upvote
I think OP may be onto something real, while you are definitely right if we translate concepts directly. But maybe the challenge, with current platforms included, is because we try to cram identities by reference. If a phone had its own identity, with which you transact as with any party then lots of the security concerns would dissolve. To tone down crankiness, I refer to identity in the technical sense, not personality etc. This doesn’t solve the challenge but it might point to a different foundation for a security model.
reply
If the phone injures or defrauds you, does it have to make restitution? If so, how?

'Transacting' requires not only identity but accountability, a completely controlled-by-you phone cannot meaningfully transact separately from you.

reply
Ownership does not imply co-identity. If my phone harms someone else, without me being responsible but e.g. the brand that updated its firmware? Your questions are good, and I don’t have the answers. I just think our current model doesn’t either.
reply
> If a phone had its own identity, with which you transact as with any party then lots of the security concerns would dissolve.

I feel like a lot of new security concerns would be created.

reply
Indeed. Some would go, some would come.
reply
I mean, everything should eh sandboxed imo. Even OS included software.

Problem with sandboxes is that it doesn't solve the "user who doesn't know or care" problem.

If you have to give access to particular files to an app, your average user will just give access to all. Someone installing tiktok doesn't look at the permissions...

The best thing would be for apps to operate on their own copy of a file regardless. But that doesn't stop bad apps from leaking importsnt files. Unless files can be signed as being for x thing requiring y special permissions as granted by the originator and not the user.

The crowd on here we can't to be able to truly own our devices. But I think for the safety of the average person they should be locked down by default, same as dev mode on android devices where you accept liability for doing silly things.

reply
The right basic idea is, the UI for "do X to Y" must combine designating which Y you want and giving permission to access that Y (and no other). It's when the OS shell separates these aspects that you have to choose between extra annoying useless permission pop-ups and any security boundaries.

(Yes reworking our all our systems in terms of capability security is a giant job. But there's a difference between a giant job and )

reply
Nope. There has never been a "good" post written in this genre ("I'm leaving my last team, here's my new project") and I'm not going to waste interesting bits on my pro-forma transition post.

I didn't submit this! Happy to chat about it, but I feel like I was pretty clear in the post that I wasn't bidding for the front page.

reply
I think you got your comment replies mixed up? I don't see the relevance of this (https://news.ycombinator.com/item?id=49851040) to that (https://news.ycombinator.com/item?id=49850998).
reply
Sorry, I'm responding to the (apt) complaint that there aren't a lot of details in the post. They're right, and I'm just adding why.
reply
The fault is mine. I commented before reading TFA, and couldn't fathom from the title that it would be a "pro-forma transition post".
reply