The apparent desire of Palm to embrace and confine Palm's once open ecosystem means that the Pre, which I had been looking forward to as another shiny Palm device, is now for me just another piece of noise like the iPhone. As a customer I'm not interested in a closed ecosystem, and I'm beginning to realize that in the end the thing in my pocket is just a phone and I can get a really cheap one (with text!) from Cricket. If I need a restaurant or movie somewhere, I can look it up before I get there, and I can listen to my own farts in the elevator without having to buy them from Steve Jobs or his counterpart at Palm.
So Palm's task is to figure out whether they'll make enough money on apps to make up for lost phone sales from people like me. Because in the end, they have no responsibility to customers, employees or outside developers; their only responsibility is to shareholders.
And if they decide to go with a closed system, then like Jean Kirkpatrick, I will wave fondly as they sail into the sunset, and look wistfully at the Palm devices in my sock drawer.
I can install apps by downloading a program file and copying it to the phone. Or I can install apps "over the air". In neither case does _anyone_ have to authorise me installing the application.
Nor will I buy any phone that makes me jump through that hoop.
On Blackberry, you have to pay 20$ to get code signing certificates, and without that you can still write basic apps, just not ones that access most of the 'interesting' features.
Android lets you self-sign applications.
All those platforms have free development tools, and in Android's case, I believe most of it is actually open source.
For example:
1. Your app cannot browse directories without the user being asked for permission on every change of directory. Try deveweloping a file browser with that restriction.
2. You cannot use a SocketConnection to connect to a remote host to port 8080 (only HttpConnection is allowed without beeing signed). Try developing an http-proxy with that restriction, when you want to forward every connection to another proxy on port 8080.
And the Problem with being signed is that you have to have about 5 different certs on your key to be accepted on any phone by any manufacturer on any carrier.
Those certificates are not free. They cost about 300$/year each.
This was really annoying.
I am so glad I do not have to do this on Android.
BUT: For a lot of the interesting APIs you need more than that. To send ICMP Packets you need a manufacturer certificate (for NetworkControl capability).
I understand that I need a different level of trust for DRM related stuff. But ICMP? Come on.
If yes, who controls access to the capability of issuing/revoking certificates?