| ▲ | rock_artist 8 hours ago | |||||||||||||||||||||||||||||||||||||||||||
We already had enough proof of vulnerabilities in the OS code and Manufacturers (eg. Samsung/Lenovo/etc privileged apps), there were enough reviewed apps that were used for fraud or access as bad actors. My banking works in my 'unprotected' computer browser. So I'd expect giving anyone equivalent freedom. I don't mind if there's a default for gate-keepers as long as they allow competition. but I would expect to have same freedom on my mobile devices as on my laptop. | ||||||||||||||||||||||||||||||||||||||||||||
| ▲ | GuB-42 5 hours ago | parent | next [-] | |||||||||||||||||||||||||||||||||||||||||||
Just because there are known vulnerabilities don't mean we should drop other security features, this is the opposite in fact. Defense in depth, an OS-level vulnerability cannot be exploited if the attacker cannot access that part of the OS. And like it or not, the Play Store approval process is a security feature. It limits the ability of bad actors to run code on your phone and access data or exploit vulnerabilities they wouldn't be able to otherwise. Some get through, but it makes their life harder, again, defense in depth. Something can be both an anticompetitive practice and a security feature. As for banking in the browser, you can, but your bank probably doesn't like it. That's why they are pushing for browser attestation, or to force you to use the app. The banks would rather take that freedom away from everyone rather than giving it to everyone. And I suspect they do it for good (as in profitable) reasons, fraud costs them, it costs them more than what they would gain by being more open. If we want security features and freedom (which is the harder option), we need competition. If Google and Apple are the only players besides an insignificant minority, it is easy to lock software to these platforms, screw that weird guy with his Linux distro. Legislation is another option if the first one fails. | ||||||||||||||||||||||||||||||||||||||||||||
| ▲ | echelon 7 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||
Sandbox, ACL, scan, sign, revoke bad actors. We should have web installs by now. The only reason we don't is because Google and Apple like cash and their little monopolies are easy money. Big tech loves to "protect us". See Anthropic and OpenAI worried about intelligence. Google doesn't care that its AdSense ads marketplace is flooded with malware. Or that YouTube is rife with scams. Wonder why not. The blatant policy contradiction couldn't be because money, right? | ||||||||||||||||||||||||||||||||||||||||||||
| ▲ | yacthing 7 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||
Do people not remember the days of viruses destroying computers? They were a massive issue before, and now they're barely a thought for most people. These review processes have been good for the general population. | ||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||
| ▲ | ignoramous 6 hours ago | parent | prev [-] | |||||||||||||||||||||||||||||||||||||||||||
> We already had enough proof of vulnerabilities in the OS code and Manufacturers (eg. Samsung/Lenovo/etc privileged apps) Vulnerabilities aren't intentional. > reviewed apps that were used for fraud or access as bad actors The App Developer Verification program, Android Advanced Protection Mode, and Play Protect are all systems put in place in response to "bad actors". | ||||||||||||||||||||||||||||||||||||||||||||