Outage aside, do you feel safe using it while knowing that it accepts updates based on the whims of far away people that you don't know?
Outage aside, do you feel safe using it while knowing that it accepts updates based on the whims of far away people that you don't know?
I can't even imagine how much worse ransomware would be if, for example, Windows and browsers weren't updating themselves.
Of course companies are going to abuse it for grotesque profit motive, but that doesn't make their necessity a lie.
Having evergreen software that just keeps itself up to date is marvellous. The Google Docs team only needs to care about the current version of their software. There are no documents saved with an old version. There's no need to backport fixes to old versions, and no QA teams that need to test backported security updates on 10 year old hardware.
Its just a shame about, y'know, the aptly named crowdstrike.
There sure are. I have dozens saved years ago.
If google makes a new storage format they have to migrate old Google docs. But that’s a once off thing. When migrations happen, documents are only ever moved from old file formats to new file formats. With word, I need to be able to open an old document with the new version of word, make changes then re-save it so it’s compatible with the old version of word again. Then edit it on an old version of word and go back and forth.
I’m sure the Google engineers are very busy. But by making Docs be evergreen software, they have a much easier problem to solve when it comes to this stuff. Nobody uses the version of Google docs from 6 months ago. You can’t. And that simplifies a lot of things.
They have to migrate each time they change the format, surely. Either that or maintain converters going back decades, to apply the right one when a document is opened.
> but they don’t need to maintain 8 different versions of Word going back a decade, make sure all security patches get back ported
Nor does Microsoft for Word.
> With word, I need to be able to open an old document with the new version of word, make changes then re-save it so it’s compatible with the old version of word again.
You don't have to, unless you want the benefit of that.
And Google Docs offers the same.
> Nobody uses the version of Google docs from 6 months ago. You can’t. And that simplifies a lot of things.
Well, I'd love to use the version of Gmail web from 6 months ago. Because three months ago Google broke email address input such that it no longer accesses the contacts list and I have to type/paste each address in full.
That's a price we pay for things being "simpler" for a software provider than can and does change the software I am using without telling me let alone giving me the choice.
Not to mention the change that took away a large chunk of my working screen space for an advert telling me to switch to the app version, despite have the latest version of Google's own Chrome. An advert I cannot remove despite having got the message 1000 times. Pure extortion. Simplification is no excuse.
But since then it has been abused for all sorts of things that really are nothing more than consolidation of power, including an entire shift in mentality of what "ownership" even means: Tech companies today seem to think it's the standard that they keep effective ownership of a product for its entire life cycle, no matter how much money a customer has paid for it, and no matter deeply the customer relies on that product.
(Politicians mostly seem fine with that development or even encourage it)
I agree that an average nontechnical person can't be expected to keep track of all the security patches manually to keep their devices secure.
What I would expect would be an easy way to opt-out of automatic updates if you know what you're doing. The fact that many companies go to absurd lengths to stop you from e.g. replacing the firmware or unlocking the bootloader, even if you're the owner of the device is a pretty clear sign to me they are not doing this out of a desire to protect the end-user.
Also, I'm a bit baffled that there is no vetting at all of the contents of updates. A vendor can write absolutely whatever they want into a patch for some product of theirs and arbitrarily change the behaviour of software and devices that belong to other people. As a society, we're just trusting the tech companies to do the right thing.
I think a better system would be if updates would at the very least have to be vetted by an independent third party before being applied and a device would only accept an update if it's signed by the vendor and the third-party.
The third-party cold then do the following things:
- run tests and check for bugs
- check for malicious and rights-infringing changes deliberately introduced by the vendor (e.g. taking away functionality that was there at time of purchase)
- publicly document the contents of an update, beyond "bug fixes and performance improvements".
There are immense benefits to using modern computing power, including both onboard and remote functionality. The cost of increased software security vulnerability is easily justified.
> The cost of increased software security vulnerability is easily justified.
Sometimes yes, sometimes no.
1. Nobody auto updates my linux machines. They have no malware. 2. It's my job to change the oil in my car. When Ford starts sending a tech to my house to tamper with my machines "because they need maintenance" will be the day I am no longer a Ford customer.
*Let's not pretend this never happens
No malware? Only if you have your head in the sand.
I ignored it because it was somewhat abusive and is missing the problem that automatic updates are trying to solve: that most people, but not all, don't do updates.