And unfortunately, this seems to be the case with a lot of HN commenters as well.
And unfortunately, this seems to be the case with a lot of HN commenters as well.
I think asking consumers to evaluate risk of installing third party apps and manage permissions is insane. My phone runs iOS. My family the same. The volume of malware in the Play Store alone, much less in the sideloading community is mind boggling. If I ran Android I would only install software that I had written myself or come from a trusted vendor, and only use a browser (probably not Chrome even, but Firefox) for any third party content.
Any anti-walled-garden screed has to grapple with the fact that in the real world, the walled garden protects people from mass data theft and infiltration. Windows used to be like this, before many more users switched to Mac (which is harder, but not impossible) to backdoor. Replicating the internet security environment of the late 90s but on our phones would be a disaster for the technology-using world.
I'm a free software nerd and I run LineageOS-sans-Google on my mobile device. I get the vast majority of my software through F-Droid, which works like a GNU/Linux distribution - they build all packages from source and sign with their own key. Only time I would sideload a package is if it's not available in F-Droid (because it's proprietary - although I've since found out about Yalp and use that instead) or if I'm building it myself. It works well enough for me.
I think the objectionable part of a walled garden, at least to a free software nerd, is the walled part. I appreciate the option of being able to step outside if I feel I need to.
"In 2016, the annual probability that a user downloaded a PHA (potentially harmful applications) from Google Play was .04% and we reduced that by 50% in 2017 for an annual average of .02%.
In 2017, downloading a PHA from Google Play was less likely than the odds of an asteroid hitting the earth."
Source: https://source.android.com/security/reports/Google_Android_S...
Is it? What do you think billions of people using Windows have done for decades?
Now the crux is this. In the 80s, 90s and arguably most of the 00's the average Joe and average Katey didn't store 90% of their personal secrets, nude photos, diaries, drug deal receipts, etc... on their desktops and later laptop computers. It wasn't until this decade that such massive amounts of personal information started to become digital. Yes very likely I among thousands of HNs had already crazy personal lives going back to the mid-80s on a desktop hard drive sitting in some dump right now. But hey, at least they barely work and CC info is probably stale.
But today, the environment is much different. I'm not arguing that what Apple and Google is OK, but at least they got some kind of notion that free-for-all might not be appropriate right now.
It might take some time but I definitely welcome new models. For example: * Certified third party app stores * Independent Software Certifiers
It can be up to the user to decide if they want to either use a specific store or decide to specifically trust the certificate of an independent software certifier. And at that point Google could, for example, treat the app as a pass through on their own store. The software certifiers will need to keep a reputation up, for example.
I know I'm providing simple examples here - not that I want to discuss in detail on HN the finer points of these ideas - but that I want there to BE another way that can allow software to be sold online, without the 30% Apple markup that chokes the independent software vendors out there.
The problem here is not a lack of competition. Ultimately, there needs to be one default software repository that people can trust -- you can't have a free-for-all here for the same reason you can't have a free-for-all for software in general. The profit motive is the problem.