@tptacek I think my question about your post is this — right now people rely on a lot of apps written by professionals for things like mobile banking, messaging, medical providers, mobile payments, and subscription services (music, tv, etc). The interests of the app publishers aren’t aligned with total user freedom — banking app developers don’t want a totally malleable OS where there are no process separations or trust partitions. Rather, they want to rely on OS level guarantees that their code is isolated from other apps, that the binaries are signed, that the platform is somehow trusted.
I love your idea of an OS where users write their own apps as they want. But if they want to connect to third party services or use commercial software, won’t there still have to be a lot of security guarantees? I don’t just mean the depressing “browsers must implement DRM or you can’t watch streaming video.” I mean “how will medical providers trust your device enough to give you your lab results” if you are thinking of majorly changing the mobile device security model.
It’s not a hostile question, I’m genuinely curious about this design tradeoff.
My lab medical results are mine and only mine. It’s for me to decide if my device is secure enough. I do not need my insurance company to decide for me what device I should use.
Same with my money in the bank.
Streaming is fair. Netflix can dictate their rules. I can decide not to pay for their content.
I’d love for this to be the case, but we’re going to need laws to make it happen. Banks will have to be forced into it and probably also shielded from liability in case the user does something dumb.
Maybe we can force them into providing APIs for us while we’re at it so I don’t have to pay Plaid if I want to build an app to track my finances.
> My lab medical results are mine and only mine.
While I agree in spirit: after a recent rib injury I wasn't allowed to take a picture of my own X-Ray using my phone or even have a copy sent to me since "that isn't the policy"... very hard to say that data was "mine" until it is "released" to me.
There is an infinitesimally small liability that some "other patient's" data might be visible on scanning device, a horde of companies assuring asses are covered and without a legal obligation to give me all "my" health data per visit I don't see an easy path to using our own devices soon, unfortunately.
Under the law now, at least in the US and EU, you do not have the legal authority to waive the obligations of your medical and financial service providers under regulatory law and court precedent.
If you want that power, you’ll need to get your national government to change the law.
decasia · · focus · HN ↗
I love your idea of an OS where users write their own apps as they want. But if they want to connect to third party services or use commercial software, won’t there still have to be a lot of security guarantees? I don’t just mean the depressing “browsers must implement DRM or you can’t watch streaming video.” I mean “how will medical providers trust your device enough to give you your lab results” if you are thinking of majorly changing the mobile device security model.
It’s not a hostile question, I’m genuinely curious about this design tradeoff.
para_parolu · · focus · HN ↗
Streaming is fair. Netflix can dictate their rules. I can decide not to pay for their content.
p_j_w · · focus · HN ↗
I’d love for this to be the case, but we’re going to need laws to make it happen. Banks will have to be forced into it and probably also shielded from liability in case the user does something dumb.
Maybe we can force them into providing APIs for us while we’re at it so I don’t have to pay Plaid if I want to build an app to track my finances.
enos_feedler · · focus · HN ↗
p_j_w · · focus · HN ↗
jamesmiller5 · · focus · HN ↗
While I agree in spirit: after a recent rib injury I wasn't allowed to take a picture of my own X-Ray using my phone or even have a copy sent to me since "that isn't the policy"... very hard to say that data was "mine" until it is "released" to me.
There is an infinitesimally small liability that some "other patient's" data might be visible on scanning device, a horde of companies assuring asses are covered and without a legal obligation to give me all "my" health data per visit I don't see an easy path to using our own devices soon, unfortunately.
yencabulator · · focus · HN ↗
snowwrestler · · focus · HN ↗
If you want that power, you’ll need to get your national government to change the law.