3 ms·
The expectations of desktop platforms to behave the way they do is a holdover of early computing not giving much regard to malicious actors. Having a system whe
by skorp01 13d ago
The expectations of desktop platforms to behave the way they do is a holdover of early computing not giving much regard to malicious actors. Having a system where you can run a binary and grant it admin/superuser permissions, giving it widespread and dangerous access across the entire system, isn't how I personally want to do my computing.
You seem to be conflating the ecosystems (which I concede are largely profit-driven), and the platform architecture. The security models that include sandboxing, MAC/SELinux, Verified Boot, and many more; are unequivocally pro-user.
I get it seems like we're speaking of totally different things but hopefully I can bridge that. You having "freedom" to have runtime root access means that any malicious actor, rogue binary, etc. also has that freedom to run amok on your machine and that access cannot be so easily taken back.
I don't know how to respond to your comment about rules other than to say that it's incredibly easy to demonstrate being wrong.
Mobile OSes like AOSP have a much better ability for you to set rules. Access permissions for microphone, camera, other sensors, network, filesystem, are HEAVILY gated by the system which enforces the rules that you choose to set.
Desktop platforms are largely ill-equipped to handle this and are highly permissive. In fact, desktop OSes are frantically trying to copy mobile OS architecture:
MacOS SIP, flatpak, Wayland, Windows Virtualization based security, the list goes on and on.
Runtime root access would allow a malicious app to silently bypass every rule that you think you've set. It does the exact opposite of guaranteeing those rules.