@tptacek I think my question about your post is this — right now people rely on a lot of apps written by professionals for things like mobile banking, messaging, medical providers, mobile payments, and subscription services (music, tv, etc). The interests of the app publishers aren’t aligned with total user freedom — banking app developers don’t want a totally malleable OS where there are no process separations or trust partitions. Rather, they want to rely on OS level guarantees that their code is isolated from other apps, that the binaries are signed, that the platform is somehow trusted.
I love your idea of an OS where users write their own apps as they want. But if they want to connect to third party services or use commercial software, won’t there still have to be a lot of security guarantees? I don’t just mean the depressing “browsers must implement DRM or you can’t watch streaming video.” I mean “how will medical providers trust your device enough to give you your lab results” if you are thinking of majorly changing the mobile device security model.
It’s not a hostile question, I’m genuinely curious about this design tradeoff.
Banks and schools and businesses should get in the business of simply vending APIs (or MCP connections). Agents and bots are taking away the need for the endless knobs and dials of traditional software. Just expose my data securely and my agent will do what I want with it, when I need it.
"Should get", so yea, not going to happen. The most obvious should get is exactly where we are now. What you're saying is "They should be forced to" which is just what we call laws and regulations regarding digital availability. Of course this is difficult to do since they will fight back monetarily against what they would consider perverse motivation to what we are already considering perverse motivations from them.
decasia · · focus · HN ↗
I love your idea of an OS where users write their own apps as they want. But if they want to connect to third party services or use commercial software, won’t there still have to be a lot of security guarantees? I don’t just mean the depressing “browsers must implement DRM or you can’t watch streaming video.” I mean “how will medical providers trust your device enough to give you your lab results” if you are thinking of majorly changing the mobile device security model.
It’s not a hostile question, I’m genuinely curious about this design tradeoff.
archeantus · · focus · HN ↗
pixl97 · · focus · HN ↗