Hacker News new | ask | show | jobs
by fouric 2106 days ago
This is a really easy problem to solve - add a scary sign and/or void the warranty when a user decides they want to use an alternative app store. Then they at least have the option - and if they take it and suffer, they're the only one to blame. There's absolutely no collateral damage among users, and this feature would not meaningfully weaken security (if implemented properly) - "the user could do something dumb that only affects them" is not reduced security.
1 comments

"This user just gave a third party their entire contact list" certainly does harm other people.

"This user just had their entire camera roll exfiltrated" certainly does harm other people.

These are social devices. Their users are, by and large, non-technical and incurious. Expecting them to not just click past the "scary sign", and so condition to do it again and again, so they can play Fortnite is a level of lack of understanding that borders on incredible.

...neither of those attacks you gave are unique to smartphones. Someone can leak personal information through any number of other channels - for instance, entering someone else's personal information into a website that send out emails for a group party invitation.

> Expecting them to not just click past the "scary sign", and so condition to do it again and again, so they can play Fortnite is a level of lack of understanding that borders on incredible.

That's not an excuse. This is bad behavior. It doesn't matter if it's common, or expected - it's wrong, and their responsibility for correcting - not Apple's, and especially not at the freedom of other users who have nothing to do with these idiots. If this behavior is normal, then we need to make it not normal, not continue to compensate for their ineptitude. Fix problems, don't avoid them.

They did fix the actual problem here: the complete intractability, to the point where your dismissal reads as at best impossible optimism, of expecting users to secure their devices when given the opportunity to get a sick screensaver or a game.

I appreciate the fix. And I don’t want to be hectored by bad actors to fuck up my phone for their profit margin.

Buy Android if you do. That “freedom” is right there for you. I used to buy Android when I thought I cared about sideloading; I don’t, so I don’t. Do likewise!

> If this behavior is normal, then we need to make it not normal, not continue to compensate for their ineptitude. Fix problems, don't avoid them.

This sounds great in theory, but two decades of history of malware on Windows have already taught us it is hopelessly impractical.