We should have the ability to run any code we want on hardware we own
861–870 of 1001 posts
Re: We should have the ability to run any code we want on hardware we own
#862I think the conversation needs to change from "can't run software of our choice" to "can't participate in society without an apple or google account". I have been living with a de-googled android phone for a number of years, and it is getting harder and harder, while at the same time operating without certain "apps" is becoming more difficult. For example, by bank (abn amro) still allows online banking on desktop via…
Wow. You nailed it. Thank you.
When desktop operating systems were dominant, the need for the freedom to control your own software installation was beyond obvious.
But now our phones are an even more dominant/necessary computing/communication tool.
Apple and Google's appeal to security is such a fig leaf. They can continue to lock down our phones, add even more security.
BUT, simply provide a way for users to mindfully bypass that. They could make the pass through screen as scary as they feel they need to. That's it.
(If they did that, customer pressure would naturally build over time, for less draconian warnings, as other verifiably/clearly responsible sources became popular.
Another benefit. Apple would soon put its considerable resources competing to delivering the most robust security of a more valuable kind. The kind that enforces the walls between unpermissioned/dark behavior without limiting desired behavior and innovation. That would create healthier quality-loyalty based "lock in" that their vertical integration and high focus DNA already gives them advantages to "win".)
Re: We should have the ability to run any code we want on hardware we own
#863Earlier quoted context omitted.
So what? Should security features be illegal so people can more easily run their own OS's on phones?
Yes? A car that can only drive itself at 10 MPH by a software lock is certainly safer. But that's stupid and that should be illegal. Also, the horse is driving the carriage here. Why do you think Apple is just de facto more secure? That's just pure blind faith. You have zero evidence for that and you couldn't find evidence if your life depended on it. The entire device is closed-source. Youre just blindly trusting Ap…
Re: We should have the ability to run any code we want on hardware we own
#864Earlier quoted context omitted.
Anywhere that US TSA runs the AIT scanners, you can opt out of them*. That is domestic US airports plus airports like Toronto and Dublin where you, for practical purposes, clear into the US on foreign soil and land in the US as a domestic flight. * - I think this only doesn't apply if your boarding pass got tagged with the dreaded "SSSS" enhanced screening tag, but that's a fairly rare corner case for most passengers…
My understanding, which may be wrong. It's been a few years since I did this dance. You can opt out of the millimeter wave radar. Opting out means you go through a metal detector, a 20-second pat-down and perhaps a hand swab for explosives sniffer. If you have SSSS on your boarding card, that means the pat-down, hand swab and digging through your carry-on luggage happen whether you opt out of the mmwave or not.
From the TSA website, https://www.tsa.gov/news/press/factsheets/technology , "Most passengers have the opportunity to decline AIT screening in favor of physical screening. However, some passengers will not be able to opt out of AIT screening if their boarding pass indicates that they have been selected for enhanced screening."
Re: We should have the ability to run any code we want on hardware we own
#865Earlier quoted context omitted.
Good point. The current security model of desktop OSs sucks. I was recently reminded of this by an issue at work. I'm used to devs having admin rights on their laptops, but here they closed that down: you have to request admin rights for a specific purpose, and then you get them for a week. I recently requested those rights again because I needed to install something new for a PoC I was working on, and that wasn't al…
There is software that does exactly that. You install a software kiosk were users can pick from and users don't get admin rights. Won't satisfy developers for long though because it cannot work. The problem is that mobile OS security systems isn't fit to develop anything but shit. It is simply no solution for desktop.
But then again, we write and execute our own code, so of course we have to be able to execute unknown code.
The whole thing feels like an exercise in futility to me. It would make more sense to specify what rights a specific application should have. Let me approve the external urls it wants to visit, the folders it wants to access, etc. Shield everything else off.
Re: We should have the ability to run any code we want on hardware we own
#866Earlier quoted context omitted.
> The real problem is that @gmail.com or @icloud.com are now required to participate in society They absolutely are not, though. I've been fully bought into the Apple ecosystem for nearly 2 decades and have used a Fastmail email address with it for the last decade (when I ditched my MobileMe email address). Similarly, I have never had an @gmail.com email address, though I've used various Google products.
They meant an apple or Google account, not literally the email address. Try to live without an Apple ID or Google account. Probably about as difficult as living without an ID.
Re: We should have the ability to run any code we want on hardware we own
#867Earlier quoted context omitted.
You mean like if there were a standard (JSON, XML, whatever) format of document that you could cryptographically sign which would order a transaction to take place? Kind of like a digital teller's slip?
That would be nice, but how would the bank verify the signature? It's the same old key exchange problem all over again. In any case, that's not what I was suggesting. I was simply suggesting that banks shouldn't be allowed to force you to depend on certain apps or app stores to get access to your money. Similarly, schools shouldn't be allowed to force you to depend on certain apps or app stores to take proper care of…
I suppose you could print your public key as a QR code on a piece of paper, or display it on a phone, or use a USB security key device, and physically give it to an authorized employee at a local bank branch. Or if there is a way to electronically open an account you submit it then, along with whatever other proof of identification is deemed acceptable. I think root of trust has been, and always will be, a hard problem. It's just about finding the acceptable level of risk. Security is weaponized inconvenience.
Edit: Just to think down that road a little further, I expect the issue exists because the solution chosen by the school/bank/gov't/business will not be the optimal one for users, but the most expedient for the org. They're going to do the lazy thing that works for 80-90%, because there currently is no better alternative that they can implement with minimal effort.
If we look at the past we see that postal mail and telephones became standard methods of communication, but you could always walk into an office somewhere and handle business in person. Now that last default is quickly being phased out. So what should be final fallback method of communication?
So I see two problems: there is no better way, and there is no required minimum. Both need to be solved.
Re: We should have the ability to run any code we want on hardware we own
#868I think the conversation needs to change from "can't run software of our choice" to "can't participate in society without an apple or google account". I have been living with a de-googled android phone for a number of years, and it is getting harder and harder, while at the same time operating without certain "apps" is becoming more difficult. For example, by bank (abn amro) still allows online banking on desktop via…
Normally tie in sales are illigal, but because it happens in the digital world, we/they fail to notice...
Its banks, but also government and health (the dutch digi-d app), food markets, schools, more and more
If there is a EU DMA, where is an independent app store?
Re: We should have the ability to run any code we want on hardware we own
#869Earlier quoted context omitted.
I think I might enjoy the CPS scenario... let them call CPS, and wait for CPS to arrive, and then discuss with CPS who is endangering the child, the parent or the school. I'm pretty sure a judge will quickly decide whether their rule makes sense or not, and I think judges in child protection cases are going to quickly side with what's important for the child. I HATE this kind of nonsense, and threatening you as a par…
Well the judge will likely rule the app is bullshit, but in the meantime CPS will argue they need to go into your house, look to see if you have a dirty dish, or the wrong proportion of snacks to vegetables, or maybe take notice your child is playing independently outside while they come around. Then they will portray that in the most insane way possible, and since it is a civil and not criminal process their is no r…
I once called them because the day care lady of a friend‘s kid is a bit of an idiot and kinda scared us about mass closure of day care centers and it was probably the nicest interaction I’ve ever had with a government agency.
But from what I’ve heard, America in general is a whole other beast both regarding expectations for parents, trust in the kids and the trouble you can get in for minor things.
Re: We should have the ability to run any code we want on hardware we own
#870Earlier quoted context omitted.
It's not theater, your IT department just isn't implementing it correctly. I recently switched jobs and gave up one macbook pro for another (work issued). Company A gave me sudo access and I could do anything I wanted. Company B locks down everything, no sudo, no brew, nothing. But I do get a big VM with root to do anything I want. There is an approved "appstore" of many different varieties of IDEs/tools. TLDR: Not h…
Interesting. If you don't mind, I have a few questions: 1. Is the "big VM with root" running macOS itself, or a different OS? 2. Do you do any work on the bare metal version of macOS, or do you just start the VM in the morning and do everything from there? 3. How do you experience the performance/UX of the VM? 4. Do you know why Company B IT has set up this VM solution, instead of a plain old MacBook locked down with…
(This was at a branch office where every employee worked on very low-level Linux kernel code, so yeah everyone ran their favorite Linux distro.)