Please Don't Make Me Download Another App
theatlantic.com
theatlantic.com
- Would you like to enable notifications to see when your EV finishes charging?
- Yes.
(in a couple of days when you're thinking about a completely different topic)
- SPECIAL OFFER! 20% OFF THE FATTY FRIES IF YOU GET A CAR WASH FROM US!!!
And that's everywhere. It pays off due to the scale, just like spam. It costs nothing to send an annoying notification to a horde of users, and even if 1% of the users go for it, it is still 5+ figures of revenue out of a handful of characters pushed to users' devices, and hours of human time wasted dealing with useless annoying distractions.
I’d argue the second twist is data collection, which for an app can be much more invasive than what a web client leaks depending on permissions.
A lot of users don't understand that permissions are optional. They just tap to make the boxes go away. So the app developer stealing your data isn't insulated from being unethical just because they gave you a series of dialog boxes on installation.
So to answer your question: your contact list, location, connected Bluetooth devices, your photos, etc.
There is also a battery status API for browsers. Safari doesn’t support it. But Android browsers do.
You don't?
I disable notifs like the fucking plague.
Notifs? Yeah, because it's not a question of if; that shit is dead on arrival.
I thought it was against all the app stores rules to spam notifications that the user doesn’t want. Maybe I am mistaken.
I generally treat computers as less than equal, so only messaging and critical apps get notifications. You [phone] only speak when asked to!
That's really cool with per app contacts lists, like on GrapheneOS. Seeing it's now on iPhone, I hope it will trickle down to Android too.
https://techcrunch.com/2012/02/07/path-uploads-your-iphones-...
Well behaved apps may not have uploaded or looked at anything they didn't absolutely need to, but the problematic ones would
It's disgusting.
With this kind of mentality, you can justify close to anything. I don't think this is sound reasoning.
- If I install an app, and if it were to request permissions I don't feel it needs, I decline them
- If it asks again later and provides a justification, I may approve it, if I feel the functionality is worth it. But I may not.
- If I don't and it continues to pester me, I delete the thing and move on.
Frankly I could count on a couple of hands the number of apps that have access to my contacts, and all of them need that access in order to function.
99% of the time I see the cookie-banner, I will say "well for this type of website this isn't necessary". Either they're collecting suspicious, unnecessary data or they misunderstood the law. Either way it's not a good look for them.
Eventually it reaches an inflection point where it's so prevalent all I can do is complain, not avoid.
My idea of an operating system design (it is intended for desktop and laptop computers, but a variant could also be possible for smartphones and stuff if wanted), that all I/O (including determining the current date and time) must use capabilities (and can be proxy capabilities). The built-in programming language allows users to define new proxy capabilities and configure existing ones, and the C programming language can also be used. This can avoid such invasion of privacy but also is useful for other purposes, e.g. for testing, or to allow programs that expect a camera to work even if you do not have a camera, or to filter or redirect notifications, etc. Therefore, permissions can be as fine and as faked as you intend it to be. And, furthermore, the standard package manager would exclude programs that are designed to be invasion of privacy and other antifeatures like that (users can still install them manually, and the security features of the system still ensure that it would protect against many kind of malware and misfeatures).
> It should not be required to, e.g., order food at a restaurant or configure your headphones.
You shouldn't need a app or a web browser to do either of those things anyways.
"My idea of an operating system design, that all I/O must use capabilities."
Any OS feature is a capability. Time and date are not I/O. What does capability mean to you?
Then you go on to say that the built in language will allow definition of proxy capabilities "and the C programming language can also be used"
How exactly does the inclusion of C avoid invasion of privacy? What such invasions? How does the conclusion follow?
I am sincere, please help me make sense of what you are saying.
> Time and date are not I/O.
In my system, they are. Anything except deterministic operations on the program's own memory is considered I/O.
> What does capability mean to you?
"Capability" refers to capability-based security. For a program to do any I/O, it must be given an object called a "capability" (which is similar than, but different than, a "file descriptor" in UNIX). There is no ambient authority; to open a file you must already be given a capability to open a file, etc. Capabilities can also be used to give someone else an additional capability.
A "proxy capability" is a capability that a program makes up itself, which can be used to pass messages between itself and another program that the proxy capability is given to. Programs cannot distinguish between a proxy capability and any other capability, therefore ensuring that anything that an application program would know from outside of itself can be overridden by the user. So, if a program wants to track your location, a proxy capability can be used to give fake location data (this is useful for testing as well, and also for other purposes e.g. if your computer cannot determine your location but you want to specify it anyways).
> How exactly does the inclusion of C avoid invasion of privacy?
Avoiding invasion of privacy is independent of what programming language is used.
In my apartment complex we're forced to use an app for laundry (no cash, no card). The fucking app doesn't even sort the rooms (I'm actually impressed. I didn't know you could do any programming without knowing what sort is. Like not even one line of code...). It also has a 30 second load time because it redraws everything during the startup when it tries to connect to the network. Luckily their API got exposed, in May... and someone made all the machines free.
They also wrapped up their sales notification with the one that tells you the laundry is done. So you disable both. Not an issue though because the latter never even worked anyways.
But it's like when people send spam through the same email you send necessary information. Universities pull this shit all the time. Guess what? It all is spam now. And these people wonder why they emails get blocked.
Or when you go to a restaurant and they make you use their app. I'm autistic enough to try hard not to use them but often I give up because people I'm with get upset I'm taking so long (but I'm not the one at fault. It's like yelling at a cashier when corporate increases price on an item. Wrong target, but I get it). I think this is why they get away with it though. Because blame is often targeted at what is right in front of you, and they're often small. But a lot of small things add up. 1 shitty app can be ignored, but a hundred is overwhelming. And I swear, it gets worse every day
So many businesses try so hard to save money that they end up losing a lot.
Yes, I can go to the laundry mat a quarter mile away or 3 miles away and pay cash. Both of which I need to be on site the entire time or I can expect my laundry to be taken or someone else to stop my machine and replace my clothes with theirs... But if I want to use the ones that are in the same building or the same complex that I live in, yes, I must use the app. As annoying as it is, there are worse options... It's just that a handful of undergrads could make a better app during a hackathon. Ones who know what a sort function is and maybe even caching!
Once they even tried to steal $20 from me. It double processed. I sent them the log from the app and showed them my bank record. They said they didn't see it. I sent the docs again and threatened a clawback. They said they didn't see it. So yeah, I made a clawback. I wonder how often that strategy works considering who their target customers usually are
I guess there's a third option. As mentioned, the API was exposed. Someone used this in my complex to set all the machines to free (I understand this has happened several places across the country given news and Reddit). I guess I could also send POST requests and pay that way.
There are technically options, but there is no option that is not exceptionally bad. I mean the bar is low to make me happy. We live in a world where my computer can talk to me in a fairly realistic voice while simultaneously to do laundry I have to wait several minutes trying to reload an app to just fucking pay. Something that could be solved with a typical tap to pay (they even have Google and Apple pay in the app! But you gotta prepay in fixed amounts. The machines also have NFC but it's not enabled)
Yes, especially if you do not have a compatible smartphone (or any smartphone, or any computer) or if it had run out of battery power. But also just in case you don't want to, or if the app is defective, etc.
(I had read on Usenet that there is a German word "Digitalzwang" if you are forced to use computers with specific software.)
> The fucking app doesn't even sort the rooms ... It also has a 30 second load time ...
Yes, also that, that they are badly written and badly designed.
> Or when you go to a restaurant and they make you use their app.
I had only been at one restaurant where this was required, although they provided a iPad for this purpose, to any customers who required it. Furthermore, the restaurant was mismanaged and not such a good quality anyways. I do not intend to go to that restaurant again.
And you email them and they don't respond. You email your complex manager and they tell you to contact them. Eventually someone yells and it gets fixed. Or someone destroys a machine or in my case, someone hacks them.
To be clear I wouldn’t delete my banking app if it showed me a marketing notification, I would go into the app and turn off that kind of notification. I have notifications turned on for my banking app because of 2FA and transaction notifications. In the past I was actually able to stop a fraudulent transaction within minutes because of a transaction notification so I value them.
Unfortunately, companies know most people aren’t like us so they keep pumping out the crap.
You can't if it's a junk app. Many reputable apps today have properly described notification channels and you can turn them off selectively (under android at least). That's what I did for my banking and several other apps. Every "marketing" channel was turned off.
Alas it seems like few apps have it implemented. Hiss boo. Wish this was available of Web Push.
It's been opt in on iOS and Android for years
I'm no bean-counter, but that seems very odd to me.
I know that you can switch off certain types of notifications, but thats only if the developer has added those in. For example Revolut uses one notification type and sends payment notifications and marketing through that same channel. So, I just don't use Revolut but it would be good if Android could let me set up keywords to block notifications.
Edit: Oh, offline mode. Towering profits?
"I don't want bluetooth and an app, I want rs485 and a specification"
Silly things. A heated coffee mug (app-controlled). An air purifier (app-controlled). A home generator (app-controlled). sigh.
At costco the other day, there were gift cards for two movie chains ($50 for $39). One was just "take this card to the register", the other one was an app/website and more mess (and a hard pass)
Me neither
> "I want rs485 and a specification”
I want ethernet and a well-documented API. Put the thing in its own network segment which does not connect to the outside world and you get to have an the advantages of a network-connected device without any of the disadvantages. No automatic updates taking away functionality, no chance for bad actors to hijack your devices but still all the possibilities offered by having direct network access.
Framework's AMD laptops notably have a Zephyr based embedded controller. Good stuff.
There's definitely some strong OpenBMC efforts ongoing right now in server space. AMD says they're going to replace (closed) AGESA bring-up code with OpenSIL, so consumers might even have access to firmware it yourself too, sometime this decade.
What kills me is I cannot… CANNOT view Instagram content on my phone without the app. I tried to actually send a link to my Instagram page to someone today and I literally could not obtain a link to my page anywhere in the web app. It simply would not allow me to do that. I could be missing something but every time I was in a logged in state on the web it was railroading me into the app. I almost deleted my account for that. I might still.
If you don’t have the app installed, and aren’t logged in, there is about a 60/40 chance that the person on the other end will be able to see what is sent. And if it’s a video, they’ll miss the first bit of audio, because it defaults to muted, and it doesn’t let the user replay the video. They employs a lot of aggressive dark patterns to get people to create accounts, login, and use the app.
Myself, I never fell into the trap of using them, living in a rural enough area that the lifestyle doesn't require it. And if a company or service does require it, i.e. doesn't offer a web-based equivalent, I move on.
Would love to see some deep dive reporting on what happens to the data after it's collected and how much money I'm actually worth to companies if I succumbed.
On the other hand, apps frequently work better with less clutter than the mobile website. It’s wild how many websites clearly aren’t tested on real mobile devices — usually just by shrinking a browser window and saying “looks good on mobile” then moving on.
Amusingly, you've just described a web browser.
Not an app, but I also had to use my phone to check my luggage curbside at the airport. This was frustrating because I had to use a small screen to enter the details that were on my phone.
Both implementations somehow manage to suck up 100% of cpu when rendering fucking text tho.
I get that there are plenty of bad webapps too, that performance can be bad. And there's not enough highly visible open source efforts on local first & off-main-thread javascript to form the backbone of knowledge to inform mainstream webdev how to stay fast, responsive, adaptable, yet (I thought we would be so much further along at using these amazing capabilities by now!). But wow, it's still so wild to me that apps are so beloved by some.
PWAs are also wild to me because they are "just" the web but without half the web's superpowers. No extensions, address bar, history, bookmarks, tabs (unless built specifically for it; wildly weird.
But we don't due to the app model being profitable as a choke point for the os makers. Web GUIs are worse on mobile than the equivalent app, and there are many things that just gated off that you don't get in the web guis, and thus everything stays as an app, while many apps would work fine as this kind of dynamically loaded native app without any 'store' you would need to go to, just a url you load. The android activity model especially lends itself to acting this way too.
But app clips and google play features you may say. They are too restrictive and clunky, and google play features still need a base app to work.
My homescreen has more links to webpages than apps, because they can give me info faster than apps/widgets. I don't have to see the news/ads/videos or 'what's new' modal windows like I usually have to with popular apps. (That said, open source apps tend to be far more sensible. F-Droid has got a lot of hidden gems.)
To get the normal price now you have no choice but to hand over your data and dignity. These mechanisms should be banned.
…But then that would mean they can’t take a chunk of companies’ profits so not likely to happen anytime soon
But it's also frustrating how the ecosystem of Google and Apple, has stifled creativity in the space. We went to the moon with less computing power than a crappy PC in the 90s. People copying Google's model of basic functionally but with ads and Apple's overly protective but nearly useless permission model has ruined a technology that should be more revolutionary than it is.
Some of it needs to be solved legislatively. I absolutely should be able to have my entire contacts list read by a random game app, and the only consequence be that I found all my friends who also play the game, with steep penalties for collecting and selling that data. But I should also be able to vet and use my mobile computer to put anything on it I want.
The original iphone had zero market share on release. First one is free. Just like Appletv, applemusic, icloud storage, apple games subs....
If you think apple's approach has ever been anything else but abusing market power to maximise revenue I've got a bridge for you with microsoft written on the side. (MS are all like "We'd have been crucified for that, well not anymore!" And the race to the bottom of your wallet continues apace.)
I was pointing out that Jobs’ instinct on the iPhone was web apps, because that’s what it launched with. The App Store was a response to customer demand and people hacking stuff onto it anyway. And of course, they looked to make money on it, as they are a business and it requires money to build and maintain the platform.
As far as their approach only ever being abuse of market dominance, that simply doesn’t make sense. In the late 90s and early 2000s they didn’t have much of a market to speak of. There was no market to abuse. Apple has been around for decades with pretty famous ups and downs.
For example, I parked in some part of Dallas the other day. I HAD to download an app to pay, there was no other way to pay.