3 ms·
"2. Our software vendors can push new software in automated updates..." Question: Why does the software need to be updated? Vendor: "Bug fixes." Question: Ca
by ised 11y ago
"2. Our software vendors can push new software in automated updates..."
Question: Why does the software need to be updated?
Vendor: "Bug fixes."
Question: Can I look at the source code?
Vendor: No.
I agree with agwa that this phenomenon of "automatic updates" goes well beyond root certificates and browser authors such as Microsoft. It is pervasive and seems to be growing.
Perhaps a related line of thought, I find it interesting that we are seeing some again pushing for enabling browsers to have more control over the user's computer. Simply put, as I see it, a user visits a webpage and someone else gets to run their code on the user's computer.
Why stop there? Why not have email attachments that open and execute automatically?
Originally there was the "Java applet" idea in the early days of the www. Then there was Adobe Flash. These days the idea it has several different working names. Obviously neither Java nor Flash is the language of choice. And the browser authors have something to try to put users' minds at ease: "sandboxing". But I see no difference in the issues this raises for users.
Is there any "sandboxing" for the browser itself? The browser and its authors are inherently trusted?
In the same way that root certificates installed on users' computers are "pre-approved"? Who approved them? Are users involved in that approval process?
If the certificate/code in question comes from the browser authors then it must be both necessary for and desired by each and every user?
The problem with automated updates from my perspective is that there are very few software authors who will not try to give me more than I actually need; if I am not careful I end up with the "kitchen sink". Without user intervention, software is like a gas: it will expand to fill space.
As for the CA system, I am my own CA root. The openssl binary is the antithesis of the so-called UNIX philosophy. How many things does it do? Perfect for an example program to include for "testing". This goes to agwa's comment. I use this software but I know it is quality control disaster. Keep those updates coming.
In any event, the only certificates I "trust" are ones which I did not obtain over an untrustworthy network, i.e., the internet. That number is of course zero.
I will sign a certificate to satisfy a browser, but that does not mean I "trust" any part of the process. In practice, outside of organizational use, I see the whole CA scheme as a joke. (But not that its implementation has impeded the success of e-commerce.)
As a user, I play along with SSL/TLS and certificates only to get today's software to work. That's it. A nuisance more than anything else.
- e12e 11y agoI agree with most of your points. One interesting thing with the new "office macro web" is that the sandboxing of js apps/domains is a little better/less convenient for the user than traditional file systems. If I install trollololz image messaging app in by ~/bin -- I've given the author access to all of my personal files -- because they're all readable by the user under which I'd run trolloloz. If I go to trollollz.com, it doesn't automatically have access to my gmail/outlook.com mail, google spreadsheets or dropbox files. Of course this is a usability problem, so now users move data to data-services like dropbox, and give apps/websites access to that data... We might have an opportunity here to give users an UX that works for more sensible compartmentalization of data/working ACL/capabilites -- but time is running out, as convenience chases security out of people's lives.