Remix.run Logo
3form 6 hours ago

What I find most annoying aspect of all software from 2010s onwards is this stupid discourse and associated results:

- some people want A, or A might even be already in use

- A is problematic for $MODERATE_OR_MILD_REASON

- B is introduced and made default

- a config switch between A and B is never considered

So, so tiring. If I want to bind ADB to localhost, _let me_. It's my device and my problem, ffs.

Arbortheus 6 hours ago | parent | next [-]

Toxic max security.

Not everyone has the same threat model as you, $BIGTECHCORP.

rightbyte 6 hours ago | parent | next [-]

Isn't security just an excuse to push user hostile features?

Like, if security was a concern we would have simpler systems and still use 2fa devices for banks etc.

SXX 6 hours ago | parent [-]

Sometimes it's truly useful featutes, but having no toggle in settings making it terrible.

Like iPhone idle auto-reboot every 3 days. After a while they added "Allow Idle Reboot" flag but it only accessible via MDM and require device wipe and for switching it to be a managed device.

TeMPOraL 5 hours ago | parent [-]

What would that be useful for anyway? Sounds like something aimed to prevent people from reusing their old/secondary devices for IoT.

RobotToaster 5 hours ago | parent [-]

Hides memory leaks

TeMPOraL 5 hours ago | parent [-]

Right, that too. But that's a reason to recommend regular reboots[0], not to force them, and "3 days of inactivity" is a suspiciously specific time that I also saw mentioned in Android settings somewhere the other day.

--

[0] - Which I find deeply ironic, in that merely a decade ago, people would laugh at Windows with its "reboot after installs, reboot in case of problems" approach, and now frequent reboots are seen as Standard Security and Stability Practice on *nix systems, both mobile and server-bound...

pirates 2 hours ago | parent [-]

I have no issue restarting my iOS/Mac/Linux machines because the time to get back to doing fun or productive stuff is measured in seconds. And usually you only have to restart one time. Windows used to take ages, and often you’d reboot only find out that something else that requires a reboot only triggered because of the previous reboot, so you were sometimes in for 2-3 restarts.

It’s not like that anymore in my experience at least but the stigma stuck.

SXX 6 hours ago | parent | prev | next [-]

They dont care about security; only about control.

There are hundreds of millions of outdated Android devices that all Google attestation systems consider secure even though they all running Linux kernel that was never ever updated and can be rooted by anything.

Now try to install your own firmware on them without said outdated kernel... How dare you.

jorvi 5 hours ago | parent [-]

Technically the security works, just for their threat model. An exploit would need root and root means you likely cannot pass attestation AFAIK. The fact that this same exploiter can download all your contacts photos and texts is immaterial to, say, Disney, who want attestation only to prevent ripping of their content.

chii 3 minutes ago | parent [-]

Security, but not for you, is no security.

pjmlp 6 hours ago | parent | prev | next [-]

Ask Jeeves toolbar disagrees.

einpoklum 6 hours ago | parent | prev [-]

It's not even "max security". We are talking about those big tech corps which are infamous for sharing all of your private information with the government, and analyzing it so as to manipulate you in to buying things, and possibly for other obscure commercial purpuses.

chii 2 minutes ago | parent [-]

They securely share your private info with their advertising partners. You know that no hackers that didnt pay google would get access to that information.

stavros 6 hours ago | parent | prev | next [-]

Google doesn't want you to be able to skip YouTube ads. It's as simple as that.

altairprime 6 hours ago | parent | prev | next [-]

No one's requested the config switch from A to B with a restriction that's acceptable to those seeking B. Idealism doesn't tend to offer compromises, and so Idealism tends to lose when it doesn't make a convincing case to regulators. Here's a simple and easy to implement example compromise that could be offered today:

"Changing between A and B requires a device reset."

Most people are going to flat out refuse to wipe their device for a phisher, especially since it'll log them out of everything and trigger all sorts of "new device on your account" warnings everywhere if it's done without their knowledge.

Sure, this is mildly annoying for the 1% that have good reason for A — but it's annoying once per device rather than losing A for good as is happening now. Sure, Google will deny service to A. They're doing that no matter what, either b/c they remove A or b/c they deny A, but this forces them to construct and defend a case for why users who went through the hassle of wiping their device to switch to A ought to be denied access to the app store, and that's a critically absent case in regulatory circles right now. (See also Graphene vs. the EU age check app.)

That's all it would take to protect B from A, but no one asks for it, and no one presses Google publicly for it, and so of course Google isn't doing it. No megacorp will help you walk off the Golden Path without some sort of extrinsic pressure. I see a great deal of clamor around wanting A, but absolutely none of the 'here's a mild annoyance that we came up with as a valid and safe compromise' clamor that would make them look incompetent in the public eye, provide further leverage for EU antitrust steps regarding Android itself, and give them a way to continue to protect users who need B for safety, while allowing those of us who want A to pursue it.

Perhaps other styles of compromise exist, too? As far as I can determine, no one else is thinking about this in terms of "what compromises will developers offer that continue to protect non-developers?", and so I have no other examples to offer. I'd sure love to see more ideas, more effort invested into offering serious and real compromises rather than inflexible resistance of every real safety improvement.

ducktective 6 hours ago | parent | prev [-]

>a config switch between A and B is never considered

And why should modern corpo maintain additional complexity to pander to 1% of privacy-aware tech-savvy users?