It would be like if the Facebook app on your iOS device could read all of the files of your banking app, or notes app. It's just not something that is enabled in any Android system claiming to have some level of security.
It would be like if the Facebook app on your iOS device could read all of the files of your banking app, or notes app. It's just not something that is enabled in any Android system claiming to have some level of security.
It’s my device not the OS or app manufacturer’s!
I’m totally onboard with per-app segregated storage as a default, but this feature is clearly gated behind user permission.
You're right that the owner of the device should have the ultimate say. But the sad reality is that most owners aren't necessarily good caretakers of those devices. They don't understand what that permission entails, and they don't actually want to take responsibility for the outcome of the decision. But they will want to hold the manufacturer accountable for the damage.
I can't count how many times I heard people say "this decision should be mine to make" only to follow it up after some time with "somebody should have warned me not to do it". It's human nature and the solution for this can't/won't be technical.
Windows XP was a good example of letting the person decide what's good for their device and it was also the OS with the slowest adoption of updates. People collectively decided that the discomfort of rebooting once in a while was worse than letting malware completely wreck their device and data.
The correct response, if (as in this case) they were warned, is to say “someone did warn you, pay more attention next time”, then walk away[1].
Just like if a beginner ignores the black piste markets and the “for good skiers only” sign at the top of a slope then complains that they fell over.
It is problematic to create in users an expectation that if they blindly mash at their globally-networked, bank-account-connected devices without paying a modicum of attention to anything that appears on the screen when they do so, that everything will be fine, and if it’s not it’s someone else’s fault.
[1] optional, depends how much you like them
In reality, this does far more harm than good. In almost all cases this goes wrong because of the 'little learning is a dangerous thing' problem. People tend to be in two camps:
- Don't care, don't want to fiddle with the thing, the manufacturer has to do everything
- Knowing just enough to break things, but not enough to fix it (and thus it is the fault of the manufacturer)
Other types like the 'I am the owner, I make the rules' crowd are insignificantly small.
This means that in the real world (so not in an echochamber) you only get one scaled and realistic scenario: the user creates problems (for themselves, others), but cannot fix them, and everyone/everything not-user then has to care for them to deal with it.
In an ideal theoretical world we might say that the end-user has to be responsible, and they have to make infinite mistakes and learn everything so they can become good caretakers of their networked systems. But that is not reality, and is not realistic.
Harm reduction isn't always the most important goal, especially when it's other people's harm and reducing it also involves restricting what they can do.
You don't have to allow all users everything, but you should allow those who want, to do as they please.
You can always hide the option behind some kind of mechanism. A mechanism a general user wouldn't use because they don't if the rest works as intended. Those who still do, should suffer the consequences, but this is not the manufacturers' problem. They have all kinds of safeguards to prevent liability because of those "special choices".
This is less relevant for the current discussion about the FireTV and this feature. It's for the more general discussion of being able to do whatever you want on a device you own.
Bad example; this "narrative" is true as often as it isn't.
You can't force them to change their mind.
The real answer: users are captive. For the vendors, they're cattle. And like with any good big farm, it does not matter how much it sucks for the cattle - but it does matter the cattle is safe, because few bad cases can become known and risk your farm getting shut down.
Are you sure you responded to the right comment?
That's the should/should not part. The rest is my take on why companies remove those features anyway - they have no incentive to provide anything above bare minimum, especially not when they could be on the hook for "some fraction"'s mishaps.
I didn't raise the 'should/should not part' at all, you are the one who raised the point. I'm focused on actual facts and possibilities in this comment chain.
Perhaps. Perhaps that should also mean there are consequences to their actions and they get disconnected from shared systems.
And as we've seen in the PC space, this will absolutely destroy security as the general population will simply hit "Ok" or "Allow" on any (security) prompt so they can get to their desired goal.
Meanwhile, in the real world, externalities exist.
So let them? I keep hearing this argument but I have yet to hear a good explanation of why it's a problem or why I should care.
If a thief walks up to someone's door and asks to be let in, and the person opens the door and lets them in, is that a security flaw on the door's part? Should we make doors harder or even impossible to open by their owners to prevent them from letting a criminal in?
Developers aren’t responsible for the general population doing dumb shit, as long as they don’t trick them into it, and it doesn’t happen as a result of bugs in their software.
Imagine if the makers of stoves or kitchen knives believed that they should design out every possible way someone could burn or cut themselves…
“Do you want to let [application] access [the calendar|your photos|files created by other apps]?” seems totally reasonable; stopping users from running programs that do this altogether, not at all.
The biggest problem with it all is: that which OS developers do to “protect users” becomes what application developers use constrain users and prevent them accessing their data, in order to extract more money or control how people use their own devices.
In an older, kinder, gentler era of computing, if I granted a permission to an app [0], it was probably doing something with that permission that I wanted. Nowadays, not so much — apps are generally actively hostile to the user, and even apps that are friendly are frequently purchased by more or less malicious companies that turn them into malware.
[0] Yeah right. There were no permissions. And apps were mostly well behaved because they had no way to call home to the mothership.
Not really… I want to ban or break up/massively curtail the apps and/or their business models and aggressively police them so that that isn't a thing…
That said this is still a user hostile change. I will never purchase a device that blocks ADB since it's required for several useful things, often related to fixing or working around issues created by the vendors themselves.
It's not a feature I want. I want to enable this on demand.
I basically paused my backup efforts until I have the energy to configure a harder to use system like syncthing or similar.
What went so wrong with personal computing that allowing an application to have access to the files on the device with the user's permission is now considered an unthinkable crime? Is the average smartphone user so clueless about the capabilities of their device beyond scrolling through tiktok that the use cases for this are beyond them?
It's because of people like you that I can't even load up an FTP app to backup the files on my android phone to my PC anymore.
The average person simply isn't cognizant of the dire security and privacy consequences of many of the things that they do when interacting with a computer.
Note that I am NOT advocated for the removal of ADB. As an Android developer, I once used adb on a daily basis. I also love the idea of using adb to ftp my filesystem to my local machine for the sake of backups and whatever other useful purposes. In the case of the FireTV, I believe that if the device is put into developer mode, ADB can still be accessed over a USB cable. I think this great, and necessary for development and other use cases.
The point here is about making a system less likely to cause incomprehensible harm to the average person. Android and iOS were an opportunity to rethink the security model of computing (for computers that most people carry with them and use every few minutes), and I think that's great.
Permission dialogs should be as informative as possible, sure, warn people that they're giving the app full access to their files if a permission is granted. If people still accept, then they accepted, it's their device and the device should respect their choice. It's not anyone else's responsibility to make that decision for them.
Not without unlocking the bootloader (which can only be done on a few phones nowadays) and having to deal with getting locked out of a bunch of apps and functionalities as a result of Google's "security".
You can fundamentally disagree with the Android security and isolation model, but if you were okay with it before this update, then the arguments presented are just an incoherent mess.