Windows 11, Amazon, and Uncomfortable Questions
commonsware.com
commonsware.com
The resigning stuff is because they alter the apps to fix dependence on Google play apis and gsuite apis. Developers were not interested in rebuilding their apps for fire and other devices without those apis baked in and this was a good solution to ease uptake for fire/Amazon app store.
Also note that ms will control this android os, so they already control the signature verification method. They could do this without you knowing very easily by just with something like carrying a second sig and hash of what they modified and the original partial sums from the original app. Google and amazon or any os supplier can.
Signature verification is only as strong as the verifier code.
Glad to burn karma to put data out there.
Except the article clearly states:
> Amazon wraps your app with code that enables the app to communicate with the Amazon Appstore client to collect analytics, evaluate and enforce program policies, and share aggregated information with you. Your app will always communicate with the Amazon Appstore client when it starts
Now, the original reason to do this might have been benign and well-intentioned, but the result is bad already. This is for now, who says they don't simply add ads like Google [0], or even without the developers knowledge like SF [1] once did? Ubuntu tried to only implement a search and it backfired badly [2], I hope this goes down a similar path.
As a side-note: Of course I'm very happy that competition to the PlayStore is getting some love. This is direly needed. But Microsoft could have gone with F-Droid easily. Trading a bad thing for something worse does not fill me with joy.
[0] https://news.ycombinator.com/item?id=27643208
[1] https://arstechnica.com/information-technology/2015/05/sourc...
[2] https://nakedsecurity.sophos.com/2012/11/01/ubuntu-search-am...
Slipping that in at the end really hurts your argument. Microsoft opting to use F-Driod would be worse than starting from scratch and only benefit F-Droid.
Presenting F-Droid as an equivalent to any of the large stores is like trying to say a lending library in someone's front yard is the equivalent to Barnes & Noble or Amazon.
It's borderline delusional to compare F-Droid to the big players in much the same way it's silly to compare FOSS apps like GIMP to Photoshop. Sure it performs the same core function but they're in completely different classes.
They aren't equivalents unless you willfully ignore a lot of differences and that is just dishonest.
You're exactly right; my thought process was "if they want to go with an existing store, F-Droid might be an option".
> Trying to censor or bully free-thinking users into accepting the narrow-minded marketing of large corporations like Microsoft and Amazon is arguably not this forum's highest and best use.
I think cptskippy just wanted to say that F-Droid is in no way a suitable replacement; since he read my comment in a different way, he just emphasized this more than necessary :)
> It's borderline delusional to compare F-Droid to the big players in much the same way it's silly to compare FOSS apps like GIMP to Photoshop. Sure it performs the same core function but they're in completely different classes.
I disagree with that. The software itself is clearly irrelevant in this case as they will hardly run the actual store app on windows and the required infrastructure is not a big problem for Microsoft. The existing app base is what matters.
To be fair, though, I wasn't aware of how alive the Amazon app store actually is.
One of the consequences of this is that apps refuse to start if they haven't been able to connect with the Store in the past `x` days.
It's absolutely terrible. Total amount of available apps is not a good metric for quality.
Curation models are better in that sense, because they have a limit that forces a quality filter. The alternative is just an evolution of the spam model. You see it with Google turning the web into blog spam, YouTube with videos, ebay/Amazon/aliexpress with "products", and the app stores with their 5million "apps".
It's not great, but it's significantly better (imho) than if they had exclusively chosen the Play Store. It's a creative way to gently pressure developers to publish to additional marketplaces, which indirectly pressures Apple since the Microsoft Store now doesn't force developers to route payments through their system (thusly reducing Microsoft's "cut" to 0% for many apps)
If the problem is that app developers don't want to fix dependencies on Google services, but Amazon has a tool to fix them automatically, why can't they just release the tool and let developers sign the output themselves? Sure, some devs might be too lazy to do it, but how does that justify forcing everyone to give up control over their signatures?
I would imagine the tool rebinds the Google APIs to Amazon's equivalent APIs rather than neutering them. Since Apps are relying on the API responses. I don't imagine Amazon wants Apps distributed outside their Store using their APIs and getting a free ride.
Am I missunderstanding things? Isn't the purpose of App Signing primarily for Google's software running on your device to verify Apps running in your device against public signatures Google holds on it's servers?
I understand there's a chain of custody and a developer can upload their App, then download it from the store and be confident it's what they uploaded. But Google now allows you to put your signing keys into their KeyStore on their servers. I guess you still have a copy and can verify an App is signed with your Key but since you didn't do the signing that isn't enough to ensure it was signed without modification.
In fact, Google is planning to soon force app developers to use this model, just like Amazon. Yes, it removes the ability for developers to know/control what code is running with their name attached to it, and it's bad regardless of who's doing it.
The primary (or at least original) purpose is to verify that app updates (or in some cases extensions/companion app that can directly access each other's data) are signed by the same key as the already installed app.
Though I supposed that these days PlayProtect will likely indeed check the signature against Google's database on first installation, too.
And if you are going to use Android App Bundles or whatever google is recommending, you'll be using Play App Signing.
I guess I'm just curious what "keys" amazon is forcing you to give up. I'm not sure they even care about your keys.
As I said in another comment, it's not any better when Google is doing it instead of Amazon.
> I guess I'm just curious what "keys" amazon is forcing you to give up. I'm not sure they even care about your keys.
If we're being literal, they're not forcing you to give up your keys. They're forcing you to give up control over what code gets signed as part of your application -- that is, control over which signatures are considered valid. The end user has no way to verify that the application is what you released; they can only verify that it's what Amazon (or Google) decided to distribute on your behalf.
Imagine if GitHub decided to take every repository with signed commits and rewrite it so that the code was signed by GitHub, instead of by the original authors. Why would anyone have a reason to trust those signatures?
Let me explain something clearly - most users are NOT checking developers signatures. The clients, their trust is in the google / amazon's of the world. What google and amazon are saying, and what users care about, is that this application went through whatever process google / amazon have to describe / disclose the developer and their details, whatever scans google / amazon do, whatever CDN distribution they use has not messed with things, whatever govt agencies / firewalls are between users and google / amazon have not messed with things etc etc.
Google already has access to users systems - if they want to root android they can (in most cases google play services has root already). Many users are more worried about bad behavior by apps on their system (and there is plenty of history of that behavior).
This also let's amazon / google etc re-target apps themselves. They can link to shim libraries to run on other platforms etc etc. The value there is high. Many developers aren't going to sort that type of stuff out.
This same model applies in open source. When Redhat / Fedora upgrade something, they can recompile their entire RHEL if they want to to target / work with whatever upgrade they've pushed. Again, users on redhat don't care about the developers signatures, they care about redhats.
Of course, on HN the outrage is going to be at Google, but most open source distros work exactly this way as well.
Microsoft has been a telemetry champion and has been collecting troves of personal data through Windows 10, all the while making it almost impossible for the average user to disable it (and re-enabling it with every major update).
So if Microsoft goes the same route as Amazon (resigning every app), it’s just a matter of choice between a rock and a hard place. On the other hand, even if they allow for the app developer to keep its signature, Microsoft is still probably very capable of gathering data and telemetry through their Android implementation.
Either way, and until it becomes illegal to collect data without explicit consent, I’m pretty sure we’re screwed…
From the user side, I am quite sure it is hurting the experience. One example is logins. MS is pretty bad about requiring logins for products which don't really require it in order to complete the user journey - for instance I bought the Halo collection on Steam, and in order to play an offline, single-player game I have to log into an MS account. As a result I haven't played the game in months, because I have to use this MS account that I don't even want to have, and I can't be bothered to reset the password for when there are other games I can play which just start up with no arbitrary hoop to jump through.
And what does MS actually get out of it? I guess they can optimize their dark UI patterns to be better at tricking people into setting Edge as their default browser?
Being data driven is good, but it seems to me it's not working if the end result is compromising the core user experience.
There are exceptions like Office and VSCode, but it seems like for the most part MS products are things which people curse under their breath and don't like to use. Part of that is because of things like how their aggressive approach to telemetry bleeds into the UX, and it just seems a bit off if the tool you have for optimizing your product is actively making it worse.
On the other hand, it's also trying to be a weird combination of Slack and Facebook at the same time (only less searchable than either) and that's pretty terrible.
It's also so much lighter on the computer than teams.
But once out of a call you end up in a messy maze of random cluttered functionality and different, confusing styles of chat options, integration with a bunch of stuff that on paper sounds like a good idea, but in reality is annoying as hell and hard to navigate.
These things still exist, and many companies still use focus groups and market research. The company I work for, for example, does this extensively because I'm in the healthcare space and the legal department doesn't want us collecting information about our users without them really really really knowing its happening.
Another example is MailChimp. It not only does video interviews with its users to determine how they use the product, it pays you for your time.
Microsoft has the money and staff to do this basic research. "Telemetry" is just a synonym for lazy and cheap.
For instance, you can track downloads, page views in documentation, the number of times a certain endpoint is pinged on the server etc. while still respecting the privacy of the user.
The practice to track a user's behavior across a wide array of products imo crosses a line, and is not needed to inform good product development.
A company could probably sell better to you if they hired a PI to follow your movements, and tapped your phone line, but that doesn't give them the right to do so.
The problem is that analytics in a vacuum are just as misleading as testimonial data, if not more so. "0.6% of users touvh XYZ and only use it for an average of 17 seconds per year" could mean that it's an unloved feature that can be sunset, or that it solves a single niche task very completely and perfectly, and ripping it out will cost those 0.6% of users five hours each to replace.
I work closely with telemetry data coming back from Windows devices. There's surely a line from collecting this telemetry to an answer to your question, but I've never heard anyone in our group talk about the profitability of this data. In fact, it costs a lot of money to process and store such huge data, which is absolutely a concern -- so there's strong belief (which I share) that this cost of business is worth it because it lets us make what I hope are good decisions about where we should focus our efforts.
The telemetry that comes back encompasses many dimensions of the user experience, and it helps us do things like figure out when an insider feature is ready to GA; what drivers or devices do poorly and how we can improve the experience; how accurately we can predict battery life; etc.
> they can optimize their dark UI patterns to be better at tricking people into setting Edge as their default browser?
I don't think whoever is in charge of 'tricking' people into using Edge actually have the kind of telemetry that most people think about with respect to Windows data collection. A lot of people think there's some sinister plot here -- apparently as evidenced by your phrasing. But if you look at the UI for default programs, it's really just a slightly annoying "are you sure?"-kind of message. (I don't use Edge by default, but I just reset my prefs to Edge then back, and I wasn't harassed again, so this isn't a persistent nagging.)
You do remember that Windows nowadays only shows "Battery xy %" instead of giving an estimated runtime, right? (Which is, btw., a "holy fuck what braindead idiot thought removing this is a good idea" moment, at first I thought Windows wasn't giving an estimate only in the first few minutes, but after a while I started googling around thinking that the lack of estimated runtime was a bug, but no, someone actually went in and removed it. A very clear and obvious example of actively, explicitly and intentionally user-hostile UX for what sure seems like no other reason than "we could, so we did".)
Apple claims they did it because the runtime estimate wasn't accurate enough. Maybe Microsoft's reason was the same. Though it does seem user hostile to remove it, unless the estimate was substantially off and there's no way to fix it.
I think the problem is that users expect percent charge to be a direct, linear correlate of time remaining, but battery discharge isn't linear. Even if it were, predicting time left is tough. Giving the user a percentage rather than a (likely incorrect) time estimate seems like the less bad approach.
Personally I don't use Windows on any of my laptops, so I only noticed this one day on my work laptop. On my Linux laptops my status bar is literally just doing a weighted average of "time_remaining = energy_remaining / current_power", which works rather nicely.
That a supposedly top-notch software company like Microsoft is trying to gaslight their users into "predicting battery life is like hard you know! We're gonna remove it because it's so inaccurate, it's basically unsolvable aha" makes me throw up a little, but is also such an accurate and damning reflection of the way these companies conduct themselves.
It seems like it would be trivial to change the default and leave the time estimate as an option.
Apple responding by hiding the estimate—even on their older computers, where it worked very well—struck me as utterly missing the point.
I used to pay hundred of dollars for Windows Pro licences for all my machines at home (desktop, self-built HTPC, self-built NAS etc). - After MS went overboard with telemetry, I switched to Linux on everything except my desktop.
Recently I set up two new machines (printer server and gaming server), in the past I would have bought two Windows licenses for those, but I didn't, and installed Linux instead.
That's more than AU $650 in missed sales for MS.[1]
I am aware that I am just one single data point with no statistical significance, but I can imagine I'm not the only person in the world who is bothered by this.
[1] One copy of Win 10 pro is currently sold for AU $339. https://www.microsoft.com/p/windows-10-pro/df77x4d43rkt
- breaking a user's multiboot
- deleting user data
Even if these are not bugs and merely the result of bad UX (lack of warnings and security for the user).
Deletion of all user data upon upgrade was a common 'problem' with earlier versions of Windows (I remember having such problems into the XP era, and I hear it happened to people on W10). Breaking other installs by MS is a common theme too in dual boot setups (whereas Linux bootloaders are more likely to pick up the Win install and offer access to it).
I remember vividly the last time it happened to me. I had been dual-booting Linux for some time (on a personal laptop dedicated to work). It was my first Linux OS, I was a newbie (precisely learning bash, programming for servers, etc). After some update, Win10 broke my dual boot. I was livid. It took me the better part of a weekend to fix it and avoid loosing all my work of several months (a lot of it was in the form of system files all over the place, I had no idea how to retrieve all that without ad hoc commands etc, and I had no idea what e.g. chroot was at the time. I learned, the hard way, haha — btw thx to the Arch Wiki for that weekend. It was a life saver).
The very next thing when I got access back to my Linux OS was to backup all my data, format everything and reinstall Linux fresh.
And that was it.
I've never used Windows ever since as my primary driver, only for testing purposes in VMs. That was 2016 iirc.
There are such things as showstoppers that make you instantly drop a product, never to look back. Microsoft's Windows desktop team never learned that, I don't know how they still pretend to be for "professionals". You don't do that to people who make a living with their computer (i.e. the vast majority of businesses nowadays).
I have tried mutiboot with different Linux distros too and had it broken too many times, eventually I got sick of this shit. Fixing the bootloader should be a simple process but requires you to sacrifice a goat.
Never multiboot again, if I need another OS it goes in a VM.
When I absolutely have to, I install another OS on a separate drive with it's own bootloader and select the one I want in BIOS. That is actually reliable and never breaks.
Will this effectively encapsulate the UEFI settings? I had a problem where Windows turned off the wifi module on my MoBo to "save power" and it messed up the wifi on Linux.
does that audience lacks of experience with developing software?
Someone looking in the window and making an inventory of all my furniture doesn't impact me in any way. But it's still an invasion of privacy and wrong from the standpoint of common human decency. A concept that has become lost to a generation that's become acclimated to thinking this is normal. It is not.
I have no idea where you're getting this from. Governments regularly perform national census, and collect data from all kinds of institutions to inform their policy. Banks constantly analyze your bank accounts and activity. Utilities meter your use for both billing and their own planning.
This is not someone "looking in the window" this is two parties (you and the company providing some service or product to you) needing to exchange data so each can do their work properly.
Those "privacy standards" you cite that have existed for centuries... that's not a thing. It seems to be based on falsifying the history and present of how humans organize and govern systems out of ignorance. Data gathering IS the "normal". Of course it's been very limited and cumbersome before, now it's easier thanks to IT.
So if your only argument is a vague discomfort from this not being "normal"... you have no argument.
>Those "privacy standards" you cite that have existed for centuries... that's not a thing. It seems to be based on falsifying the history and present of how humans organize and govern systems out of ignorance. Data gathering IS the "normal". Ever thought that you and parent live in different countries with a different value for privacy? Even a "simple" thing like a census in Germany led to Constitutional Court ruling and the establishment of a new right, that of informational self-determination. And that was in the eighties and it was about a census in the form of a total survey to be carried out door-to-door by civil servants or agents of the public administration.
Now you private companies fathering more data more often than ever before. So it's worse, calling that "normal" is strange.
Probably companies haven't been able to serve billions of individuals worldwide, so they had less data. Microsoft has more customers, and has more data to process.
No one here is describing WTF is this "data" harming them personally with. It's not personally identifiable, and it's extremely mundane. Surely Microsoft will destroy your life by having some stats on how often people in a given region play Solitaire.
In other words, for TV they paid a small portion of the audience to record and report their habits.
Telemetry involves everyone by default and it's hardly optional unless you decide to actively fight it - speaking about Microsoft Windows here. The choices offered by Microsoft doesn't offer users true control over data they gather and process; hell, that actually applies to other big companies as well - you have just the illusion you are in control of what they managed to collect about you and the vague assurances, promises that they aren't up to no good with that stuff.
Government will most likely benefit from planning its politics having the data gathered from census while Microsoft might or might not use the telemetry data and honestly, seeing what they did with Windows 10 over course of all its releases, it doesn't appear they do actually use that telemetry data for anything. They don't even bother with users, power users opinions regarding the features that are causing issues in Windows.
The electric company probably needs to know usage for billing. Microsoft does not need any information about Windows users for the product to work. Even things like fetching updates doesn't need to leak information, although I'll grant that it's a little bit more work to avoid leaking any data.
Honestly, it's amazing you can say this with a straight face? You don't think Microsoft needs to know which parts of its product crash or not, and are used or not, in order to deliver a well-working product?
I don't know if most of you here work with large-scale products, but Microsoft has no the luxury of going to every Windows user personally and asking them how's Windows and what you want more or and less of. That "conversation" happens through telemetry.
Just taking it from everyone without offering the ability to turn it off is very poor practice imo. I understand they want this data to improve stuff but I should have the ability to not contribute to it.
Proton's not perfect, but it's been mostly worth it for me not to have to boot windows.
I personally compile it myself off the AUR with the -O3 -march=native flags (look at the PKGBUILD for more details), and I get fewer FPS than Windows, yet more consistently than Wine. No microstuttering.
How much PII is really collected via W10 telemetry? Or is the amount of times you click the start menu, accidentally search for something via Bing, then close that window now considered personal information?
Not your computer. Not your data.
Unfortunately, Microsoft thinks otherwise. See the huge discussion here for example:
https://news.ycombinator.com/item?id=27629350
(tl;dr: thanks to Secure Boot, Microsoft had to give permission for Linux to boot.)
Also, don't forget the whole "Windows as a service" crap.
With industry privacy changes, having a persistent login at the OS level let's you do an end run around privacy protections in a browser, or incognito mode type stuff potentially.
I'm not sure how the terms of the integration go, this could be avoidable - and it would be awesome if it was possible to port F-Droid to Windows.
I always disable telemetry, but iphonesubmissions.apple.com:443, radarsubmissions.apple.com:443 and securemetrics.apple.com:443 are still contacted.
People messing with ocsp.apple.com:80 (https://github.com/StevenBlack/hosts/issues/1460) also need to be aware of ocsp2.apple.com:443.
The iAdSDK setting is somewhat respected, but all the Siri subdomains are pinged even if Siri is turned off.
Opening the App Store app, for example, sends your hardware serial number. Macs and iOS both maintain hardware-serial-linked 24/7 connections to Apple's push servers, too.
There aren't opt out UI settings available for the majority of Apple's phone-home.
0: ie, that windows doesn't really support APKs because it doesn't provide the APIs needed for them to work properly
My memory of the details is fading, thankfully, but I think side loading was disabled for 8.0 and 8.1 (without a key), and the restrictions were removed or relaxed in 8.2.
0: Provided it runs on your OS in the first place, obviously; adding support for APKs in general is a meaningful feature, in the same way as wine adding support for EXEs on linux.
1: In the same windows has been able run arbitrary EXEs since... well the entire time it's existed, give or take incremental extensions and revisions of the file format.
Here some news for you. You can even side load Exe files and MSI files. See, nothing special. APK yes, side loading no.
Actually, it is:
"Sideloading describes the process of transferring files between two local devices, in particular between a computer and a mobile device such as a mobile phone, smartphone, PDA, tablet, portable media player or e-reader." https://en.m.wikipedia.org/wiki/Sideloading
Additionally side loading refers to mobile devices not desktop PCs.
Words can have different meanings under different contexts, and I'm providing you that context, which is important for understanding what people are talking about here. Please stop being obtuse.
Another question is, how does Amazon solve the GMS problem? Do they provide their own shim library, modify the apps somehow, or something else? Could the whole Windows 11 thing pressure developers not to rely on Google APIs now that there's more competition in the space?
Android apps are also inferior to Windows apps, so the real question is: Who is going to use Android apps on Windows.
Android app developers seem to be the target group.
It's not something they'll understand the significance of. That doesn't mean it isn't important.
>Android apps are also inferior to Windows apps, so the real question is: Who is going to use Android apps on Windows.
Many people who use their phones for a lot of the time and want a similar/identical experience on their laptop.
>Android app developers seem to be the target group.
I disagree. It's for people who want snapchat or signal or whatever on their devices. Android developers already have emulators or test devices.
Ok, so why even have freeform window mode? Well, that is because Android has a "desktop mode" that is supported by some Android 10+ devices. If you have a USBC/HDMI/USB adapter (same thing you use with newer macs), you can plug your phone in and use it like a desktop. It's not great, but it is surprisingly useful, especially when an airline loses your laptop bag.
There is no windows app to access my credit card, an Monzo doesn't even bother creating a website to access your bank account.
Some functionality specifically requires a mobile app and is not accessible from websites.
You see where this is going. Google has moved _so much_ functionality into play services that Android as a platform is losing features every day if you don't have it. It's fine for fully local applications, but should you rely on location services, dynamic module delivery, any maps service, etc, you are utterly fucked.
On the one hand, maybe tablets will improve a bit because mobile apps will have even more incentive to spruce up their large-screen experiences.
On the other hand, literally every app I have seen auto-ported to desktop in this way has been awkward at best. Usually at least a few standard platform things just don’t work, like universal keyboard navigation. Having mobile UIs appear unaltered on the desktop is just jarring, at the very least requiring unnecessary scrolling and controls that do not resemble anything else.
And I am not convinced that this will improve with time; on the Mac side some of these pseudo-apps have had years to get better but they are still packed full of UI quirks.
The operating systems aren't the only ones to blame here. Haven't you seen desktop sites using hamburger menu? That abomination came to life thanks to mobile web.
As a publisher who recently redesigned one of our websites, using the hamburger menu across devices and screen sizes was strongly considered. It is very annoying on larger screens but these represent such a small traffic share that it is what it is... We still did not go ahead with that, but it was close...
But because the website is mobile-first in its CSS, we can very easily —some day— test this with Optimize for example.
Just ask a left handed guitar player about limited choices and/or awkward usability.
It’s going to be great.
We went into the cloud before Azure was a thing. AWS was a thing on the US when we did it, but back then no one in the Danish public service would’ve put our data into an American cloud. We instead rented iron instead of buying it, which sort of amounts to the same thing except it isn’t in your basement, but in someone else’s. Perfectly fine when the business case is there, which it was, and it helped us immensely for the world of today since we began getting everything virtual back then. Anyway, a decade later and now the move is going toward Azure (it could just as easily be AWS if Amazon had Office365) but it’s not like we want to move away from Microsoft as such. Yes we are idealists who want more open source in the public sector, but we’re also realists who have a staff of 30 to deal with the IT needs of 10.000 employees, some of which can’t tell support if the device they need help for is an iOS or Android device. We also don’t pay our IT staff enough to hire equal level talent for Linux systems, because that talent mass is just so much smaller.
Getting back to my point though. Over the years we’ve gone from using different Kanban and planning tools to using Microsoft teams and planner. We’ve gone from using different document sharing systems (and the strict control over these) to using OneDrive for business. We’ve gone from using Cisco software phones to using Skype for Business and teams. We’ve gone from using dreambroker to using the video tools in windows and teams for presentation. We’ve gone from having different ways of running the scripts that maintain our org data, and BI tools that present them, to using azure services and powerbi. We started our using Softomotive as our Robotics platform and became the leading public sector organisation with it, and Microsoft just bought it. The list goes on.
In short, we’ve gone from buying software from 30 different countries to simply using what Microsoft is now supplying through its platforms. We know it’s maybe not the best strategy, but it’s hard to defend not doing it when it’s both cheaper, easier for the organisation and what our IT staff wants because it gives them CVS that can be used almost every where.
Maybe this is just Microsoft being very good at spotting trends in the European public sector, but they are just so much better at it than agencies like Gartner, Deloitte, E&Y and even their competitors in the form of IBM and Amazon. Although as far as legalisation goes, Amazon has them beat by a lot despite starting slow.
My job has definitely become a lot harder since we went all in with MS.
The engineers that carefully built large, performant, working science software on a dozen platforms, where almost always against the change. One of the founders and a Senior Scientist, would talk and talk, and in fact had moved to Microsoft stack personally also.
It was entirely obvious that the contrast between plural vendors, with plural engineering, was weighted against a single mono-culture of software and OS, and that decision makers went for the latter.
That said, why exactly do I want even more kitchen sink functionality in my OS? In a world trending towards devices and services, we should see general purpose OS trending more towards slimmed-down, tailored-for-use implementations - maybe the same code base supports a game console and a streaming media device and a phone and a tablet, but each instance stripped until it's just what is needed. Why do I want bloat exactly?
I'm not saying this results in a healthy industry (monopolies using their monopoly to get into a much wider field) but if you see the world from an average user on one end, and a profit oriented company on the other, it's rather obvious how things happen.
I like Android, where the default is the play store, but i can sideload or use f-droid as well.
Interestingly, she's avoided viruses on Windows for decades. I think thats because she wouldn't trust random apps from dodgy websites in the way she'd trust Google Play.
My parents are also very cautious with what they install on Windows, and I think that's a pretty good approach. But it's pretty clear that plenty of people aren't so paranoid, and it's not always easy to tell a dodgy site from a legitimate one.
The store will then build the application binaries based on provided instructions, run tests to make sure the application meets store criteria, and publish it if everything looks good. Perhaps there will need to be some manual intervention when necessary but we should be able to automate things more as we see more use cases.
That and the client "store" should be decoupled from the server store and users should be able to add/remove server stores as they see fit.
As the OP is pointing out, the simple alignment of one platform with one app store is also a bit blurred. Neither Google nor Amazon control Windows. You can install the Amazon store on other Android devices. No doubt Samsung (and some other manufacturers) are trying to do their own marketplaces. And it's conceivable that in the future, they're forced to allow more competition (e.g. something like Steam for phones).
Microsoft can achieve the same goal already through Windows Defender. My app was recently flagged as a trojan (false positive) and it would be wiped from users' computers before they could even run it.
>they also have the ability to remove it from devices where it was already installed.
That Microsoft can't do, but I'm not really sure that it's a good thing...
>The app store model probably also delivers security updates to legitimate apps more effectively than every developer managing their own distribution.
Citation needed there.
Linux’s package manages show that quite well. I can update (almost) all my packages with a simple command. On Windows, if Inkscape has a security vulnerability that an update fixes, I'm not informed of this unless I follow the development or use an RSS feed of sorts.
If every app handles its own updates, that also means that either you've got N background auto-updaters running, or the check has to wait until you run the software - and potentially get exploited by a hole patched in the update it's just downloading.
I was shocked!
Removing signatures by design in the face of a recent huge impact supply chain attack? Hopefully US Gov can leverage some simple purchasing controls (that don't require 'an act of congress') to convince Amazon to stop this behavior.
I wonder if this alliance will quell handwringing about Apple having some sort of “monopoly” simply by its choosing the contrarian path of designing, building, and marketing a full experience for those seeking one.
Dominant desktop platform + dominant mobile platform + dominant online commerce platform & cloud platform … versus a firm doing it differently: FAANG becomes FANG aligning against the odd A.
Quick, don’t let the market decide, ban Apple’s UX design model and the business model that sustains it?
Could be there’s room to let this one play out with Apple back to its innovation integrator chasm-crosser zone as niche underdog, rather than trying to preemptively pop the zeitgeist bubble stressing people out.
In the short term, breaking the App/Play Store duopol will be a good thing.
But what will happen after that?
If you could install a store inside your browser and then buy web apps from there instead, your apps is no longer tied to the operating system, only to the store (that requires a compatible browser)
But I don't think it will happened because it doesn't benefit the two major players on operating systems, Microsoft and Apple.
What probably will happen is just solidifying the Android based native app as the dominant application platform, now you can develop against the Android SDK and cover 80-90% of the market, both desktop and mobile.
If you don't know Java already, it is time to learn. Welcome to the future - poms, jars, classpaths and AbstractFactoryFactory nightmares everywhere, buggy and slow Android apps running over a virtual machine with a user experience not adapted for mouse and keyboard. There will be Hacker News threads about how they miss good ol' Electron apps.
Good things for power users.
However I'm concerned about the impact on "normal" users that just want their stuff to work. There's little stopping a Facebook App Store from taking similar measures, for example.
The way the average consumer views "security" is: "Is this a trusted brand?". As of today Microsoft and Amazon are trusted brands. Western Digital not so much. So instead of trying to understand how Windows 11 running wrapped Amazon Store Android executables might be insecure, users see the words "Microsoft" and "Amazon" and feel secure. (as a side note, security is really just a feeling anyways...)
With regard to freedom, what's freeing to the common consumer is the freedom to have access to functionality they care about. They don't care that someone else is tracking them or that they are limited to apps on these stores.
So, really, these uncomfortable questions are only uncomfortable for people who aren't the target audience of this feature.
Is it not possible that the telemetry exists only to collect data on how to improve software? Do we know it's being used for advertising?
>actually discuss how it violates their privacy
The privacy violation is the collection itself.
What I know is that they collect huge amounts of data and we don’t have protections on how that can be used.
If you aren't happy with Apple's telemetry, then use Linux.
If you aren't happy with bug reporting tools remove it.
They're not going to change it.
Also exaggerating by saying "spy on their users" is just misrepresentative.
And muddies the water when discussing actual spying on users computers.
According to a tcpdump running on the host of a Windows VM this blocks absolutely everything, even connections originating from kernel drivers. I tested this with LTSC though, so YMMV.
Maybe, and barely. You've only been able to do this since November, and only on new Macs. When Windows 11 ships, assuming the TPM requirement isn't an issue, a bigger share of Windows users will almost immediately have this feature, rather than having to buy new hardware.
It's especially strange since .NET is a great cross-platform framework.
But... the developer put the app on the Amazon store. They trust Amazon to redistribute it any hacky way they want. It's okay to say "I don't like Amazon tracking me" but it's not okay to lie and confuse the issue by saying that Amazon is doing app devs dirty.
I would, however, enjoy a scheme where I could trace the Play Store's signature back to the key I used to sign the app bundle for upload. Like if I could sign their key with mine.
Other than that, I'm so happy that my Fire HD 8 bricked itself, and the Fire 7 is about to take its last breath, because there is absolutely nothing which I managed to like about Fire OS. Never again, and I hope that MS doesn't start to try to nag me into using it.
How exactly can this be done?
> However, there is a dark cloud with all of this: the primary source of Android apps for Windows 11 users appears to be the Amazon AppStore for Android.
Is there any evidence of this? There's no linked article and it's entirely unsourced. I for one would NEVER install software that Amazon has had any hand in.
we don’t modify and distribute your application code without your knowledge and approval º
Notably, this person used “don’t” and “will not”… as opposed to “can’t” and “cannot” º
So the next stage in the plan for the tech giants is to now take control over all our software applications and really lock them down too?With locked iDevices and smartphones that don't allow you to install the system software you want, that can be crippled and made unusable by the manufacturers, and have nearly unrepairable hardware (with lobbying opposing right-to-repair legislations), the tech giants have ensured that we have already lost control over our hardware devices. Today we only "own" them in name.
The article highlights a real worry - It is not at all far fetched to believe that by wrapping apps with their own proprietary codes, the tech giants can control and steal our app data (a very likely goal of all the tech giants) and even modify the apps to cripple them or convert it to a malware (at the behest of over-reaching governments).
This just adds to my worry, and ire, at App Stores, and provides a new perspective of them I had never considered before.
º https://commonsware.com/blog/2020/09/23/uncomfortable-questi... .
It's like trying to have a functional democracy with people who want it to be easy so it can get out of the way.
Big-tech control is just a side-product of atomization, as far as I can see.