duskdozer 15d agoThat's a tangential issue. 1. don't force auto-updates 2. still review apps uploaded to Google Play, but don't force users to use Google Play If the concern is what if users use an alternate source for apps and those have viruses, then.... okay. If the user wants to stay with strictly Google-vetted apps, they can. If desired, you could have an option on setup that users could choose to select that would put the device in a restricted mode that can only use apps installed from Google Play. But the motivation here isn't just security, it's control. Google doesn't want anyone to have an Android device that is independent of Google services.
- MRtecno98 15d ago> If the concern is what if users use an alternate source for apps and those have viruses, then.... okay. If the user wants to stay with strictly Google-vetted apps, they can. If desired, you could have an option on setup that users could choose to select that would put the device in a restricted mode that can only use apps installed from Google Play. So this doesn't solve the issue pointed in the OP. > don't force auto-updates I'm sure everyone would love non-technical people to stay behind dozens of security patches for apps they may use everyday because they forgot to press update.
- Forgeties79 15d ago>So this doesn't solve the issue pointed in the OP. Yes it does. This is their point: > The fact that we cannot download and install software from the internet onto our phones JUST like we can do with our computers is a symbol of our inept and ineffective politicians. It should be as easy for me to use an alternate storefront - or download directly from a site - straight to my phone. The googleplay store, which is (somewhat) curated and (generally) "safer" can also exist. I, as a user, get to decide which path I want to take. This is literally no different from my desktop and laptop, we already live this life. MacOS allows me to download .dmg files and install (though they are admittedly getting increasingly annoying/friction-y about it) at my own risk. Why should my phone be any different? It’s a small computer. That’s it. It’s about user choice. It’s my hardware, so I can do with it what I want so long as I’m not using it to inflict harm on others.
- basilikum 15d agoPeople accidentally hurt themselves with kitchen knives every day. They are also very often used for violent crimes. Clearly we need to regulate the kitchen knife industry more. There should be a central authority that sells authorized kitchen knives with at max 6cm length and all other knives should only be available to certified chefs. Once we have outlawed the longer knives and strong restrictions on ordinary kitchen tools become normal we should just outlaw knives altogether. You can still hurt yourself with a short knife. Only chefs should ever be allowed to own such a dangerous tool. Just buy or order readily prepared food. Why would you do this weird nerd thing called cooking anyway? Just choose from the official list of allowed foods. The idea that we have to prevent people from being in control of their own computers — that's what a smartphone is — is deeply dystopian and authoritarian.
- bluefirebrand 15d ago> People accidentally hurt themselves with kitchen knives every day. They are also very often used for violent crimes People are rightfully nervous when they see someone walking down the street swinging a knife i.e openly misusing it or treating it casually People don't realize how much software is being misused or treated too casually. They might be similarly bothered by lax security on databases and data leaks if they realized that it represented a threat to them
- basilikum 15d agoYes, hold people accountable for their actions. Don't take away their freedom. We may prohibit individual actions that involve a general tool when they harm others. That is compatible with a free society. We may not prohibit fundamental tools¹ That is fundamentally incompatible with a free society. Especially when that tool forms the infrastructure for the flow of information and free speech. [1] General purpose computing
- Buttons840 15d agoHow about the same thing we do when companies leak half-the-nation's personal data twice a month. Nothing. When companies get hacked and millions lose their personal data, nobody cares. When individuals get hacked, it's a major issue that justifies locking down consumer's hardware to protect them from the burden of controlling their own devices. See how that works?
- miroljub 15d ago> And what should we do about apps' getting hacked, sending out malicious updates that get auto-updated and thereby infecting tens of millions or billions of phones simultaneously? "Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety."
- rock_artist 15d agoWe already had enough proof of vulnerabilities in the OS code and Manufacturers (eg. Samsung/Lenovo/etc privileged apps), there were enough reviewed apps that were used for fraud or access as bad actors. My banking works in my 'unprotected' computer browser. So I'd expect giving anyone equivalent freedom. I don't mind if there's a default for gate-keepers as long as they allow competition. but I would expect to have same freedom on my mobile devices as on my laptop.
- yacthing 15d agoDo people not remember the days of viruses destroying computers? They were a massive issue before, and now they're barely a thought for most people. These review processes have been good for the general population.
- bronson 15d agoWhat review processes on computers?
- pflenker 15d agoI didn’t write the previous comment, but I think the point here is that there is a long-running trend aiming to protect users both from malicious intent and to a certain extent from themselves. In the past, viruses had it easy to infect and spread computers because of both inattentive users clicking on mails claiming someone loved them, and the default access mode for any user granting them admin access. Even though review processeses generally do not exist for computers, they are part of that same trend.
- nekooooo 15d agomac app store / windows app store
- dazgjkyfedbu 15d agoAnd outside stores we have Windows’ UAC and Mac’s annoying-but-understandable “this dmg is sus” dialogues. Granted they are review processes but they’re often what keeps common users from wrecking their devices.
- rpdillon 15d agoThe app stores are neither necessary nor sufficient to curb malicious software. Conflating the centralized app stores with safety is a mistake that only serves the gatekeepers.
- charcircuit 15d agoJust because something is not perfect that does not mean it's worthless. Most things security things operate this way where it's impossible to stop all malware or attacks.
- rpdillon 15d agoWhen analyzing whether something is a net good for society, I look not only at the value it brings, but the cost that it brings. The mobile ecosystem normalizing the idea that the vendor that sold you your everyday computing device is the sole arbiter of what can run on that device is of enormous cost to society, but anytime anyone brings that up, there's an immediate retort bringing fear, uncertainty, and doubt about software obtained outside of those centralized silos. As I've said countless times before, the answer is clear. Operating systems can install software from repositories. The vendor of the operating system can provide a default set of repositories. Third parties can also provide their own repositories. Device owners can choose what repositories to install software from. Saying that there can only be one true repository is carrying water for trillion dollar companies to further extract money from their customers.
- fsflover 15d agohttps://news.ycombinator.com/item?id=49731273 https://news.ycombinator.com/item?id=49731273