points by chroma_zone 1 day ago

> That makes a lot of sense in a world where we’re importing all our software from strangers. It makes less sense in the world we’re heading to, where most of the software we’re carving up fiefdoms for has the same provenance.

If I'm running software written by an LLM, even if I was the one who prompted the LLM, I would still want my OS to treat it as if written by a stranger.

I know he's not necessarily talking about relaxing security models here, but he's not being very specific about his vision otherwise.

cgio 1 day ago

I think OP may be onto something real, while you are definitely right if we translate concepts directly. But maybe the challenge, with current platforms included, is because we try to cram identities by reference. If a phone had its own identity, with which you transact as with any party then lots of the security concerns would dissolve. To tone down crankiness, I refer to identity in the technical sense, not personality etc. This doesn’t solve the challenge but it might point to a different foundation for a security model.

  • lesam 23 hours ago

    If the phone injures or defrauds you, does it have to make restitution? If so, how?

    'Transacting' requires not only identity but accountability, a completely controlled-by-you phone cannot meaningfully transact separately from you.

    • cgio 15 hours ago

      Ownership does not imply co-identity. If my phone harms someone else, without me being responsible but e.g. the brand that updated its firmware? Your questions are good, and I don’t have the answers. I just think our current model doesn’t either.

  • autoexec 22 hours ago

    > If a phone had its own identity, with which you transact as with any party then lots of the security concerns would dissolve.

    I feel like a lot of new security concerns would be created.

    • cgio 15 hours ago

      Indeed. Some would go, some would come.

fennecbutt 20 hours ago

I mean, everything should eh sandboxed imo. Even OS included software.

Problem with sandboxes is that it doesn't solve the "user who doesn't know or care" problem.

If you have to give access to particular files to an app, your average user will just give access to all. Someone installing tiktok doesn't look at the permissions...

The best thing would be for apps to operate on their own copy of a file regardless. But that doesn't stop bad apps from leaking importsnt files. Unless files can be signed as being for x thing requiring y special permissions as granted by the originator and not the user.

The crowd on here we can't to be able to truly own our devices. But I think for the safety of the average person they should be locked down by default, same as dev mode on android devices where you accept liability for doing silly things.

  • abecedarius 8 hours ago

    The right basic idea is, the UI for "do X to Y" must combine designating which Y you want and giving permission to access that Y (and no other). It's when the OS shell separates these aspects that you have to choose between extra annoying useless permission pop-ups and any security boundaries.

    (Yes reworking our all our systems in terms of capability security is a giant job. But there's a difference between a giant job and )

tptacek 1 day ago

Nope. There has never been a "good" post written in this genre ("I'm leaving my last team, here's my new project") and I'm not going to waste interesting bits on my pro-forma transition post.

I didn't submit this! Happy to chat about it, but I feel like I was pretty clear in the post that I wasn't bidding for the front page.