HNHacker News
TopNewBestAskShowJobs

plst

74 karma · joined May 1, 2025

submissionscomments
plst··on Google will allow only apps from verified developers to be installed on Android
> Saying "the users need to be educated" doesn't solve anything. Google could start an education campaign tomorrow (...)

Of course just saying it doesn't fix anything.

I don't want Google or Apple or any other vendor to do any education campaigns (and they clearly don't even want to try), part of my point is that the issue is too deep to be solved by such technological measures. For example, not skipping such warnings (includes invalid/expired certificates in https) and basic cyber hygiene should be taught in schools. There should be more public campaigns about these issues.

So I'm not even sure if Google should be fixing that particular problem (although I can guess why they are really eager to "solve" it this particular way). I would rather they focused even more on a stronger sandbox, making sure system software on licensed phones has no vulnerabilities and making sure the users understand what power they give to an application, than pretend that this fixes much. Sideloading restrictions only barely (because it's not like they are actually going to verify the applications, nothing about that in the post) plug one way to scam people remotely, over many, many other more severe ways. The banks in many countries don't even properly verify identity of people they give loans to, why not focus on that instead? (Yes, Google won't fix this, I'm not asking them to, they shouldn't try.)

We lose more than we gain.

> Then install a custom rom. All the power you want is already available

On most phones it's not, but that's besides my point.

> Seems silly to demand Google screw over the majority of their customers because you don't want to install a custom rom.

I'm not demanding Google to screw over anyone, and the current "sideloading" situation does not screw over anyone. I just believe that the vendors should not have the sole power to decide what applications can be installed on devices they don't own. Maybe let's have multiple certification authorities besides Google, like with TLS, as a start/compromise? I see the point of actually having an expert verify if an application is legitimate, and this isn't even it.

> On the contrary, you choose when you purchase your phone.

That choice should not be made when the phone is purchased.

And also I'm not talking about what I want to do with my phone, I'm talking about what I believe people should be able to do with their phones - for example they should be able to opt out of such protections if they don't want them (and leave them on if they want them), or choose who verifies their applications. Only possible if they know what the protections do and what the risks are, going back to what I wrote about education.

plst··on Google will allow only apps from verified developers to be installed on Android
> You'd be surprised at what warnings/permission boxes people will blindly accept when they think they're talking to someone from Microsoft or Google's tech support.

But I know they do, I've seen this first hand. It's lack of education (except for extreme cases of people who cannot take care of themselves. but that's not the majority)

> Agency they don't want and never use. It's taking away agency from people like us but for the average user, Google is taking away nothing they've ever cared about.

It's agency they don't know they want, until it suddenly becomes useful. I'm not expecting everyone to use side-loaded, unapproved apps every day, it's about keeping OS vendors in check, about limiting their power over devices they don't own. If they act against users, there should be a way to circumvent them. Such ideas take that away.

> I was just saying a couple of days ago that we need a service for old people where any transaction above a certain configurable threshold (for example, $500 in a day) has to be approved by an employee of this service who serves as a neutral 3rd party whose sole function is to try to prevent scams.

Enabling such a service is a choice they would have to make. The default is control. The situation with all side loading restrictions is opposite - you don't get to choose.

Unless you are suggesting that such service should be forced on people that match some vague "old" criteria. Our disagreement goes far besides technology in that case.

plst··on Google will allow only apps from verified developers to be installed on Android
> And they believe it.

Two reasons: they are not educated about devices they use, desktop operating systems are still awful at security (exe from a mail attachment can have a pdf looking thumbnail, executed with two clicks, even if accidental, immediately gets access to all user files... the whole concept of antivirus software...). It has nothing to do with side loading, especially on Android, where sideloading is a very explicit action already, and then you need to allow the application to do harm.

> Giving them the power to run any software they want, also means giving everyone else the power to make them run any software they can be tricked into installing.

You are taking away people's agency. Either you get to control your bank account risking that you get scammed, or someone will control it for you.

plst··on Google will allow only apps from verified developers to be installed on Android
But this is not about device integrity.

I'm all for code signing and integrity verification. We need both technologies on pretty much all devices.

You are just conflating two different issues - side loading has nothing to do with device integrity.

plst··on Google will allow only apps from verified developers to be installed on Android
You are forced to trust Google or Apple if you want a smartphone. They own the whole market, it's a duopoly. You already have no power to install an OS without such limitations on most smartphones.

Limitations because it's not just protection - you don't get to choose which authorities you trust. Defaulting to manufacturer/OS vendor as the default authority would be ok, but there is no option to choose. Users have no power over their own device. That's not ok even if most choose to never execute it or don't know about it, it will lead to abuse of power.

plst··on Allianz Life says 'majority' of customers' personal data stolen in cyberattack
Looking at the number of already discovered vulnerabilities in popular applications, I would say it's actually impossible to build secure systems right now. Even companies that are trying are failing. IMO it's still way too easy to introduce a vulnerability and then miss it in both review and pentests. We need big changes in all parts of the software buliding and maintaining process. Probably no one will like that, because we are still in "move fast and break things" software development age.
plst··on The Future of Flatpak
I love AppImages, but Flatpak tried to go way beyond - centralized updates, sandboxing/permissions system, package once, run on many distributions...

Getting software from repositories is not just laziness, you automatically get updates and the software from repos is supposed to work with your distro, that apparently is not always true with AppImages.

plst··on The Future of Flatpak
> But imagine saying you’re disappointed the Windows executable format isn’t evolving!

I actually am disappointed about pretty much that. There is still no good permissions/sandboxing mechanism for PC operating systems like what's on smartphones. (to be clear I'm not calling for smartphone-like freedom restrictions on PCs, just more control over what applications can do)

That's one of the issues Flatpak tried to resolve on Linux. AFAIK Windows Store is an idea pretty similar to Flatpak (permissions, solving distribution problems...) but also no one uses it. So it's not like Microsoft doesn't want to evolve exe either.

plst··on Jury orders NSO to pay $167M for hacking WhatsApp users
> Geez, you're really tilting at windmills here. What makes you think if you had your choice of 100 different security products (as is the ecosystem on Windows and Mac) that you'd be any more secure than "just" relying on Apple's security team (which is surely world-class)?

Why shouldn't I have a choice? I could then depend on more than just Apple's security team.

> Remember that Windows exploits abound, despite the antiviral/antirootkit ecosystem that grew up around it.

Many exploits for iOS and Android, too. Seems that locking down the phone doesnt't help with that... (different security model for apps/userland does, but that's unrelated to my point)

> I have an OS for you: Linux, BSD, maybe Solaris or something exotic.

No, I want what works on phones now, with more user control.

plst··on Apple violated antitrust ruling, judge finds
Responding to a comment by bn-l, but also to the general sentiment about Apple and untrusted code I often see on hacker news.

> The broader consumer base will install anything a bad actor wants them to and then blame the manufacturer for not stopping them with some draconian rule.

Has this even happened? Has anyone ever sued and won the case with a laptop manufacturer (or Microsoft or Apple), because they downloaded and executed an executable with malware on their computer? Do average people really blame Microsoft for malware? I would kind of agree that they should, but not because Microsoft allows people to run untrusted code, but because the security model of Windows (and other PC operating systems) is still bad. But not because it allows people to run unsigned code.

Don't get me wrong, I don't think we should return to security model of old operating systems - smartphone OSes definitely got that right, except for the part that forces users to give up control of their devices. It's just that the argument, that allowing people to install software not signed by Apple on their own devices would make iPhones insecure, is totally unsubstantiated to me.

I see some people still arguing that (ex. older) people will do what they are told and will install shady software. If Apple really cares, they could provide a switch that allows users to disable installing "unverified" software. Maybe ask about it during setup. Maybe allow locking it until factory reset, or allow head of icloud family to control it. There are many options to keep some people secure from all unverified apps, while allowing others to run them. Not to mention that the idea that all apps not signed by Apple are somehow malicious is just bad. You could have other entities than Apple verify code. Currently, even running apps you yourself wrote, on your own hardware, is hard and limited. For no good reason.

The only reason Apple is blocking other stores, or preventing people from installing homebrew, is to collect more money. It's good that they are investing into security of their software and hardware, but in this particular case, security is used only as a distraction.

← PreviousPage 2 of 2