I'm not saying we have the perfect system but anything that slants the system towards "easier downloads" or "less gatekeeping" brings large, obvious risks. I don't see how regulation would address them.
I'm not saying we have the perfect system but anything that slants the system towards "easier downloads" or "less gatekeeping" brings large, obvious risks. I don't see how regulation would address them.
My banking works in my 'unprotected' computer browser. So I'd expect giving anyone equivalent freedom. I don't mind if there's a default for gate-keepers as long as they allow competition. but I would expect to have same freedom on my mobile devices as on my laptop.
They were a massive issue before, and now they're barely a thought for most people.
These review processes have been good for the general population.
Even though review processeses generally do not exist for computers, they are part of that same trend.
And I'm sure everyone remembers ransomware.
No one is saying OS shouldn't have security measures, permissions/entitlements and app sandboxing, user land, etc.
I still don't understand why my desktop/laptop is allowed to be 'owned' by me. but my iPhone is a closed-gardened where I'm just a guest in a device I own. and that's nearly what Google is now doing.
Even on desktops... where there are no such review processes. Apparently we've found other mechanisms to reduce those issues, without app stores everywhere.
Anecdotally, at least once a month for the past several years, I notice a youtube channel in my feed get hacked. Their usual content gets replaced with crypto, Roblox, or Elon/SpaceX spam. Big channels, small channels, it happens to them all.
There's usually a post-mortem when they manage to regain control. Every time the infection happened through a virus attached to an email or by following a link on their discord.
This kind of attack simply cannot happen on mobile (unless your phone is rooted and you have disabled all warnings).
We should have web installs by now. The only reason we don't is because Google and Apple like cash and their little monopolies are easy money.
Big tech loves to "protect us". See Anthropic and OpenAI worried about intelligence.
Google doesn't care that its AdSense ads marketplace is flooded with malware. Or that YouTube is rife with scams. Wonder why not. The blatant policy contradiction couldn't be because money, right?
Vulnerabilities aren't intentional.
> reviewed apps that were used for fraud or access as bad actors
The App Developer Verification program, Android Advanced Protection Mode, and Play Protect are all systems put in place in response to "bad actors".
And like it or not, the Play Store approval process is a security feature. It limits the ability of bad actors to run code on your phone and access data or exploit vulnerabilities they wouldn't be able to otherwise. Some get through, but it makes their life harder, again, defense in depth. Something can be both an anticompetitive practice and a security feature.
As for banking in the browser, you can, but your bank probably doesn't like it. That's why they are pushing for browser attestation, or to force you to use the app. The banks would rather take that freedom away from everyone rather than giving it to everyone. And I suspect they do it for good (as in profitable) reasons, fraud costs them, it costs them more than what they would gain by being more open.
If we want security features and freedom (which is the harder option), we need competition. If Google and Apple are the only players besides an insignificant minority, it is easy to lock software to these platforms, screw that weird guy with his Linux distro. Legislation is another option if the first one fails.
1. don't force auto-updates
2. still review apps uploaded to Google Play, but don't force users to use Google Play
If the concern is what if users use an alternate source for apps and those have viruses, then.... okay. If the user wants to stay with strictly Google-vetted apps, they can. If desired, you could have an option on setup that users could choose to select that would put the device in a restricted mode that can only use apps installed from Google Play.
But the motivation here isn't just security, it's control. Google doesn't want anyone to have an Android device that is independent of Google services.
So this doesn't solve the issue pointed in the OP.
> don't force auto-updates
I'm sure everyone would love non-technical people to stay behind dozens of security patches for apps they may use everyday because they forgot to press update.
Yes it does. This is their point:
> The fact that we cannot download and install software from the internet onto our phones JUST like we can do with our computers is a symbol of our inept and ineffective politicians.
It should be as easy for me to use an alternate storefront - or download directly from a site - straight to my phone. The googleplay store, which is (somewhat) curated and (generally) "safer" can also exist. I, as a user, get to decide which path I want to take. This is literally no different from my desktop and laptop, we already live this life. MacOS allows me to download .dmg files and install (though they are admittedly getting increasingly annoying/friction-y about it) at my own risk. Why should my phone be any different? It’s a small computer. That’s it.
It’s about user choice. It’s my hardware, so I can do with it what I want so long as I’m not using it to inflict harm on others.
I mean, probably not technically due to some EULA you were forced to sign which says the hardware is actually Google/samsung/etc and not yours. Giving them the right to brick your phone the moment you step out of the bounds they define.
We really need some sort of open firmware legislation that mandates manufacturers of computer components need to opensource their drivers and firmware. There's no "special sauce" in that software that warrants a company being able to keep it secret. It's literally just so they can force you to purchase new devices when they get bored of supporting their old devices.
this is identifying the tension yeah, but if a review process regularly takes weeks or months, then the security patches are still missing
Splitting git tech-monopolies it is a survival need. Or we do it, or we will end up with a collapsed society. Entities that spy on all citizens and gatekeep access to news and services are contrary to basic human rights and democracy.
MacOS has been moving to a more locked down model over the years - increasingly difficult to install unsigned applications, SIP, etc.
> Windows
I think Windows is incredibly impressive for its ability to run binaries from many years ago, but I don't think there's much people would point to as a positive regarding Windows’ approach to app security.
Yet life in Windows land is perfectly fine in 2026 and has been for at least 2 decades.
If Windows, which started at the bottom of the barrel security wise can make it, surely we can have more modern OSes that make freedom bearable?
People that accidentality cut their fingers in lawnmowers due to lack of safety features are allowed to sue the lawnmower company.
What I would agree is that it is about time computing gets the same liability laws that the rest of the world already has in place and no EULAs that work around local laws should be considered valid in any form or shape.
Lets stop talking about open source as special snowflakes where everything is excused.
Lets strive for quality in software.
Software only got this bad, because we educated users broken tools are acceptable and fixable with computer reboots and anti-virus.
But the special thing about security flaws is that they turn a one in a billion error into a guaranteed attack. It's moderately hard to make something that doesn't feel buggy, but ridiculously hard to be secure. If you hold to the standards of a bake sale it's the former. If you want full security then nobody releases anything outside very strict contracts.
- https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32...
- https://www.nsa.gov/Press-Room/News-Highlights/Article/Artic...
And I could keep listing several other world regions.
Anyone is allowed to sue the lawnmower company. Did they win?
I agree that the defaults should be secure, but you can't force security on people without creating parallel issues which are maybe worse. Centralizing this power in a single point can have orders of magnitude bigger blast radius than a security failure on an app.
At some point users have to take responsibility and be accountable for their actions. We can't just infantilize them forever as if a magical hand will always be over them protecting and having their best interest in mind. And we certainly shouldn't punish every user for the sake of some of them.
The worst part is that Google gets the benefit of putting itself as the central point of control over the ecosystem based on a promise to keep users safe, but without any of the liability from failing to keep that promise. When the app store is chock full of malware I'm really starting to suspect that their goal is actually only the control. And all those people defending it with "but people don't know better, they need a hand to guide them" were equally misled. What do you think?
And, honestly, if you think the endpoint safety problem doesn't apply to you, you are part of the problem.
If computers aren't safe enough that a reasonably competent user, who doesn't open random files they found online and obvious spear-phishing emails, can't use one without losing their 401k, then maybe we need to just reevaluate modern life and go back to bank tellers.
The computer itself won't really do anything. But I'm sure suicides go up when people lose all their money, or get personal private details leaked, and so on.
Therac-25 is an important software-development case study but a torturous stretch of "Using a computer wrong"
Yes you can check every single program out there, when digital stores are the only acquisition mechanism.
Or as alternative, signed binaries.
Coupled with liability like anything else in our societies.
Is that true - do you not see significantly fewer of those installs on random PCs now than you did years ago? And that's even with the current situation not being what I'd call fully locked down.
Even super basic stuff like remembering a single secure password instead of reusing the same 2 or 3 basic initials-dob-symbol permutations that were probably pwned 10 years ago seems insurmountable.
If people want to have dumb passwords and download malware, then so be it. You think they can’t do that today with the google play store? Of course they can. Most malware on android comes from the Google play store.
I don't really understand why a well designed sandbox and permissions system doesn't solve the problem.
For free (like for real no microtransactions) that is different. For the rest, they already have that.
As for doing without Google, I'm kinda doing that myself (using a Linux phone even). But tbh, I think that nowadays moving to another country to escape a government you fundamentally disagree with is easier than moving away from Google.
If you're banned from Google? Good luck, you're fucked.
I would be shocked if you could publish an iOS app without Apple being able to tell the government who you are. Less because Apple cares and more because Apple requires you to pay, which is very hard to do anonymously for something like this (I’d bet the options they offer are effectively “credit card only”).
As I've said countless times before, the answer is clear. Operating systems can install software from repositories. The vendor of the operating system can provide a default set of repositories. Third parties can also provide their own repositories. Device owners can choose what repositories to install software from.
Saying that there can only be one true repository is carrying water for trillion dollar companies to further extract money from their customers.
"Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety."
Clearly we need to regulate the kitchen knife industry more. There should be a central authority that sells authorized kitchen knives with at max 6cm length and all other knives should only be available to certified chefs.
Once we have outlawed the longer knives and strong restrictions on ordinary kitchen tools become normal we should just outlaw knives altogether. You can still hurt yourself with a short knife. Only chefs should ever be allowed to own such a dangerous tool. Just buy or order readily prepared food. Why would you do this weird nerd thing called cooking anyway? Just choose from the official list of allowed foods.
The idea that we have to prevent people from being in control of their own computers — that's what a smartphone is — is deeply dystopian and authoritarian.
People are rightfully nervous when they see someone walking down the street swinging a knife i.e openly misusing it or treating it casually
People don't realize how much software is being misused or treated too casually. They might be similarly bothered by lax security on databases and data leaks if they realized that it represented a threat to them
[1] General purpose computing
When companies get hacked and millions lose their personal data, nobody cares. When individuals get hacked, it's a major issue that justifies locking down consumer's hardware to protect them from the burden of controlling their own devices. See how that works?