Sometimes attacks happen from users being instructed to enable settings in order to achieve something regardless of whether you’d expect them to have a reason to use the setting
Sure, sometimes people get social engineered into taking money from their bank account and giving it to criminals. Should banks stop allowing withdrawals?
Your argument is of course absurd, but in general, I think it is a reasonable position to take. The grandmother of someone I know was social engineered into installing a malicious app and changing developer settings on a phone, and lost quite a lot of money. The grandson is at this point absolutely in favor of completely removing the things that allowed that attack vector (I believe in this case it's "merely" the ability to install apps from unknown sources).
I disagree with him. While yes, it's awful and tragic that happened to his grandmother, I think it's incredibly dangerous to allow companies to lock down our devices like that. And I think from a practical perspective, we're never going to be able to eliminate these attack vectors fully; if the grandmother was going to go along with this scammer in this particular way, there would always be some vector that she would fall for, no matter how hard we might try to lock them down.
But I can't bring myself to say his stance is unreasonable. He's dealing with a devastated family member whose retirement is now ruined, and he has to help her pick up the pieces. Not a good position to be in.
If someone is willing to click on build version 5 times and then gets a mystery prompt about dev mode, and still goes along with the next 4 steps I think they were gonna get hacked a billion different other ways
The solution to social engineering can't be to remove useful features - you can socially engineer people to do literally anything, you can have someone walk to their bank, withdraw cash & fly to you with it with a dating scam: there are literally no boundaries once you get into that area of security. Digitally, you combat that through UX, messaging & education.
I totally agree they're easy to dismiss and start to feel cumbersome, but if "protecting users" is their actual motive (I doubt it), this would be a reasonable way to handle it while giving power users the flexibility they want, and that there's high demand for.
Log in to Facebook.com and hit developer console. Can't totally idiot proof it, but people do read enough warnings if you yell loud enough. Which puts it on them.
Half the issue is, people need to acquire the same wisdom about cybersecurity hygiene as they do looking both ways before crossing the street, but even that's too much to ask for some people. They just don't do it.
At some point, it has to become the responsibility of the potential victim, if liability is such a concern from big tech companies.
I am not in favour of limiting adb access, but this does beg the question, how many accidents would it take to cause enough overfull ERs to make the requirement of staircase railings a thing, in order to make sure there are doctors to treat other things than broken bones. uh happy Saturday.
Well in my book it is a cost vs benefit question. Handrails are not expensive in comparison to a medical procedure, nor are they particularly hindering in the daily use of the stairs. In fact, quite the opposite: anybody who uses stairs without handrails may find themselves temporarily disabled, e.g. if a circuit breaker tripped and you have to walk down the stairs in the dark.
That means, handrails cost little and have nearly no downsides. Which is why I used helmets as a metaphor. The proposed restrictions has a lot of downsides to deal with a mostly theoretical risk.
I am not arguing with this. I am pointing out that there might be a burden on the medical infrastructure a whole lot of dizzy or partially blind or drunk/high people might put on the system. If you can guarantee you won't prevent someone else from a wait or medical care then it essentially affects noone else but whoever might need to clean up or buy the house you are in if you die and noone finds you in time from the head wound or broken limbs. :).
While I certainly think we should not be taking features away from people just because there exist people who will let themselves be social-engineered through arbitrary hoops, don't go creating wild conspiracy theories to explain something that supports much simpler explanations instead.
It's easy enough to imagine that Google is trying to fix something they see as a problem, and not caring about the developer case rather than specifically seeking to destroy it.
When Apple fixed security issues that allowed for jailbreaking, they weren't doing it specifically because people use it for jailbreaking, they were doing it because it was a security issue.
We should have 100% control of our own devices. But we should have it by design, in a fashion that makes sure that we control them rather than other people.
I think there's very plausible a middle ground too: Google does want to remove these features for business reasons, and is using the real problem of social engineering as an excuse.