Live data from Hacker News

Update from the CEO

googleblog.blogspot.com

201–210 of 216 posts

Re: Update from the CEO

#201
post #194

Earlier quoted context omitted.

You manage to say a lot while saying absolutely nothing of value. That sounds harsh, but seriously thus far you've said that Andy Rubin is to blame for because , and Android has versus . I don't think I've ever read such an absolutely and completely unsupported comment chain that wasn't sitting deep in negative territory on HN. And seriously, the nonsense tweet by Schiller (who would have known that Apple would toss…

I linked to our research page, right? http://www.trailofbits.com/resources/mobile_eip_2.pdf http://techchannel.att.com/play-video.cfm/2013/1/8/Conferenc... http://techchannel.att.com/play-video.cfm/2011/7/14/Conferen... If you think that Android has a "deeply secure design", than then you probably want to start at the top. Android sits somewhere between "gift to hackers" and "Windows XP". Phil Schiller's tweet was po…

Firstly, the updating problem is a distribution flaw, not a design flaw. The carriers are to blame for that.

Secondly, code-signing is a very restrictive approach and is hardly without tradeoffs. If you're going to use iOS as an example, it strongly discourages casual development for a slew of reasons, and there are countless examples of Apple rejecting apps for arbitrary reasons, far beyond issues of malware.

Your third point is really only an extension of your second.

Maybe you don't personally feel you've had to give anything up for the security that iOS affords, but it's disingenuous to assert that there aren't any tradeoffs at all. Android's more open approach is more true to its open source roots. For it to be different than iOS gives us choice, which is a good thing.

Re: Update from the CEO

#202

Observation by Benedict Evans: almost all key divisional leads at Google were born in India. Android, Engineering, Advertising, Youtube… Polar opposite to Apple, which is a white boys club.

Does Apple have any non white VP level/very senior management level folks? (I don't have a problem with this being the case, just curious).

Re: Update from the CEO

#203
post #138
post #134

Earlier quoted context omitted.

He's not wrong. There's always a tradeoff between security and usability. http://www.schneier.com/blog/archives/2009/08/security_vs_us... The key is finding the right balance.

You couldn't be more wrong and, unfortunately, I don't have the karma yet to enable downvoting :-). Easy example as long as we're on the topic, the Chrome browser or ChromeOS. I can think of a dozen things that could be done to Android to both mitigate against current threats and exploited weaknesses and either not interfere with or improve user experience. Unfortunately, we are long past the point where fundamental…

Please be humble, when you have the capability to down vote comments in the future and think of the humbleness from the HN Guidelines and this particular part: "When disagreeing, please reply to the argument instead of calling names." (Albeit, you're not calling names - but threatening to down vote is a little bit uneasing.)

Thank you.

Re: Update from the CEO

#204
post #86

Earlier quoted context omitted.

That's a very narrow perspective, based solely on what is "painful" for the developer. Developer pain isn't, generally, a good indicator of the public good. Obviously the real driver for "fragmentation" is that there exists a market which is (1) lucrative and (2) easy to enter. So everyone rushes in with their devices and competes. And somehow you think this is a bad thing? Stated simply: "fragmentation" is a side ef…

I agree with the efficiency part with regards to android lowering the Barrier to Entry, but the 2 year contract to make the devices "affordable", surely doesn't work in favor of market efficiency.

My N4 out of contract from google wasn't that much more than say an S3 on contract... My last three phones have been off contract with cheap all you can use reseller services... the lower month to month makes up for the price difference in 4-6 months

Re: Update from the CEO

#205
post #194

Earlier quoted context omitted.

You manage to say a lot while saying absolutely nothing of value. That sounds harsh, but seriously thus far you've said that Andy Rubin is to blame for because , and Android has versus . I don't think I've ever read such an absolutely and completely unsupported comment chain that wasn't sitting deep in negative territory on HN. And seriously, the nonsense tweet by Schiller (who would have known that Apple would toss…

I linked to our research page, right? http://www.trailofbits.com/resources/mobile_eip_2.pdf http://techchannel.att.com/play-video.cfm/2013/1/8/Conferenc... http://techchannel.att.com/play-video.cfm/2011/7/14/Conferen... If you think that Android has a "deeply secure design", than then you probably want to start at the top. Android sits somewhere between "gift to hackers" and "Windows XP". Phil Schiller's tweet was po…

If Android didn't have side-loading, the capability of having third-party app stores, and access to the shell (to the point of being able to run a terminal), I would likely not be using it. The more PC-like it is, the more usable it is to me, in the medium / longer term, as devices in tablet form factor replace mobile PC use cases.

Re: Update from the CEO

#206
The "open source" posturing is very annoying. They're just doing it for the PR.

Even considering the subset of Android that is "open source" the development process is closed and we just get code drops after product releases. It's like Apple used to do when they were playing the game with Darwin. They're doing a lot of work to avoid and purge LGPL and GPL code so they can work this way. It's not even free to use for vendors, you need to pay licensing fees to get a useful system out of it and sign contracts subjecting you to Google's whims.

Re: Update from the CEO

#207
post #194

Earlier quoted context omitted.

You manage to say a lot while saying absolutely nothing of value. That sounds harsh, but seriously thus far you've said that Andy Rubin is to blame for because , and Android has versus . I don't think I've ever read such an absolutely and completely unsupported comment chain that wasn't sitting deep in negative territory on HN. And seriously, the nonsense tweet by Schiller (who would have known that Apple would toss…

I linked to our research page, right? http://www.trailofbits.com/resources/mobile_eip_2.pdf http://techchannel.att.com/play-video.cfm/2013/1/8/Conferenc... http://techchannel.att.com/play-video.cfm/2011/7/14/Conferen... If you think that Android has a "deeply secure design", than then you probably want to start at the top. Android sits somewhere between "gift to hackers" and "Windows XP". Phil Schiller's tweet was po…

>Android sits somewhere between "gift to hackers" and "Windows XP".

It is hard to take you seriously.

Let's be clear that the malware problem on Android aren't apps exploiting any weakness in the platform itself beyond the simplicity of pushing apps onto the market. They aren't exploiting that devices are running Gingerbread or anything like that.

These are apps doing exactly what they are allowed to do by the system -- after advertising their intentions and doing exactly what they declared that they could do -- but they are malicious because the things they are doing aren't in the best interest of the user.

e.g. an ostensible puzzle app that actually sends contact information to a third party (after declaring and getting permissions for contacts and internet access), or that sends pay SMS' to Nigerian sex operators, again after declaring and getting permissions for contacts and internet access.

When anti-virus vendors and please-pay-attention-to-us tiny security upstarts talk about malware, that occupies 99.9% of the space (if not 100%). It is a trust and validity issue with Google and the Play Store that requires much better vetting and culpability of developers, and vetting of applications (not in the "don't do anything that overlaps us" manner of Apple, but simply to validate the scope of functionality, fitness for advertised purpose, and lack of clear trademark and copyright infringement that is so prolific on the Play store).

That has nothing to do with the platform and everything to do with one store.

Re: Update from the CEO

#208
post #194

Earlier quoted context omitted.

I linked to our research page, right? http://www.trailofbits.com/resources/mobile_eip_2.pdf http://techchannel.att.com/play-video.cfm/2013/1/8/Conferenc... http://techchannel.att.com/play-video.cfm/2011/7/14/Conferen... If you think that Android has a "deeply secure design", than then you probably want to start at the top. Android sits somewhere between "gift to hackers" and "Windows XP". Phil Schiller's tweet was po…

>Android sits somewhere between "gift to hackers" and "Windows XP". It is hard to take you seriously. Let's be clear that the malware problem on Android aren't apps exploiting any weakness in the platform itself beyond the simplicity of pushing apps onto the market. They aren't exploiting that devices are running Gingerbread or anything like that. These are apps doing exactly what they are allowed to do by the system…

You clearly didn't read a single link that I posted. I did a comprehensive study of all malware targeting mobile devices between 2011 and 2012 and, yes, they are targeting the device itself and the design choices made while building it.

EDIT: oh wait, there you go blaming the user again. "Grandma should have known the difference between THIS app that requested her contacts and THAT app that requests her contacts and stole them. Jeez Grandma! Get with it!"

How is that not a design problem? I thought we gave up delegating security decisions to the user after we saw what happened with SSL?

Re: Update from the CEO

#209
post #194

Earlier quoted context omitted.

I linked to our research page, right? http://www.trailofbits.com/resources/mobile_eip_2.pdf http://techchannel.att.com/play-video.cfm/2013/1/8/Conferenc... http://techchannel.att.com/play-video.cfm/2011/7/14/Conferen... If you think that Android has a "deeply secure design", than then you probably want to start at the top. Android sits somewhere between "gift to hackers" and "Windows XP". Phil Schiller's tweet was po…

If Android didn't have side-loading, the capability of having third-party app stores, and access to the shell (to the point of being able to run a terminal), I would likely not be using it. The more PC-like it is, the more usable it is to me, in the medium / longer term, as devices in tablet form factor replace mobile PC use cases.

There are safe ways to enable access to it. Take ChromeOS for example, which has a hardware switch on the outside of the device that "jailbreaks" it and allows access to these features. Lack of such creativity by the Android team with regard to security has had a major impact on their current state.

Re: Update from the CEO

#210
post #201
post #194

Earlier quoted context omitted.

I linked to our research page, right? http://www.trailofbits.com/resources/mobile_eip_2.pdf http://techchannel.att.com/play-video.cfm/2013/1/8/Conferenc... http://techchannel.att.com/play-video.cfm/2011/7/14/Conferen... If you think that Android has a "deeply secure design", than then you probably want to start at the top. Android sits somewhere between "gift to hackers" and "Windows XP". Phil Schiller's tweet was po…

Firstly, the updating problem is a distribution flaw, not a design flaw. The carriers are to blame for that. Secondly, code-signing is a very restrictive approach and is hardly without tradeoffs. If you're going to use iOS as an example, it strongly discourages casual development for a slew of reasons, and there are countless examples of Apple rejecting apps for arbitrary reasons, far beyond issues of malware. Your t…

The updating problem is a design flaw they knew they would have to deal with and that they did nothing about until version 4, when they started trying to separate core functionality out into apps. That's not acceptable.

Code signing can be implemented while still allowing for casual development. See my comment above about the hardware switch on ChromeOS devices.

My third point is regarding how the architecture of the platform complicates the ability to analyze apps that run on it for malicious behavior. The NDK, the access to the Linux kernel, and a strategy based around dynamic analysis were all design choices that impacted that.

I understand that Android wants to be more open than iOS but you're making the same mistakes the Android team did. Namely that there's no way to deploy the same or similar security improvements without sacrificing something else. It's just not true.

Post reply on HN