>
I really hope not to see that day. So, how to avoid it and not be open to security issues like these?I don't know. Part of the answer likely lies in determining who the "owner" actually is. I want to be the owner of my computer, but business interests go against it. For instance, MAFIAA doesn't want me to be the owner, because they want secure means to enforce DRM on me. Other businesses would also like to be the owners, because they can monetize me better this way.
> I don't think we have much to fear from the 'professionalization of programming', not if the kind of code I see on a daily basis is anything to go by ;)
Let's hope so, but I think it naturally follows from Trusted Computing - the technology will enable proffessionalization. Because right now, there isn't much you can do to prevent people from getting their hands on a compiler and using it.
> There have been numerous attempts at slapping a gateway on the ability to write software for the hardware that you already own, the only environment where this has taken hold is on mobile platforms, I sincerely hope that that is a development that we will sooner or later be able to revert.
I hope so, but I fear we won't - that at some point a company will finally figure out how to lease PCs to general population instead of selling them. You'll get a nice, cheap laptop, but it will be locked down, equipped with trusted computing hardware (the company will be the trusted actor, of course) and require to connect to the Internet every now and then to verify everything is ok. Basically, what happened to mobile, only worse. And people will buy into it if the price difference will be significant enough. Actually, I'm not sure what's stopping companies now from doing this.
> But in order to revert it you'd have to come up with a solution for the pandemonium that would ensue if everybody and their brother would use the likes of 'download.com' or some equivalent to install their software from. Maybe something along the lines of apt-get for phones would be a starting point.
Yup. Crap like this is a huge problem, but I'm not sure if it requires locking things down. You can go the Apple way and aggressively verify every piece of software you allow in your repository. This makes you the trusted authority, which carries risks like abuse of trust, but solves the problem without heavy sandboxing.
So far I see the issue of distributed vs. centralized as a tradeoff between secure but inefficient, and efficient but with serious failure modes. I wish there was a way to capture benefits of both while avoiding the risks.