Depends on who "we" are. Some people also wanted a hassle free device, which only runs curated apps, and that keeps the whole experience more secure, unified, private, etc that a "open for all" environment.
Depends on who "we" are. Some people also wanted a hassle free device, which only runs curated apps, and that keeps the whole experience more secure, unified, private, etc that a "open for all" environment.
To serve this kind of users I think what Apple does is perhaps all right. What I criticize strongly is that there is no option for experienced users (besides jailbreaking) to free themselves (also completely) from this walled garden - ideally in a way that allows users to free themselves only for certain security aspects so that they still have the security advantages of the prohibitions that they don't deactivate.
Is it now possible to allocate executable memory (e.g. for development apps or writing a JIT compiler)? Is it now possible to write apps that have root permissions?
Not all the time, but sometimes - both under GNU/Linux and Windows - I want to/have to run an application with root/admin permissions.
As a passenger I suspect you would expect different standards from an Aircraft autopilot than a cellphone. But, there is a lot to be learned from system that just work.
From the hacker ethics by Stephen Levy:
> https://en.wikipedia.org/w/index.php?title=Hacker_ethic&oldi...
"Access to computers—and anything which might teach you something about the way the world works—should be unlimited and total. Always yield to the Hands-On Imperative!
Levy is recounting hackers' abilities to learn and build upon pre-existing ideas and systems. He believes that access gives hackers the opportunity to take things apart, fix, or improve upon them and to learn and understand how they work. This gives them the knowledge to create new and even more interesting things. Access aids the expansion of technology."
This is what spontaneously comes to my mind. But if I reflected for some time probably more things would come to my mind.
You are not a hacker.
The willingness to look under the hood or desire to at least be able to do so is a rather universal property of hackers.
You're putting me into a category (or excluding me from one) based on your own subjective opinion on the meaning of "hacker".
I don't really care for the label, but I think you are probably still wrong. Just because I have no interest in doing this with my phone, doesn't mean I don't elsewhere in my life. For example, you don't know about the time I took a MIDI controller apart and nodded it to add more functionality (both physical hardware and software). Or the time I spent reverse engineering the Diameter protocol with wireshark (yes I have used it) so I could figure out how to talk to another system (technically this was for work, but I didn't have to inspect the packets to learn how to use it), or any time I've stepped through a binary in a debugger to see what it does, or inspected some source code, or the time I tried to fool RF sensors with a home-made EMP device, or written some utility or otherwise hacked the world to do what I wanted it to. Yes, I am willing to look under the hood if it helps achieve my goals or if it's fun to do so.
Yet somehow all of that is irrelevant because I have no desire to do any of that on my cell phone. Or maybe the world isn't as black and white as you're making it out to be.
The iPhone offers a safe environment for you to play in. Root access is fundamentally incompatible with that idea. If you want a device that lets you shoot yourself in the foot, get something else.
Are there other restrictions on apps installed via Xcode today? E.g do they work for a limited time? Or work only on devices approved in some way?
Thanks!
I wish there were more than two options, but the modern mobile market is still only about 10 years old.
The SafetyNet stuff is somewhat understandable for banking apps but it means rooting, Xposed modules and custom Android builds is out of the question, taking away a lot of freedom.
E.g., I guess it could be code-signed and that the apps that use it have to check the signature. That uses a private key that "FakeSafetyNet" couldn't duplicate (well, assuming the SafetyNet people could keep it a secrect). It also incorporates a hash of the binary being signed so that FakeSafetyNet couldn't get away with just swiping the signature from SafetyNet to present as its own (the binary hash of FakeSafetyNet wouldn't match the signature).
I'm just speculating here, though.
Xposed is a bit like torrents, jailbreaking, etc. A lot of people use it to pirate stuff or to cheat in games but there's also genuinly useful usage like:
• why does my banking app not allow me to take a screenshot?
• root permissons for Greenify and Amplify so I can make my battery last for days
• better privacy management than what Google only recently implemented
[1] https://phoneia.com/google-updated-safety-net-and-there-is-n...
That's my main gripe as well. I'm currently using a Nexus 5 with Sailfish OS as my daily driver, but it's hard. I really do not have the time anymore like I did in the past to make it all work.
I'm running it with Alien Dalvik so that I can run WhatsApp and some other Android apps that do not have a native version yet. Without that it wouldn't really be possible.
(The reason I'm testing SFOS out is that Jolla (the developer of Sailfish OS) has a deal with Sony to release it on their Xperia X on the near future. Also Jolla's got a deal with Russia as well, because more entities are worried about the walled gardens.)
Isn't Android (at least stock) more open, if one so wishes?
* If you pay them $500+ for the computer
Freedom is a good thing, even if it comes at the price of some risk, no matter what the context.
Besides the walled garden of Apple is not so walled - you can install any app you want on your iDevice, as long as you have access to Xcode (which is free). It is the access to the marketing and reach of App Store that Apple denies.
Yes, but the point was that people do not always realize the consequences of their choices, not that there were no differences.
> Do you support Amazon allowing sellers of counterfeit goods on Amazon Marketplace?
I don't support the Amazon 'marketplace' at all, Amazon should take full responsibility for anything sold through Amazon.com and if they allow counterfeit merchandise on their store that should be their problem, not the problem of their end users. And there is plenty of counterfeit merchandise on Amazon so I do not get what the point is, unless you wanted to make the point that in spite of being curated Amazon fails horribly at keeping their store in good shape.
> Besides the walled garden of Apple is not so walled - you can install any app you want on your iDevice, as long as you have access to Xcode (which is free).
That's fine, but for your regular end-user this has been made so difficult that it is something only developers will use.
> It is the access to the marketing and reach of App Store that Apple denies.
No, it goes much further than that. To all intents and purposes if your app is not in the app store then it doesn't exist because iDevices users think that that is the only way apps can go on their devices.
You want Amazon to take full responsibility for their merchandise, but yet okay with Apple not doing the same thing.
Amazon has to take the same responsibility with goods, as Apple has with apps.
Apple does not have the same kind of duties when it comes to apps in the Apple app-store, they have created a de-facto monopoly on the channel between the people programming applications for ios and their customers.
And comparisons with police states or monopolies are just ludicrous. With police state you have no choice, but with app ecosystems you are free to choose another (yes, with a different phone - but you don't buy a $700 phone by mistake or chance). And Apple is not a monopoly, there are plenty of other viable options.
This kind of hyperbole isn't helpful. The differences between voting in a police state and using a walled garden app ecosystem run by a private company should be obvious.
> Freedom is a good thing, even if it comes at the price of some risk, no matter what the context.
What about the freedom to choose an application platform?
Since I'm sure I need to make this disclaimer, I don't own any Apple (or Windows) devices aside from my work-issued macbook.
It is helpful in the sense that it points out that people will often do things that have far reaching consequences out of their free will because they do not realize the long term effects.
> The differences between voting in a police state and using a walled garden app ecosystem run by a private company should be obvious.
Yes, but in the one case people vote with their ballots, in the other the vote with their dollars. In both cases the long term effects are negatives but since those effects are still safely over the horizon we can pretend that they don't exist. By the time those effects are felt it is too late to change course.
> What about the freedom to choose an application platform?
That would be fine with me, but only if the hardware were 'open' enough by default that third party application platforms would have a chance of making it to single digit percentage penetration.
> Since I'm sure I need to make this disclaimer, I don't own any Apple (or Windows) devices aside from my work-issued macbook.
I don't care what you use or why, what matters to me is that there is - at least in the mobile space - the choice between Google on the one side and Apple on the other and that both of those have substantial shortcomings when it comes to the freedoms they afford their users.
With Google you'll be tracked from here to kingdom come and with Apple you're going to be handed a smart terminal. Neither of those choices appeals to me.
This article [0] has made points that I'm not certain I completely agree with, but has done enough for me to suggest that my original position might need updating.
The point being, essentially, that at some point we might need to consider the trade off of who we're actually afraid of and where we can get the best protection as part of a trade-off, since things like "freedom", "risk", "security", and "privacy" aren't absolutes in any meaningful way.
[0] http://www.newstatesman.com/2015/11/coming-anarchy-john-gray...
Or how about it's along the vast majority of the people merely wanting the police to guarantee safe cities?
You don't live in your mobile phone: you use it.
>Freedom is a good thing, even if it comes at the price of some risk, no matter what the context.
"No matter what the context" is BS. I presume you lock your house doors or wear a safety belt -- sacrificing freedom of movement for more security.
> Or how about it's along the vast majority of the people merely wanting the police to guarantee safe cities?
Which more often than not includes being safe from the police, and that's where the problem lies. This sort of power is bound to be abused.
> "No matter what the context" is BS. I presume you lock your house doors or wear a safety belt -- sacrificing freedom of movement for more security.
Interesting. I've lived in places where unlocked doors were the norm, the village where I live (20 Km from Amsterdam) still has plenty of unlocked doors. People wear safety belts because there are no downsides and because they are required by law so that stretched analogy doesn't hold.
Did you count Android amongst Linux? It is after all...
The Android eco-system does everything it can to bury the fact that it uses Linux under the hood, and it is relegated to the role of a fancy HAL.
Android is all about Java.
The NDK is there as layer for implementing Java native methods, games and high performance audio, and general purpose native libraries from other OSes.
This is what you are allowed to call from C and C++ on Android:
https://developer.android.com/ndk/reference/index.html
https://developer.android.com/ndk/guides/stable_apis.html
Trying to call anything else terminates the application as of Android 7.
https://developer.android.com/about/versions/nougat/android-...
As of the upcoming Android 8, calling syscalls outside of what libc requires leads to application termination as well.
https://developer.android.com/preview/behavior-changes.html#...
Basically nothing really UNIX specific and could be implemented with any other kind of kernel (hence Fuchsia).
Think what? That Linux is malware-free? If you're addressing me only, I'm just asking for clarity on the dataset in question, not expressing an opinion about the safety of the platform.
Given the OS architecture Google can easily announce a version using other kernel, given that there is very little UNIX specific on what can be done with public NDK APIs.
Only those customising Android builds would be impacted.
An estimate 99.99% of the Linux software I use is from a curated repository. Yes, I could just download src.tar.gz and ‘make install‘ but I prefer the safer more convenient alternative.
It is the inability for mortals to install stuff from anywhere but the App store that causes the curation policy to be an issue.
Every human is mortal.
Thus unless you were implying non-human mortals, your point is stale and no longer valid.
When you are in a collision with out a seat belt more often than not your body becomes a 100 pound plus projectile going at non trivial speed that could easily kill some one.
Consequently even libertarians might be for seat belt laws (unless of course you are on private roads).
What was it people used to say about Apple and he perceived lack of viruses and malware issues? Security through obscurity.
> I've lived in places where unlocked doors were the norm, the village where I live (20 Km from Amsterdam) still has plenty of unlocked doors.
Arguably that experience is an edge-case, at best annecdata.
> People wear safety belts because there are no downsides and because they are required by law so that stretched analogy doesn't hold.
If they are required by law, does that not limit your freedom of choice? Does this not stretch your own limited analogy?
One could argue that no one was forced to install those apps that always tracked them, or that they could manually switch between the options. However the small minority of people who care about the privacy of their location will now have a lot more apps available to them with less hassle, because Apple is deciding to enforce a rule.
I don't think these new guidelines about executable code in education apps will be a problem, but I can imagine dropping the restriction altogether allowing developers to take advantage of users who aren't vigilant, or simply making people have to be much more suspicious about everything they allow on their phone.
That's a shallow quote, though. You're right, on the face of it – freedom is a good thing. But we accept compromises on absolute, unbridled freedom all the time, in order to trade of some other desirable outcome.
I would be concerned if computers generally were locked-down. But they aren't – competitors to iPhones are freely available, and desktop & laptop computers are ubiquitous. I will continue to oppose restraints on what can be done with them, but the freedom to choose a curated garden is also a freedom that should be respected.
I don't think most people know what they want. They've never understood the trade-off. Instead they just go to their local electronics supplier and take something off the shelf.
You don't have to be a lawyer to know that if a person enters a contract that's cheating them? They probably wouldn't do it if they knew. You don't have to want the world to all be lawyers. All that's happening here is that one person is saying folks are happy with a trade and another person is saying most folks don't understand the trade. Professions, skillsets, or how I'd like the world to be have nothing to do with it.
I'd agree there is a trade, I disagree that it is uninformed. My experience with consumers says that they just do not value the loss of control within the same order of magnitude as they value convenience and reliability.
Having the freedom to repair or modify your car does not mean you are a "wannabe mechanic". It may mean that in rare situations, but most people utilize that freedom when they take their car to for maintenance or repair at an independent mechanic. Locking down a device isn't necessary to provide a curated market. Apple could achieve a similar limited-market by including some kind of warranty with apps purchased through their curated store to increase confidence that their curation guarantees a minimum level of quality/security)
This isn't about people wanting to be developers (or mechanics); it's about property rights. Are you buying your phone, or are you leasing it? Apple says[3] "buy" in the page title (and the URL!). The software industry - and recently John Deere - like to pretend that copyright law and carefully worded contracts of adhesion give them de facto ownership over anything by adding software. This misuse of copyright[4] is an attack on property rights. There are many ways to provide convenience, security. Guaranteeing some amount of quality in products or services does not require giving up your ability to own modern goods.
[1] https://www.law.cornell.edu/uscode/text/15/2302#c
[2] http://www.taftlaw.com/news/publications/detail/1247-ftc-cla...
[3] https://www.apple.com/iphone/buy/
[4] https://apps.americanbar.org/litigation/litigationnews/pract...
I know I did. And I'm a techie. I just don't like fiddling with my hardware.
>Or did the industry quickly lock hardware devices into little gadgets for generating income?
Well, considering that Linux as a Desktop OS is totally open but it's still at very low single digits for desktop use, and that all the "comes with Linux pre-installed" ventures failed to gain any traction, I'd say lots of people don't care for that kind of openness at all over use of use, practicality, polish, etc.
Not to mention that mobile devices are now far less locked than they used to be for the average user. For the first 10 years of mobile phones, they came just with the apps that the vendor offered and no APIs, or very limited crapware (e.g. in mobile Java) -- now there are 1.5 million apps to chose from, many of incredible quality.
The first ten years were 1983 (release of the DynaTAC 8000x) to 1993. I don't think they came with any apps at all.
If you mean pre-iPhone, then it's not true; I was running my own Python scripts (which could use the GPS, camera, etc) on my S60 before that, using an interpreter provided by Nokia itself.
One of those mobile crapware Java applications was Google Maps actually.
What is your suggested alternative: Android? Functionally speaking, how is Android different? That's all consumers care, and should care, about: How does the difference affect my life. They don't care about your grand philosophical argument. If Apple's walled garden actually affected people's lives, they would care. It doesn't. They don't.
But Apple fails to meet this wish, too. If the curation consists of barely keeping out the absolutely worst of abysmal stuff, but allows regular crap apps, that does not count as "curated".
Well, it does, within reason.
If they put out apps just because they were crap (subjectively) then devs and press would be shouting bloody murder.
But they do stop the riff raff -- at least better than the "anything goes" camp.
http://www.computerworld.com/article/2475964/mobile-security...
https://arstechnica.com/security/2017/03/preinstalled-malwar...
https://medium.com/@johnnylin/how-to-make-80-000-per-month-o...
https://news.ycombinator.com/item?id=14526156
In fact, app store is opposite of all these qualities. Secure? It's provided by sandboxing, not app censorship. But almost every popular game in app store will read your contacts and send to its server. Unified? No one, except for top companies are able to follow UI guidelines, and most apps has weird UI. Even good apps have over-use of arcane swipe actions which makes them un-unified. Private? Most apps are very privacy-invasive. Even you are making app as a hobby, you will likely use privacy-invasive ad networks in order to pay back $100/year ad store fee.
Only if you let it.
> No one, except for top companies are able to follow UI guidelines, and most apps has weird UI.
Hmm, I'm not a top company but I try to follow the UI guidelines. In fact, by default, if you use native controls, you're doing that for free!
> Even you are making app as a hobby, you will likely use privacy-invasive ad networks in order to pay back $100/year ad store fee.
That's only if you want to make money. Some people don't; they do it just for fun.