logoalt Hacker News

surajrmalyesterday at 1:09 PM3 repliesview on HN

Security at its core comes down to trusting the supply chain that provides the software that runs on your hardware. There are many alternative secure supply chain models, but ultimately users often are incapable of making great choices on what is trustworthy. It does generally make sense that the OS vendor needs to play a key part in helping ensure trusted parties are involved in the supply chain.

Comparing phones to PCs isn't a great comparison because PCs don't have a great track record and the amount of personal data and ease of installing lots of apps is quite different. Of course the current arrangement is far from perfect, but acknowledging the problems it's trying to solve is an important step towards trying to find a solution that is better.


Replies

LanceHyesterday at 1:13 PM

I'm not sure how much manual review in these stores is for security rather than content and enforcement of business rules.

I imagine nearly all the security review is automated scans, and not the source of the delays.

chiiyesterday at 1:26 PM

> It does generally make sense that the OS vendor needs to play a key part in helping ensure trusted parties are involved in the supply chain.

this position of privilege is what the OS vendor (google in this case) wants, because it spells profit.

I dont trust it.

The only trust i have is community trust. Piracy works on this trust, and it has worked for very long.

malwraryesterday at 1:31 PM

Hard to find better solutions when we have no agency to enact them. The “arrangement” was one-sided from the start.