Earlier quoted context omitted.
But they are horrible as production machines, at least until when our brain is no longer using our body as interfaces. For pure pocket sized computing, why not use RPi? It's both much cheaper, more customizable, and it runs Linux. With enough tweaking you can make it run completely headless, plug-and-run mini computer that you can ssh over local network. I think the biggest problem with the combining idea is that com…
Phones are kinda too small, but iPads (which are, in essence, oversized phones) are just fine for production machines if you don't equate productivity with programming. With a Pencil and Procreate, it's really hard to beat for drawing and illustrating. With an external keyboard and some kind of stand writing is a joy, I like it better than on a proper computer because of a ton of little things that help me keep focus…
Google have declared Droidscript is malware
221–230 of 665 posts
Re: Google have declared Droidscript is malware
#222Earlier quoted context omitted.
>> "Can't you just make us a general-purpose computer that runs all the programs, except the ones that scare and anger us? Can't you just make us an Internet that transmits any message over any protocol between any two points, unless it upsets us?"[1] The War On General Purpose Computing continues. Far too many business models depend on selling general purpose computers as "appliances". They presume it is possible to…
From the article parent linked: "It doesn't take a science fiction writer to understand why regulators might be nervous about the user-modifiable firmware on self-driving cars" It's not just regulators who are nervous! What if someone modifies the firmware in their self-driving car and introduces a bug that causes the car to crash and kill someone?
Re: Google have declared Droidscript is malware
#223Earlier quoted context omitted.
Most users would prefer a mostly safe experience and gladly give up the option to run arbitrary code on their device for that experience (including arbitrary code they've written). In an all-out "this or that" between allowing IDEs on the Play Store in general and giving the average Play Store user what they want, the IDEs would lose. But it does suck if there is no legitimate way to release an IDE targeted to run on…
Most users don't really understand what they're giving up when they give up the option to run arbitrary code As with privacy (Facebook privacy settings, cookie boxes), it's easy to bamboozle the general public with complexity and then interpret their confusion and (violated) trust as consent.
It's not like people didn't have the experience of using Internet-enabled devices without an app store equivalent in the nascent days of the Internet, where many options were good, a few would inject malware onto your system, but (most importantly) all of the options were equivalent and there wasn't a "correct" one to choose.
Don't make the mistake of assuming that people spend so much on Apple products for no reason. A major portion of the marketplace likes the lack of choice paralysis. The ability to run arbitrary code is one giant choice-paralysis engine. Google has found a good middle ground in selling a device that is basically configured as "safe by default, but here's the break-glass button if you want to run arbitrary code and maybe be more vulnerable to someone tricking you into root-kitting your own device," but their average customer would still rather never worry about the risk of rootkits and they have the data to know that.
If we are to be in the business of protecting the right to free(-as-in-speech) machines in the mobile ecosystem, we need to understand the average consumer that is paying the bill for that industry to exist, and asserting they just don't get it isn't how you start that process.
Re: Google have declared Droidscript is malware
#224Earlier quoted context omitted.
Android is so bad for privacy.
Is AOSP bad for privacy as well? I've been migrating all my services and devices away from Google (I've owned nothing but pixels and nexus phones for a long time) but I was hoping flashing to lineage would work rather than buying a new phone.
Re: Google have declared Droidscript is malware
#225It's seriously time to re-embrace the idea of ownership and control of our devices, and reject Android and iOS altogether. Developing for those platforms has become worse and more restrictive over the years, and this kind of crap is now just everyday news. How good are Pinephones[1]? Are there better alternatives? [1] https://www.pine64.org/pinephone/
Overall I would agree, but I don't see how this specific example has anything to do with that sentiment.
You still have control of your device and can install DroidScript from APK or F-Droid, it was only removed from Play Store, Google's own store.
Obviously this is awful for DroidScript themselves, but you as a user didn't really lose any ownership over your phone due to this specific issue.
Re: Google have declared Droidscript is malware
#226Earlier quoted context omitted.
There's nothing wrong with the appliance business model - embedded devices that use microcontrollers are Turing complete and yet no one complains about those. It's only when devices are marketed as general-purpose (i.e. smartphones, PCs) but are locked down to prevent running arbitrary user-loaded code that it becomes a problem.
As far as I'm concerned, as soon as you've publically released an SDK and invited third parties to form businesses off of developing software for your device, you have no right to represent the device as an appliance. At that point it is obviously a general purpose computer.
Re: Google have declared Droidscript is malware
#227Earlier quoted context omitted.
Maybe it's just time to see phones as what they are - a phone. I don't really care what software is ran in my truck, as long as it works (And that's why I'll not buy a Tesla). It's a phone, use it to call text and guide and browse some internet. That's it.
What’s wrong with Tesla software?
Re: Google have declared Droidscript is malware
#228Earlier quoted context omitted.
Does it? Everyone is quick to judge but coming up with an alternative is hard enough that nobody has done it so far. With scale comes scaling issues; general purpose computing and repairability need a different commercial model that doesn't match with the currently used models. This leaves two avenues: - Make it worse for everyone but keep it going - Make it worse for everyone in a different way and keep it going I d…
Your primary alternative already sounds materially better than the 'Current Scenario' you describe: 1 - I'm not sure I've encountered anybody that universally falls within the 90% 'ideal' coverage. The more hostile things are to outliers, the more difficult everyone's life becomes. 2 - As far as I can tell, the slack that allows the bottom and top vigesimile (? 1/20th) to survive is also what allows the flexibility t…
As for point 2: that should indeed be how it works, but the circumstances have changed, especially for large scale general purpose computing, and for various reasons and stakeholders as well. This is also the (wrong) fuel on the (wrong) fires in the current discussions on ownership, repairability and shared systems; it often tries to compare the "now" with a chosen "back then", and leaves out externalities causing the whole comparison to be useless.
For example: it used to be that you could run whatever code you wanted and you didn't need anyones permissions and nobody could stop you. Now, at scale, that means everyone from teenagers at schools circumventing the implementation of a usage policy to state-level actors extracting information would run whatever they want. They are of course already doing that to some degree, but this would be so much bigger and so much easier when you just 'run whatever code appears at the JMP', we might as well not have an internet.
This, in turn, means that you have to have some form of control, and some form of distribution or supply of such control as neither the will, nor the skill exists at the required scale to have everyone do this individually. How does one assert such control? Cryptographically. And now you're in PKI hell, or you're in DRM hell with DRM servers that go offline and render systems unusable. Oh, and you get DMCA and Legal requirements for free too.
It would be amazing if we could figure out a way to operate shared systems, and have some form of delegated control without having a PKI-like authority as the only way to ensure it. But I haven't seen it yet :-(
And this is just one of the many issues.
Take hardware for example; you can do plenty of nefarious things with hardware, and the user would never know about it. Want to backdoor an audio module so it constantly streams what the microphone picks up to an actor of choice (a social media company, advertising company, your abusive spouse, the government of a state that will hurt you on detection of dissent), you can do that and no normal user would ever notice. How would you then prevent such modification? Well, you could make hardware hard to access or hard to modify without visible marks. That's one area (slightly) covered, but then there is the software, imagine hacking that remotely. So how would you do something about that? Perhaps signing the software and checking the signature. Bam, back in PKI hell.
And if you were to make hardware hard to access, now you have a bad UX when someone comes to your service department and gets presented with a huge bill because your device had to be rebuilt because your kid put puke in the microphone hole. But if you make it unsafe you have the other problems again. No winning deal there. Or what if you use seals, now you have no idea why the seals are broken. Did someone tamper with it? Was it just a service call that's not registered in your system because it was done elsewhere? Who can you trust? What if you fix the reported issue but now something else breaks and you don't know if you did it or the previous tech did it? Guesses everywhere, everyone is sad, nothing works. yay.
Again, no real solution here. Say you do the (not very often implemented) secure boot method where you insert your own CA; that's great for yourself, not great for a shared system, because now everything else that requires you to be securely booted needs to trust that CA too. This, hoever, is an area where you can do a partial fix: if you just want local verification and you have the CA and CT you can at least know for yourself. But that doesn't work at scale. We can't expect billions of people to be PKI experts. And we can't expect them to understand the ramifications of the lack of verification either. (which includes effects on them, but also effects on everyone else they are in contact with by proxy) So now you still need that 'magic' central authority making a policy and a verification for that policy and enforcement. PKI hell all over again!
(keep in mind, I don't name PKI hell a hell because PKI is bad, I think it's great and I love me some hashing, public-key cryptography and root-of-trust chains -- it's just that there is no solution right now where you don't end up having an authority that can use it for good and bad at the same time)
There are a lot of scenarios where we could mitigate 'some' of it:
- Authenticated core but leave peripherals alone (your mainboard and CPU and AV chain would be on its own, but your keyboard can be key logging you as much as you want)
- Unauthenticated mode but no interaction with shared systems (would work great for things like farming equipment)
- Offline or do-it-yourself mode (again, no interaction, but you'd be offline anyway)
But then you're still in the realm of real-world abuse (want to know your ex'es password? backdoor the keyboard! steal your boss's documents? backdoor the printer!).
I don't know how to fix all of this, but removing all forms of authentication and still having shared systems isn't the way.
Re: Google have declared Droidscript is malware
#229Earlier quoted context omitted.
As far as I'm concerned, as soon as you've publically released an SDK and invited third parties to form businesses off of developing software for your device, you have no right to represent the device as an appliance. At that point it is obviously a general purpose computer.
Would you call things like the Amazon Echo and Sony Playstation general purpose computers?
Re: Google have declared Droidscript is malware
#230It's seriously time to re-embrace the idea of ownership and control of our devices, and reject Android and iOS altogether. Developing for those platforms has become worse and more restrictive over the years, and this kind of crap is now just everyday news. How good are Pinephones[1]? Are there better alternatives? [1] https://www.pine64.org/pinephone/
Maybe don't scratch Android too fast. Android is opensource, and is technically really great. There is a great opensource community of people that are very capable in this area, and supports already the vast majority of devices in the world. You only need to get rid of Google. Which many custom Android provide. Personally my smartphone is a Pixel 5 (IMO best smartphone currently available that fit in a hand), running…
Android itself might be really good, but it's pretty obvious that deGoogled phones have a strong chance of being functionally useless in the future.