Live data from Hacker News

Android’s desktop interface leaks

9to5google.com

381–390 of 393 posts

Re: Android’s desktop interface leaks

#381

ChromeOS is 14 years old, not really sure why they’re just now going this route. Android laptops are nothing new, unless you don’t count the crappy low end ones that have no business running it. I’m sure Google will make their flagship apps nicely tailored but regular phone centric apps has to be an awkward experience.

I like ChromeOS but really having two different operating systems is a liability.

Despite all the effort they've put into it, chromeOS is worse at running Android apps than android tablets except for support for having them in resizable windows.

All they need to do is improve the support for a laptop mode on android and make chrome on android in the laptop mode equivalent to chrome on ChromeOS and they can kill ChromeOS entirely.

It makes no sense to have to choose between two operating systems

You should be able to get a fully compatible android like experience in tablet mode and a chromebook like experience in laptop mode all in one os

And the ChromeOS like experience should be available on any android tablet if you use it with a keyboard

Re: Android’s desktop interface leaks

#382

Earlier quoted context omitted.

Hiding the bottom bar doesn't solve the problem because it still takes the corners away. You can't put UI there because the bottom bar will come up and cover it when you mouse into the corner. The OS is taking all four corners for itself. Greedy! Apps should have that space. Apps are what we are here to use and the OS is getting in the way.

macOS doesn't seem to care and that's what all the designers use. I'm guessing people think it's pretty? The dock would also better if it weren't stretched to the entire screen width by default but perhaps Google is planning to use that space for something. It's also possible they're going to remove the top bar at some point, that'd make the UI standard Windows-shaped. The Gnome trick for the dock is to only show the…

Only designers earning US like wages.

Designers in the remaining 80% of the computing world have to do with what is available.

Re: Android’s desktop interface leaks

#383

They ought to put the status bar at the bottom. All the designers using Macs probably forgot, but Chrome's tab interface was designed for Windows where it could be all the way at the top of the screen. And in general it's more common for desktop apps designed for mouse and keyboard to have frequently accessed UI elements at the top of the window than the bottom. So desktop apps would benefit from being able to use th…

Samsung did not forget, and did it right with DeX. They did, however, get some of the interactions wrong (not to mention, handling of display resolution), so in the end, you can't exploit Fitt's Law in DeX either.

Yeah even on an oldie S6 Lite is good enough.

Re: Android’s desktop interface leaks

#384
post #347

Earlier quoted context omitted.

You can't provide a passkey to a malicious site without writing your own web browser. And the "password" is a 128-bit integer. It completely solves the phishing-password-stealing problem.

That was an example, I was talking about phishing in general. Phishing will always exist: as long as a human has a right to do something, someone else can trick this human into doing it for them. Passkeys are great, and they do improve the situation. But they won't remove phishing as a concept.

I think a passkey is a good example of how, when the user has a trusted third party grant them limited instead of unlimited permission to do something (e.g. they can use a secret with the site that created it but they can't extract the raw secret from it to send to an arbitrary site), it is possible to make them immune to a particular type of phishing.

As an example of mitigating another type of phishing, if the user only has the ability to log in to a web site from a particular device or country, an attacker tricking them into providing their password gets a much less useful win.

You could argue they have the "right to do" less in that situation. Sure, that's a reasonable perspective. I'm not passing moral judgement here. But I think that it is a factually true statement that it is indeed possible to mitigate (and even entirely prevent) phishing vulnerabilities by giving end users devices that have stronger security policies - with those policies being written by the device creator, and not edited by the end user themself.

I think this principle applies to every single type of social engineering attack. Limiting the context of permissions lessens the risk of a confused deputy.

Re: Android’s desktop interface leaks

#385
post #300

Earlier quoted context omitted.

Android runs Firefox.

... for now. I mean all Google's decisions are going the same way, and let's face it: Firefox stands in the way of their destination.

No Firefox increases their chance of being broken up for monopolization.

Re: Android’s desktop interface leaks

#386

Oh, I see Google's angle now. They want to make android a viable desktop OS in order to have more users using android Chrome rather than Windows Chrome, because the former lacks extension support, and thus ad blockers. Of course, you can still install brave or kiwi browser or Firefox to your heart's content, but most people won't. It's brilliantly simple. It's not too bad for power users, they'll probably use a diffe…

This shows a version of Chrome with extensions. > The Google Chrome interface mostly aligns with the current large-screen Android version except for the Extensions button, which is currently only available on the desktop browser.

Wow, I don't know how I missed that. Guess that theory goes out the window!

Re: Android’s desktop interface leaks

#387
post #347

Earlier quoted context omitted.

That was an example, I was talking about phishing in general. Phishing will always exist: as long as a human has a right to do something, someone else can trick this human into doing it for them. Passkeys are great, and they do improve the situation. But they won't remove phishing as a concept.

I think a passkey is a good example of how, when the user has a trusted third party grant them limited instead of unlimited permission to do something (e.g. they can use a secret with the site that created it but they can't extract the raw secret from it to send to an arbitrary site), it is possible to make them immune to a particular type of phishing. As an example of mitigating another type of phishing, if the user…

I am not sure what you are trying to say.

Security is a gradient. At some point, adding security means reducing freedom. It is a societal choice where you stop. If you put all the humans in your country in a jail, each in a separate cell, never let them go out and just bring them food, then there will be no crime in your country. But nobody wants that.

> I think this principle applies to every single type of social engineering attack. Limiting the context of permissions lessens the risk of a confused deputy.

A confused deputy is a computer program. We're talking about phishing.

Re: Android’s desktop interface leaks

#388
post #387

Earlier quoted context omitted.

I think a passkey is a good example of how, when the user has a trusted third party grant them limited instead of unlimited permission to do something (e.g. they can use a secret with the site that created it but they can't extract the raw secret from it to send to an arbitrary site), it is possible to make them immune to a particular type of phishing. As an example of mitigating another type of phishing, if the user…

I am not sure what you are trying to say. Security is a gradient. At some point, adding security means reducing freedom. It is a societal choice where you stop. If you put all the humans in your country in a jail, each in a separate cell, never let them go out and just bring them food, then there will be no crime in your country. But nobody wants that. > I think this principle applies to every single type of social e…

Originally you were positing that phishing (specifically password phishing) was not preventable.

Now you are arguing that by restricting users' permissions it is possible to move along the security gradient, potentially to a point where phishing is not a viable threat.

I agree.

Re: Android’s desktop interface leaks

#390
post #387

Earlier quoted context omitted.

I am not sure what you are trying to say. Security is a gradient. At some point, adding security means reducing freedom. It is a societal choice where you stop. If you put all the humans in your country in a jail, each in a separate cell, never let them go out and just bring them food, then there will be no crime in your country. But nobody wants that. > I think this principle applies to every single type of social e…

Originally you were positing that phishing (specifically password phishing) was not preventable. Now you are arguing that by restricting users' permissions it is possible to move along the security gradient, potentially to a point where phishing is not a viable threat. I agree.

As I said, I was talking about phishing generally. Password was an example, and passkeys do help with some of the pain there, for sure.

> potentially to a point where phishing is not a viable threat

You keep ignoring the parts that are inconvenient to you :-). I said that at some point, increasing security means decreasing the freedom. It's a compromise. And as long as people have some freedom, someone will be able to abuse it. Phishing will always exist. The only way to prevent phishing entirely is to remove all the rights of everybody. If I cannot do anything, then I cannot do anything wrong. As long as I can do something, I can do it wrong. Phishing fundamentally leverages that.

Post reply on HN