Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's probably where we're headed. Hypervisors running single-application kernels talking via message passing over some networking protocol to display servers and other virtualized hardware.


Am I the only one who thinks this reality sucks? Everything locked down, no way to tweak or repurpose any of your software. I know, there are bad actors out there, etc. but shouldn't there be a limit for destroying utility of things in the name of security?


It definitely sucks to some degree, but it is the same kind of change when going from a small town or a rural area into a big city.

The houses where I lived in Canada weren't locked, they didn't even have locks. In Amsterdam it would take about 6 seconds from the time you left to have your house burgled if you did that.

As far as it reduces your ability to tweak or repurpose your software: I don't think that it has to be that way but it will definitely be harder than in an environment of trust.

Maybe there is an easy way to get both ease of fiddling and very high security but I haven't seen anything like that yet. There are some interesting research projects revolving around 'capability based operating systems' and such, maybe that's where they key lies, or in some other development currently underway.


Why would proper sand boxing limit tweaking or repurposing of software? (I must admit I'm not sure exactly what you mean by that). It just limits apps interactions with each other and the OS environment.


You answered your own question:

> It just limits apps interactions with each other and the OS environment.

That makes a whole slew of modifications and tricks harder and/or impossible without having access to the sourcecode of the software, which is (on windows at least) not rare at all.

Any kind of interaction not explicitly allowed is then forbidden and the sandboxing will be a lot harder to overcome than two apps on the same machine talking to each other using a third.

Maybe some kind of unified app-to-app messaging protocol can take care of this, similar to how linux systems uses 'dbus' and the likes.


Exactly this. I still remember the times when if I needed to change something in an application, I could just write to its process memory directly. Those were fun times...

What I want is to retain the ability to repurpose the software on my terms. To move data in and out of the software whether software's authors like it or not. It's becoming harder each day, as more and more tools move to the cloud and turn into apps. I'm happy we still have userscripts in the browser but how long will it take before they get banned too?

This problem has many names. "War on General-Purpose Computation" is one of them, but I suppose the "professionalization of programming" is another. How long will it take before you'll need an engineering license to be allowed to use a compiler, or work with a Turing-complete language?


I really hope not to see that day. So, how to avoid it and not be open to security issues like these?

It used to be that you could get a lot of use out of a computer all by itself, nowadays that's changed and the trend to 'always on, always online' translates into having your machine potentially under attack 24/7.

Being vigilant against enabling the war on general purpose computation is very good, it is the biggest threat in the longer term and one of the reasons why I think that all these large silos are a very bad development.

I don't think we have much to fear from the 'professionalization of programming', not if the kind of code I see on a daily basis is anything to go by ;)

There have been numerous attempts at slapping a gateway on the ability to write software for the hardware that you already own, the only environment where this has taken hold is on mobile platforms, I sincerely hope that that is a development that we will sooner or later be able to revert.

But in order to revert it you'd have to come up with a solution for the pandemonium that would ensue if everybody and their brother would use the likes of 'download.com' or some equivalent to install their software from. Maybe something along the lines of apt-get for phones would be a starting point.


> I really hope not to see that day. So, how to avoid it and not be open to security issues like these?

I don't know. Part of the answer likely lies in determining who the "owner" actually is. I want to be the owner of my computer, but business interests go against it. For instance, MAFIAA doesn't want me to be the owner, because they want secure means to enforce DRM on me. Other businesses would also like to be the owners, because they can monetize me better this way.

> I don't think we have much to fear from the 'professionalization of programming', not if the kind of code I see on a daily basis is anything to go by ;)

Let's hope so, but I think it naturally follows from Trusted Computing - the technology will enable proffessionalization. Because right now, there isn't much you can do to prevent people from getting their hands on a compiler and using it.

> There have been numerous attempts at slapping a gateway on the ability to write software for the hardware that you already own, the only environment where this has taken hold is on mobile platforms, I sincerely hope that that is a development that we will sooner or later be able to revert.

I hope so, but I fear we won't - that at some point a company will finally figure out how to lease PCs to general population instead of selling them. You'll get a nice, cheap laptop, but it will be locked down, equipped with trusted computing hardware (the company will be the trusted actor, of course) and require to connect to the Internet every now and then to verify everything is ok. Basically, what happened to mobile, only worse. And people will buy into it if the price difference will be significant enough. Actually, I'm not sure what's stopping companies now from doing this.

> But in order to revert it you'd have to come up with a solution for the pandemonium that would ensue if everybody and their brother would use the likes of 'download.com' or some equivalent to install their software from. Maybe something along the lines of apt-get for phones would be a starting point.

Yup. Crap like this is a huge problem, but I'm not sure if it requires locking things down. You can go the Apple way and aggressively verify every piece of software you allow in your repository. This makes you the trusted authority, which carries risks like abuse of trust, but solves the problem without heavy sandboxing.

So far I see the issue of distributed vs. centralized as a tradeoff between secure but inefficient, and efficient but with serious failure modes. I wish there was a way to capture benefits of both while avoiding the risks.


> I hope so, but I fear we won't - that at some point a company will finally figure out how to lease PCs to general population instead of selling them.

They'll give them away just to get you to be part of the ecosystem!

Apple does provide some verification services but the major reason the app store in its current form exists is as a choke point to extract revenues and as a way to remove any credible competition to Apple supplied applications.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: