The big cloud providers will also, over time, shape what's available in hardware in a way that won't benefit on-premise customers.
When the network becomes free, all will be lost.
That's what I'm guessing anyway.
It's for good reason that Tech Solidarity and other security-conscious organizations recommend using iOS and Chromebooks where possible: https://techsolidarity.org/resources/basic_security.htm
Of course, we must fight tooth and nail against any regulations that would restrict access to general-purpose computing, or put limits on connecting a general-purpose computer to the Internet. But it's important to remember that there are absolutely legitimate reasons to use and recommend locked-down machines, and that the most technically adept of us will use a combination of both categories of computing device in our lives.
I like to think of a general purpose computer like a giant truck: great if you like that kind of thing, but not for everyone.
Using various Ubuntu-based distros and Free Software apps over the last 8 years, I have never felt like any program was overstepping the boundaries.
http://download.com? Now owned by CNET, and full of sketchiness.
Or maybe you like http://freeware.com? Oh, snap, it's down and parked by a squatter now.
Or maybe an open source site? How about https://sourceforge.net? How'd that work out?
Could start by installing Java, let's see, oracle.com, click, ah, what's this? It's installing the Yahoo! browser toolbar by default??!!!
Yeah. Curated.
And even if you do manage to get a curated software store without lockdown that has a business model, it's not clear to me how you solve the problem of people sharing passwords with sketchy family members and friends who then install hidden software that secretly, behind their back, stalks them without so much as an informational prompt or opt-in.
No, I think there are good reasons for having devices somewhat locked down, especially when it's being done for the sake of the end user.
And of course Steam, GoG, and the HumbleStore provide curated repositories for proprietary games on many platforms.
I guess that's a fair use case for locking down the OS.
But when it comes to various sites giving you bad software, how is locking the device and not giving the user control supposed to help? Any security measures like sandboxing could exist on a device without taking control from the user. And while installing zero programs is pretty secure, the user could make that choice without a lockdown.
> So, which curated software store/repo do you prefer?
Ninite is quite good. Other comments already pointed out various linux repos that do a very good job. Also look at the iOS store for something that has pretty aggressive quality control, even if the rules aren't perfect. (While iOS is locked down, the store would work the same if it wasn't.)
Don't want to deal with the official repository you can easily host your own and provide a package that adds your own repo and serves the latest and greatest version of your software. Want a solution that targets multiple distros and bundles deps there is no snappy.
Preventing untrusted users from installing software is also a solved problem. Require the root password or simply don't let them use sudo.
If you give morons and bad people physical access your machine AND permission to install software it seems to me that you have put you in a bad place where no amount of lockdown can render you safe.
Rather than make the futile effort to render your situation tenable when we know it wont how about we continue to improve actually feasible use cases?
You get this security in exchange for all your personal data being uploaded to their servers (for advertising to try and change your behavior for their clients, and for storage for your government, and perhaps others), and Google getting to decide which apps you can run, and which apps developers can publish in the store.
As long as you stay aligned with the interests of the shareholders of the ad-surveillance company (and the government) it's a great deal.
You're also not forced to use Google's Chrome Web Store (except on Windows with the official distribution of Chrome).
On top of that, Chromebooks are mostly used in an education environment where they are in fact locked down to Chrome OS for specific email address domains. Then the domain administrator can conveniently switch it into a brick.
General purpose computing is dependent on 2 things : ability to run your own programs AND the ability to lie about that fact to the network. Without the second the first is useless.
Google understands this subtle point, but it appears most people do not. So Google is exploiting our ignorance here.
I think with Apple it's more about allowing the end user (the real end user, not the end user's boyfriend/girlfriend/wife/husband, child/sibling/parent, boss/teacher/roommate etc.) to have control over their own information.
In order to enforce this end user control, Apple needs to lock out rogue programs. It can't do so 100%, but it tries to get as close as reasonably possible. They try even harder with mobile devices, because mobile devices tend to be so personal and capture so much private information of one individual.
Apple has every reason to help your mom/dad/boss/school ensure that you don't misuse THEIR property.
Your perspective seems to be mostly unfounded speculation that doesn't hold water.
That's the primary selling point. "We got this, don't look under the hood" Getting your own boot rom on there is a huge pain (I had to remove a screw off the main board) there were like ten steps I would never tell a non expert to attempt.
While you're correct that it's a pretty closed platform out of the box, you ultimately have more control over the platform than a typical x86 PC, if you go through the hoops of flashing your own Coreboot payload. The fact that it's hardware with official Coreboot support is notable, IMO.
[0] https://github.com/coreboot/coreboot/search?o=desc&q=google....
You can write and run arbitrary code on it, you can swap the OS, and you can even rebuild the firmware from source and flash it yourself (though at that point you will void the warranty since the firmware is in a position to cause hardware damage, but not for any of the other things). There is a local terminal emulator, and when you turn on developer mode you can have a local unix shell with mount and write access to removable disks, so you can image install media for an operating system. The boot firmware comes with SeaBIOS by default for the reason that Google (for whatever reason) wants you to be perfectly able to install bios-based operating systems as long as they're compatible with the hardware. If it's Linux, then any downstream hardware drivers involved are packaged in google's public kernel repositories, and if it's a userspace component, it's in the ChromiumOS repositories, where you can pull and build the entire operating system (aside from the pepper plugins for digital restrictions management and flash).
Seriously, try doing many of these things with a typical off-the-shelf Windows or Apple laptop and get back to me. On Windows laptops you need to jump through hoops to disable firmware features which prevent you from installing new operating systems, on Chromebooks it's well documented and has no effect on warranty or your ability to roll back the changes. Most (all?) windows laptops have no vendor-provided open source firmware, and most of them don't have even a third party one which works. To write an install disk on Windows, you need to install a third-party image burning application, and there's no guarantee that the firmware will even let you boot it. Many windows laptop manufacturers will either inconvenience or flat-out deny warranty claimants who have replaced the operating system on their laptop. Microsoft does not publish the source code of the NT kernel. Most Windows laptops contain at least one piece of hardware which is not adequately documented such that somebody could write a driver for it without reverse engineering.
Apple laptops are in some ways better, in some ways worse here. On the one hand, the firmware does not explicitly prevent you from booting third-party images, on the other hand, the firmware and hardware have undocumented behaviour which makes it exceedingly difficult to get most new operating systems to reliably boot and install on it. Usually even if yo u do manage to install and boot something, some important piece of hardware (the wireless chip, the display output multiplexer, the webcam, the touchpad) is either slightly or completely different from a documented counterpart, and takes months or years to be supported by anything except OS X and the first-party drivers on Windows. Darwin releases are usually eventually open source, Apple's compilers are partially open source, but also include several proprietary components. Most of the operating system libraries which weren't already available when they started are proprietary. Though on the plus side, you don't really need anything extra to write a boot disk for a third-party operating system. On the down, there is no provided firmware source code, and the system is sufficiently underdocumented that it's unlikely anyone will ever write an alternative firmware image for your given Apple laptop model.