> Now read the entire sentence for the context which you carefully removed for that quote:
There is no context to save it, the mistake remains: in the common situations you describe the poor user will not be helped with the prompt
> The point is that most people have an incorrect threat model for USB devices
Sure
> This policy is a compromise designed to deal with all of those problems
Except it does nothing of the sort. You've ignored this type of question a couple of times, maybe 3rd time is the charm: how would an ignorant user learn of the correct threat model from this prompt?
> if you want to rules lawyer I would suggest considering whether any “strongest plausible interpretation” requires trimming quotes like a creationist, not to mention whether a brusque and cursory dismissal of a security UI decision made by one of the top companies in both disciplines is a substantial contribution.
And I would suggest whether using more inflamatory terms about lawyering/creationist is repeating the same mistake. Also, there is no context to save your quote, so I don't understand which strongest interpretation would help you.
Argument from some company's authority is also rather weak
> One scenario is certainly that the device is left logged in and unlocked and someone just hammers the Allow button without thinking about it but it's not the only one.
Sure, but it's the most common scenario, so it's the one that matters most in evaluating this change!
> 1. The device isn't unlocked so they get power but nothing else, and the device is never attacked.
There is no prompt in this scenario, how is it relevant?
> 2. That device is still connected but when the owner unlocks it, they see the prompt and deny access
You know my response to this already since you referenced it earlier, but didn't understand it and also didn't bother to think about it when I pointed the misunderstanding out. Let me elucidate: this scenario doesn't justify prompts when a device is plugged into an unlocked laptop.
> 3. you know a light shouldn't need anything other power.
You know nothing of the sort, there is "Smart" written on the package, so of course it's expected for it to communicate with the computer! We're living in the future after all where even your toaster has a wi-fi!
> Having seen one of the many movies or TV shows produced in the last 30 years which has a plot detail along these lines, you consider the possibility that it's something nefarious.
Yeah, this is exactly the mythical consumer I argued against - learning about computer security from pc-illiterate TV shows!
> An OS vendor has to design mechanisms which are suitable for a wide range of people and that's why the UI for this is configurable.
This is not suitable for a wide range of people. It's suitable for the tiny minority knowledgable about these type of attacks (and you can't learn about them form the prompt itself, the OS vendor knows best!) while negatively impacting everyone else
> It's not ad hominem to point out the problems with your argument.
That's not what you did, instead you've made up an angry emotional state as the explanation
> Multiple people in this thread have been trying to help you better understand the threat being countered and how the situation isn't as simple as your dismissals assume.
Right after I'm convinced that multiple people can't repeat mistakes