With an iPhone you are stuck with whatever new decision from Apple with no opt-out. That’s abnormal.
See, I’d be ok to say that Apple can do whatever they want with iOS the day they give me the keys to the boot loader. Until then, they’ll have to assume their role of gatekeeper.
I have no issues with walled gardens as long as you’ve got the key to leave. Here the key to leave is called "throw your $1000 phone to buy another".
And Airport security loves invasive search - why do people understand one is a violation of privacy, but tolerate the other?
Just look at cases where governments abuse Apple's power over users to squash protests and delete important Apps from the Appstore. Without competing Appstores users are left at the mercy of a trillion dollar company which cares about profits and profits only. Not being able to freely install apps from any source the owner of the computing device prefers is outrageous and we can only thank the EU commission for recognizing that.
https://www.npr.org/2019/10/10/768841864/after-china-objects...
Which iPad owner ever thinks "oh I wish my iPad were even less capable"? Most people are annoyed by its limitations but they accept it as a trade off. I personally would use my iPad much more if it were as capable & open as a Mac.
Me, kinda. I've disliked most of the moves to make it more like a general purpose computing platform and less like a slab of glass that becomes different tools (but mostly one at a time!). I have other options for that other crap, the iPad was (still is... barely) a distinct different category that I liked also having. iOS 6 is peak-iOS to me.
https://www.qubes-os.org/intro/, snapd and BSD jails are all forms of locking down a general computer OS ways similar to the way iOS is locked down, and things that individual users choose to do on their own computers. Sure those users can install anything else they want as well, but then there's also a reason why these things are niche, even within the nice of *nix users. Because the administration and management is a headache and people don't generally want to do that.
>Turns out that grown ups don't need Apple to babysit them for additional "security"
I think you have an over estimation of the average "grown ups" ability to judge the safety and security of their computer or the software they run on it. There are plenty of people out there who do not want or need to understand system security and administration and are much better served by having someone else manage that for them. There's a reason why Windows and MacOS are still more popular than Linux, and there's a reason why in the Linux world, Red Hat, CentOS, Debian and Ubuntu are more popular than Arch. People only have a limited amount of time and energy to dedicate to things and not everyone wants to dedicate theirs to our shared hobby.
And having certain restrictions to hide complexity from users to hide complexity is by no means comparable to "security" whose only purpose is to shackle users so they can never escape obscene fees because Apple uses the same strategy as the mafia: "pay us for protection".
If it's not voluntary, what's the difference between Apple's behavior and Tony Soprano's behavior?
If you read past the first sentence, you would discover I wrote more than just that one. In fact, the second sentence which starts with:
>Sure those users can install anything else they want as well
and then goes on to explain why super hardened security OSs aren't even mainstream among tech people who should in theory be all about super hardened security in their OS.
>If it's not voluntary, what's the difference between Apple's behavior and Tony Soprano's behavior?
Except it is voluntary. Apple didn't force anyone to buy an iPhone. They didn't walk into people's homes with a baseball bat in hand commenting on the "nice general purpose computers you've got here". They didn't promise free computing and the ability to install anything from anywhere and then suddenly switch away locking people in after investing in a huge open system where none of their apps are available anywhere else. Any user can walk away from the iPhone simply by buying a device from any one of a number of other sellers, all of which offer Android OSes with all the freedoms they could possibly want, and Apple can't do anything about it, nor will Apple show up at their house in the middle of the night to leave a headless server in their bed sheets.
>and then goes on to explain why super hardened security OSs aren't even mainstream among tech people who should in theory be all about super hardened security in their OS.
You are intentionally arguing in bad faith, the point is and was that Apple's intention is not restriction for the sake of "security" but for the sake of funneling everything through their gate so they can impose a tax on everybody. It's the same with their sanctimonious "privacy" arguments, it's all BS and the DOJ realized this too. [0]
>>If it's not voluntary, what's the difference between Apple's behavior and Tony Soprano's behavior?
>Except it is voluntary. Apple didn't force anyone to buy an iPhone.
That's a bullshit framing that's a bait and switch in level, which is similar to saying "well the rail barons didnt force you to use their railroads, just use other railroads LOL". If a product or service becomes so prevalent in society then certain rules and regulations apply in a fair market and the EU commission has recognized that and finally the U.S has recognized that as well. By making that argument you also implicitly admit that the "security" argument is actually bogus and not really for the user's protection otherwise they would see no problem in granting an escape hatch for power users, but they don't do that because it's not about security an it never was.
[0] https://techcrunch.com/2024/03/21/doj-calls-apples-privacy-j...
That's not true, if those "design decisions" are anti-competitive in nature then they are absolutely not allowed to do that, that's what the EU commission is fixing with the DMA and now the U.S. is suing Apple too.
https://en.wikipedia.org/wiki/Security-Enhanced_Linux
the delightful irony is you’re literally so wrong they put it right in the name. Security Enhanced.
The military knows damn well that limiting unprivileged users to running a limited selection of vetted and approved apps and restricting their ability to make tools that might aid their ability to jump the sandbox increases security. They literally built the canonical OS extension to do it. It’s not sufficient for security by itself, but it does additively increase security vs a non-policy-enforced environment with higher freedom.
It is, however, necessary for security. Literally every enterprise sysadmin, every single one, windows or Linux or otherwise, knows that letting users set policies on their own devices decreases security. And in the real world, those policies/access control are either: (a) mandatory, or (b) ineffective. If you allow a mechanism for users to opt out - they will opt out 100% of the time, and it’s ineffective. There is no middle ground, if there is a way to go around then users will do it, it's either a matter of policy or it functionally doesn't exist.
Facebook et al will certainly exploit their network power to push users to do that, just like any other attacker. No different than Chinese agents going after a debt-laden private. They literally already got caught using their dev credentials trying to pull a sneaky and tunnel users data via a VPN for data mining purposes.
https://arstechnica.com/gadgets/2019/01/facebook-and-google-...
But I’m sure you know infosec better than the NSA. This is HN after all.
And again - such escape valves already exist. You can sideload apps on an iphone without paying any extra money. Altstore/Appstore++ exist to refresh your app notarization automatically etc.
Almost as if this is really all about the transaction fees and apple's cut of money that tim sweeney sees as rightfully his, and not user freedom at all... but I'm sure there's a very good, very pro-consumer reason Sony and Microsoft exempted themselves from the DMA?
The example you mentioned is fundamentally different, why? The owner has the option to completely disable anything they dislike or install a different OS, especially on linux which prides itself on maximum user choice. And even then it's asinine to compare features that are for enhanced security and Apple's version of "security" which just limits user choice to products that have to pass Apple's gate so they have to pay a tax to enrich Apple.
Wow, gold standard for sure. Is this why iOS zero day costs less than Android one?
I would argue it's much more secure and more private this way
I'm no security expert, but I know that security is certainly not a linear, at the very least it's some multi-dimensional thing that's exceptionally hard to generalize.
One system can be more or less secure than another for some party or parties, for some particular threat models if you can or cannot install certain apps, etc etc. Skipping all those bits makes the statement vague, increasing the risk of misunderstanding of the implied conditions.
Just a quick example. Installing an app could paradoxically make the device simultaneously more and less secure for the owner. Let's say it's an advanced firewall app. On the one hand it improves the network hygiene, improving the device security against its network peers. On the other hand, it may help in compromising the device, if someone gains access to its control interface and exploits it for nefarious purposes.