1,632 karma · joined May 21, 2012
Debian repositories are quite secure, but also pretty limited in scope and extremely slow to update. In practice, basically everyone (I'm sure there are a few counterexamples) using a Linux distro uses it as a base and runs extra software from less tightly controlled sources: Docker hub, PyPI, npm, crates, Flathub etc. It's far easier for attackers to target those, but their openness also means there's a lot of useful stuff there that's not in Debian.
Holding up Debian as a model for security is one step up from the old joke about securing your computer by turning it off and unplugging it. It's true, but it's not really interesting.
If you don't want to play their game, sideloading will get substantially harder.
I think this whole discussion is based on an assumption that changing the default is part of an agenda to get rid of middle-click-paste entirely. I don't think it is.
Ctrl-C/Ctrl-V copy and paste is not such a big issue because far more people are familiar with it, and it requires more deliberate actions on both sides (copying and pasting). So you're less likely to accidentally copy something around that you didn't mean to.
That's not really accurate: Firefox peaked somewhere around 30% market share back when IE was dominant, and then Chrome took over the top spot within a few years of launching.
FWIW, I think there's just no good move for Mozilla. They're competing against 3 of the biggest companies in the world who can cross-subsidise browser development as a loss-leader, and can push their own browsers as the defaults on their respective platforms. The most obvious way to make money from a browser - harvesting user data - is largely unavailable to them.
To my mind, the 'only just started' argument is wearing off. It's software, it moves fast anyway, and all the giants of the tech world have been feverishly throwing money at AI for the last couple of years. I don't buy that we're still just at the beginning of some huge exponential improvement.
Some of the bigger open source communities, like GNOME, do some amount of these things. But I think very few people are excited enough about user studies or marketing to do them as a hobby, unlike writing code. It's hard to see how you could beat Google/Apple/Microsoft at their own game like this without a lot of money. Red Hat is probably the biggest company that might be interested in this, but still about 2 orders of magnitude smaller than the giants.
Someone wrote it into the grant agreement. It's a fair bet that they think that has some effect beyond what the law already achieves.
Apps can certainly detect if a phone is rooted and refuse to work, like with a custom ROM. It's up to the developer what they care about, but this is not unusual. There are ways to try to trick the check into passing, but it sounds like the kind of thing that might break on any update.
Apple is of course locked down, but that's not news. The anger is because Android was the better option on this dimension.