3 ms·
We already had enough proof of vulnerabilities in the OS code and Manufacturers (eg. Samsung/Lenovo/etc privileged apps), there were enough reviewed apps that w
by rock_artist 19d ago
We already had enough proof of vulnerabilities in the OS code and Manufacturers (eg. Samsung/Lenovo/etc privileged apps), there were enough reviewed apps that were used for fraud or access as bad actors.
My banking works in my 'unprotected' computer browser. So I'd expect giving anyone equivalent freedom. I don't mind if there's a default for gate-keepers as long as they allow competition. but I would expect to have same freedom on my mobile devices as on my laptop.
- yacthing 19d agoDo people not remember the days of viruses destroying computers? They were a massive issue before, and now they're barely a thought for most people. These review processes have been good for the general population.
- bronson 19d agoWhat review processes on computers?
- pflenker 19d agoI didn’t write the previous comment, but I think the point here is that there is a long-running trend aiming to protect users both from malicious intent and to a certain extent from themselves. In the past, viruses had it easy to infect and spread computers because of both inattentive users clicking on mails claiming someone loved them, and the default access mode for any user granting them admin access. Even though review processeses generally do not exist for computers, they are part of that same trend.
- nekooooo 19d agomac app store / windows app store
- dazgjkyfedbu 19d agoAnd outside stores we have Windows’ UAC and Mac’s annoying-but-understandable “this dmg is sus” dialogues. Granted they are review processes but they’re often what keeps common users from wrecking their devices.
- rock_artist 19d agoI believe people in HN also remember the days before we had MMUs. And I'm sure everyone remembers ransomware. No one is saying OS shouldn't have security measures, permissions/entitlements and app sandboxing, user land, etc. I still don't understand why my desktop/laptop is allowed to be 'owned' by me. but my iPhone is a closed-gardened where I'm just a guest in a device I own. and that's nearly what Google is now doing.
- oblio 19d ago> They were a massive issue before, and now they're barely a thought for most people. Even on desktops... where there are no such review processes. Apparently we've found other mechanisms to reduce those issues, without app stores everywhere.
- tredre3 19d agoThey're still very much a thing on desktop. You're not wrong that Windows got better at protecting itself, but I suspect the reason you don't hear about them is just that few people use desktops anymore (other than developers who, for obvious reasons, are typically less prone to be infected). Anecdotally, at least once a month for the past several years, I notice a youtube channel in my feed get hacked. Their usual content gets replaced with crypto, Roblox, or Elon/SpaceX spam. Big channels, small channels, it happens to them all. There's usually a post-mortem when they manage to regain control. Every time the infection happened through a virus attached to an email or by following a link on their discord. This kind of attack simply cannot happen on mobile (unless your phone is rooted and you have disabled all warnings).
- echelon 19d agoSandbox, ACL, scan, sign, revoke bad actors. We should have web installs by now. The only reason we don't is because Google and Apple like cash and their little monopolies are easy money. Big tech loves to "protect us". See Anthropic and OpenAI worried about intelligence. Google doesn't care that its AdSense ads marketplace is flooded with malware. Or that YouTube is rife with scams. Wonder why not. The blatant policy contradiction couldn't be because money, right?
- ignoramous 19d ago> We already had enough proof of vulnerabilities in the OS code and Manufacturers (eg. Samsung/Lenovo/etc privileged apps) Vulnerabilities aren't intentional. > reviewed apps that were used for fraud or access as bad actors The App Developer Verification program, Android Advanced Protection Mode, and Play Protect are all systems put in place in response to "bad actors".
- GuB-42 19d agoJust because there are known vulnerabilities don't mean we should drop other security features, this is the opposite in fact. Defense in depth, an OS-level vulnerability cannot be exploited if the attacker cannot access that part of the OS. And like it or not, the Play Store approval process is a security feature. It limits the ability of bad actors to run code on your phone and access data or exploit vulnerabilities they wouldn't be able to otherwise. Some get through, but it makes their life harder, again, defense in depth. Something can be both an anticompetitive practice and a security feature. As for banking in the browser, you can, but your bank probably doesn't like it. That's why they are pushing for browser attestation, or to force you to use the app. The banks would rather take that freedom away from everyone rather than giving it to everyone. And I suspect they do it for good (as in profitable) reasons, fraud costs them, it costs them more than what they would gain by being more open. If we want security features and freedom (which is the harder option), we need competition. If Google and Apple are the only players besides an insignificant minority, it is easy to lock software to these platforms, screw that weird guy with his Linux distro. Legislation is another option if the first one fails.