What I find most annoying aspect of all software from 2010s onwards is this stupid discourse and associated results:
- some people want A, or A might even be already in use
- A is problematic for $MODERATE_OR_MILD_REASON
- B is introduced and made default
- a config switch between A and B is never considered
So, so tiring. If I want to bind ADB to localhost, _let me_. It's my device and my problem, ffs.
Toxic max security.
Not everyone has the same threat model as you, $BIGTECHCORP.
Isn't security just an excuse to push user hostile features?
Like, if security was a concern we would have simpler systems and still use 2fa devices for banks etc.
Sometimes it's truly useful featutes, but having no toggle in settings making it terrible.
Like iPhone idle auto-reboot every 3 days. After a while they added "Allow Idle Reboot" flag but it only accessible via MDM and require device wipe and for switching it to be a managed device.
What would that be useful for anyway? Sounds like something aimed to prevent people from reusing their old/secondary devices for IoT.
> What would that be useful for anyway?
It puts iPhone in cold boot state if for instance police or any agency confiscate it from you. Better tamper proofing.
Hides memory leaks
Right, that too. But that's a reason to recommend regular reboots[0], not to force them, and "3 days of inactivity" is a suspiciously specific time that I also saw mentioned in Android settings somewhere the other day.
--
[0] - Which I find deeply ironic, in that merely a decade ago, people would laugh at Windows with its "reboot after installs, reboot in case of problems" approach, and now frequent reboots are seen as Standard Security and Stability Practice on *nix systems, both mobile and server-bound...
I have no issue restarting my iOS/Mac/Linux machines because the time to get back to doing fun or productive stuff is measured in seconds. And usually you only have to restart one time. Windows used to take ages, and often you’d reboot only find out that something else that requires a reboot only triggered because of the previous reboot, so you were sometimes in for 2-3 restarts.
It’s not like that anymore in my experience at least but the stigma stuck.
They dont care about security; only about control.
There are hundreds of millions of outdated Android devices that all Google attestation systems consider secure even though they all running Linux kernel that was never ever updated and can be rooted by anything.
Now try to install your own firmware on them without said outdated kernel... How dare you.
Technically the security works, just for their threat model. An exploit would need root and root means you likely cannot pass attestation AFAIK. The fact that this same exploiter can download all your contacts photos and texts is immaterial to, say, Disney, who want attestation only to prevent ripping of their content.
No it doesnt actually work because its possible to do privilege escalaction without tampering with firmware or filesystem or triggering other markera. OS will be practically rooted while passing attestation just fine.
Only things attestation do is security theater and messing up people ability to use software of their choosing.
Security, but not for you, is no security.
Have you read the android security model? It's a multi party security model which considers apps and users as equals. It's a legitimate security model and just because it's not what you want doesn't mean it's wrong.is it user hostile? Maybe. But that is different than saying it offers no security. It's also not worth bickering about every small decision that is made in line with that security model. If you want a different one, push for it via alternative OS.
Ask Jeeves toolbar disagrees.
It's not even "max security". We are talking about those big tech corps which are infamous for sharing all of your private information with the government, and analyzing it so as to manipulate you in to buying things, and possibly for other obscure commercial purpuses.
They securely share your private info with their advertising partners. You know that no hackers that didnt pay google would get access to that information.
Google doesn't want you to be able to skip YouTube ads. It's as simple as that.
More specifically apps and users have equal agency in the android security model. Which comes down to the fact that if you don't own the app you can't control its experience. This feels grounded to me. Push for more open source apps where you retain control and ownership.
No, I bought the device, I should be able to do whatever I want with it.
And app developers have the right to not offer their services to users who don't give them the security model they want.
You are free to install a custom OS which provides you the security model you desire. You have choices.
No, when you can't participate in modern society without specific apps, I would argue those developers, in fact, don't have the right to not offer me their services.
No one's requested the config switch from A to B with a restriction that's acceptable to those seeking B. Idealism doesn't tend to offer compromises, and so Idealism tends to lose when it doesn't make a convincing case to regulators. Here's a simple and easy to implement example compromise that could be offered today:
"Changing between A and B requires a device reset."
Most people are going to flat out refuse to wipe their device for a phisher, especially since it'll log them out of everything and trigger all sorts of "new device on your account" warnings everywhere if it's done without their knowledge.
Sure, this is mildly annoying for the 1% that have good reason for A — but it's annoying once per device rather than losing A for good as is happening now. Sure, Google will deny service to A. They're doing that no matter what, either b/c they remove A or b/c they deny A, but this forces them to construct and defend a case for why users who went through the hassle of wiping their device to switch to A ought to be denied access to the app store, and that's a critically absent case in regulatory circles right now. (See also Graphene vs. the EU age check app.)
That's all it would take to protect B from A, but no one asks for it, and no one presses Google publicly for it, and so of course Google isn't doing it. No megacorp will help you walk off the Golden Path without some sort of extrinsic pressure. I see a great deal of clamor around wanting A, but absolutely none of the 'here's a mild annoyance that we came up with as a valid and safe compromise' clamor that would make them look incompetent in the public eye, provide further leverage for EU antitrust steps regarding Android itself, and give them a way to continue to protect users who need B for safety, while allowing those of us who want A to pursue it.
Perhaps other styles of compromise exist, too? As far as I can determine, no one else is thinking about this in terms of "what compromises will developers offer that continue to protect non-developers?", and so I have no other examples to offer. I'd sure love to see more ideas, more effort invested into offering serious and real compromises rather than inflexible resistance of every real safety improvement.
>a config switch between A and B is never considered
And why should modern corpo maintain additional complexity to pander to 1% of privacy-aware tech-savvy users?