We need to stop automating everything and then complain that companies aren't putting optional banners everywhere. This is beyond stupid.
We need to stop automating everything and then complain that companies aren't putting optional banners everywhere. This is beyond stupid.
The reality is many applications developed for those devices try to harvest data from the user, often without their consent. Contact details, location data, correlation to other apps installed, and so on, in order to make money.
The reality is that this is unethical without explicit consent, and nothing will stop these actors except technical barriers to this malicious activity.
Your desire to sleep in your apartment with the windows open and doors unlocked and cameras off is yours, but if there is a binary decision of "have these protections or not", the answer is clear.
The online data privacy crisis isn't really about data or the bad actors, but the lack of understandability and control over our own electronics.
To solve the problem you need to make users more involved, remove automation in favor of manual processes but simplified as much as possible. "Protections" are mostly band-aid hiding the real cause.
>protection against ... your own device? Why is your device harming you to begin with?
Yes. Because some apps do more than they claim to do, and users are unaware, and thinking that all citizens can be perfectly informed and thus do not need to put guardrails on app permissions is foolish.
>but the lack of understandability and control over our own electronics.
The lack of control over the data that can be extracted by bad actors that seem like good actors.
>"Protections" are mostly band-aid hiding the real cause.
The real cause is that humans can be malicious, others can be fooled, and the first goes after the second.
All humans are fallible, but it may be out of your control. There is no other human between you and your device.
> Yes. Because some apps do more than they claim to do, and users are unaware, and thinking that all citizens can be perfectly informed and thus do not need to put guardrails on app permissions is foolish.
Why do you even have to trust what apps say? That's my problem with this reasoning, we are under the assumption that programs control your device and that nothing can be done about it except adding warnings. Why do programs need instructions to access data? How about forcing the user to plug any environment access into the app? Anything that isn't plugged cannot be accessed, no trust required.
> The lack of control over the data that can be extracted by bad actors that seem like good actors.
The solution is to give control over the data, not with protection, but understanding. You are transforming this tech problem into a human problem.
> The real cause is that humans can be malicious, others can be fooled, and the first goes after the second.
Again no human between you and your device/program. We however decided that software can be malicious.
I am not saying that automation shouldn't be possible at all, but that platforms shouldn't be designed this way.
If users had to consent to contact access, socket connection, and every single packet sent (obviously they would need to become readable to layman) there would be way less demand for data privacy laws.
By "involving" I do not necessarily mean harder, the goal isn't to make computers less accessible, but if we give users the ability to control whatever go in and out their devices maybe that making them a bit more interactive so instead of clicking "yes" to allow keyboard access you could drag a keyboard icon to the app or any other device you want to use as input instead.
Consent doesn't need to be presented as yes/no, there are multiple ways to make users understand what is being accessed.
Now, making the base process manual doesn't mean that the user will need to do the same thing over and over. I am not against automation, but I believe that it should come from the user, not a fancy system that some external entity decided is the best way to handle permission.
By outsourcing the responsibility to your data, you are effectively giving up on understanding it.
Ideally, I believe that consumer computers should become interactive/programmable systems where the OS is responsible for exposing all the environment calls, and the apps all stateless functions. The process of mapping environment access to app is manual, but create consent AND customizability. Plus additional benefits like easing the development of cross-platform applications and maintainability.