logoalt Hacker News

Malleable software: Restoring user agency in a world of locked-down apps (2025)

150 points • by evakhoury • yesterday at 7:01 PM • 71 comments • view on HN

Comments

trashb • today at 10:39 AM

I agree that the current state of software is quite rigid. There is no room for imperfection and often one opinion is seen as fixed the best.

I think the essence of the GPL is trying to solve this issue, the freedoms of that license is focused on keeping software as editable as possible. The idea of malleable software is not new but most "business/industry" software is still very rigid.

One of the more interesting realized concepts of malleable software are the freewheeling apps from Kartik Agaram (https://akkartik.name/freewheeling/). Additionally in my opinion the idea of malleable software is at the core of unix everything is a file and the plan 9 system.

piterrro • today at 8:45 AM

This whole article is true and to the point but... reality is: most people still don't build their own setups: work, home - most of them follow a sh*tty software or decorate with Ikea. I think this applies only to a small group of users how will be willing to go extra mile and prompt their ideal interface for whatever they need to do.

➕ show 1 reply
lucrbvi • today at 9:35 AM

I think one of the best ways of stopping lock-in is to be file-based. Obsidian is a good example of this. Users can just keep their data as is and move on with their lives.

➕ show 1 reply
dzink • today at 12:57 PM

Intelligence and the mental load it requires has a budget - in both real and artificial forms. In real - people are bombarded with tools and requirements and when the teams behind those don’t consider mental load required, that spends down the budget. Thus people give up fighting all battles and are forced to prioritize their resources. Denial of service attack on the brain. AI models running out of context will do the same and get lazy. Sadly any bad actor private or government knows this and uses it as a tool to fight intelligent resistance to its plans.

apatheticonion • today at 5:48 AM

I believe it is critical for regulators to force mega-corporations (and software vendors in general) to permit third party clients.

I use services like YouTube every day, why can I get sued if I write my own YouTube client that's better than the one provided by Google? Why can I get sued if I create a chat client that aggregates the myriad of chat services I use?

I'd argue that this even extends down the stack. Why is there only Android and iOS? It's because hardware drivers are practically impossible to write for undocumented hardware (which is virtually all hardware). Vendors should be compelled to document their hardware such that drives could be produced for them.

Asahi Linux is a testament to a team attempting the impossible and making unbelievable progress - but it's still not competitive with first party drivers.

I want a world where I can run Linux on my MacBook Pro and my phone. I want a world where I can flash a custom firmware to my TV that removes the bloat and spyware. I want a world where I can use the services I depend on in ways that are better than what the vendor can produce. I want a world where I can rebuild applications and games lost to time.

I have the skills and desire to do these things.

But nah. Not allowed.

➕ show 4 replies
dang • yesterday at 7:01 PM

Discussed at the time:

Malleable software: Restoring user agency in a world of locked-down apps - https://news.ycombinator.com/item?id=44237881 - June 2025 (114 comments)

finn888 • today at 8:19 AM

Miss the days you could script or tweak everything. Modern apps feel like sealed black boxes with no escape hatches.

Ouman • today at 7:28 AM

This makes me miss the era when computers felt more like environments than products

jongjong • today at 6:34 AM

The other day, I spent at least 20 minutes trying to share screens with my mother on Google Meet. She uses OSX.

There was a cascade of subtle issues which blocked every possibility.

My mother was using an an Apple iPad and I was using Linux. I sent her the link to the Google Meet to her email. When she tapped it, it opened in Safari browser. Safari did not allow screen sharing via Google Meet so I told her to download Chrome and told her to copy the URL into Chrome. Safari would not let her copy the URL from the address bar... She ended up literally typing out the URL and the resource ID by hand while I read it out to her. Then when she opened Google Meet in Chrome, it required her to download a browser extension (I don't recall having to do this on Linux)... Anyway it was unbelievably tedious.

It's obvious that operating system companies have been intentionally making it difficult to 1. Know where you are when browsing your file system or the web and 2. Copy the URL or path between different apps.

This has been a major point of frustration for software developers. First, it started with OSes hiding file extensions, then converting the address bar into breadcrumbs/buttons which can't be highlighted or selected... Then hiding the protocol (e.g. http:// or https://) then hiding most of the start of the breadcrumbs which make up the address so that you can't even see the full path in a single screen and you can't even select individual words to copy even a single folder name.

And this trend spread to a lot of other apps. Sometimes in downright dangerous ways. For example, recently, I noticed that my email client was hiding most of the email address of the sender of an email I had just received. If I clicked on the email address it opened up their contact card in a modal but only showed their name! Their email address still cut off on the contact card view and also not selectable... I just wanted to see if the domain name was legit but I physically couldn't see what the domain name was. OMG. Nowadays, whenever I'm forced to use one of these crappy web applications, I just open up the Chrome developer panel and inspect the HTML directly. I don't know what's wrong with people that they put up with this stuff voluntarily.

willtemperley • today at 7:15 AM

Looks like Microsoft were listening to Ink & Switch and borrowed their multiple-values-in-a-cell idea.

Feb 2025: https://www.inkandswitch.com/ambsheets/notebook/

September 2026: https://techcommunity.microsoft.com/blog/excelblog/excel-now...

Driftbench • today at 10:14 AM

Miss the days of hacking binaries or deeply customizing apps. Modern SaaS feels like renting a sealed box.

dunlin • today at 9:51 AM

Remember when software felt like clay, not concrete? Hope this vision actually takes hold.

rsavage • today at 6:38 AM

So many companies (including mine) built software to replace spreadsheets - but of course spreadsheets are great because you can do anything you want.

When there is no 'standard' way of doing things, you end up writing feature after feature to meet all the different ways people want/need to use the software to replace their spreadsheets.

Eventually it just becomes a huge messy. If instead we allows our customers to customize the software themselves, so each customer got what they needed, but still had the core backend, data, and shared functionality shared between them maybe we could build simpler software again that also does.

Maybe they can just vibe everything themselves, but vibe coded features feel like a solid middle ground.

I know of rough.app and vendo.run trying to allow vibe coded features, but I haven't seen anything take off like lovable yet. Is there something out there that is being widely used that lets any software become malleable?

➕ show 3 replies
sim04ful • today at 6:57 AM

I've been thinking about this issue. One thing i realized early on is that the presentation layer is transcient it doesn't matter as much as data representation and storage.

Norwell_io • today at 9:02 AM

Missing the Winamp skin days. We truly had more agency modifying our tools back then, unlike today's locked ecosystems.

fen_wick • today at 10:03 AM

Yes! Tired of apps dictating my workflow. Give me Emacs-level customizability everywhere, please.

XorNot • today at 6:37 PM

What's really restoring my agency right now is Claude's APK reverse engineering skills.

I've been tearing through the apps on my phone and just adding the features I want.

My biggest problem is I'm going to need actual good home CI and some compute: having these check in on new releases and maybe once a month give me a summary of what we need and build a new copy.

peter_retief • today at 3:42 PM

I have been trying to promote open source sw for as long as I can remember but peoplel like my wife who is a social worker says it is too clunky and gets in the way, recently I have been vide coding with apps on Raspberry Pi's and just maybe that gap is slowly starting to close.

I for one am watching this space with a lot of interest.

TeMPOraL • today at 10:42 AM

I have my own take on this; I was meaning to write a blog post about it to "coin" the terms, but might as well do it here. My philosophy and attitude related to writing and using software have, in the past years, developed into distinct set of methodologies. There's "maintenance minimization engineering" aspect to creating products, but as a user/prosumer, I have a different approach:

Bypass-Driven Development: making progress by routing around obstructive abstractions instead of integrating on their preferred terms.

Motivating thought: often enough you already have all the pieces to solve your problem, and have legitimate right to use them, yet those pieces refuse to talk directly with each other because of a mix of technical and business reasons. API boundaries, OAuth walls that invite getting additional vendors (identity providers) involved for no good reason, platform purposefully preventing interoperability, enshittification, lack of "business need" to integrate - or worse, having a business need which means integration suddenly involves you being a third party to a contract between two service providers.

There's no technical limitation to prevent this, but I've noticed people started taking abstraction layers, API boundaries and "intended use" as holy writ, and assume you can't do something because "it's not how it's supposed to work".

BDD is my claim that an abstraction which obstructs a legitimate goal forfeits its right to be respected.

Subpattern of this, Bypass in Anger (BIA), when routing around becomes routing through. Evocative example: modern soldiers navigating dense urban environment by ignoring it entirely, and moving in straight lines, just blowing holes in any walls that are between them and their destination. That is my answer to when "the computer says no".

Kinda a pragmatic blend of Adversarial Interoperabiltiy/ComCom, "computational self-determination", good ol' hacker ethos, and a counterpoint to "security maximalist" doctrine that runs modern computing, with a hefty dose of defiant "you are not going to tell me what I can or cannot do with my data on my computer".

Razengan • today at 9:33 AM

Isn't AI making that possible?

If you read old computing magazines from the 1980s or watch any of the TV shows about computers from that era (a fun rabbit hole on YouTube if you're ever bored), the prevailing optimism was that everyone and their cat would have a computer in their kitchen, and just write the programs to do whatever they want.

But the fragmentation of operating systems and programming languages didn't really let that take off. HyperCard and Visual Basic came close, but they were killed off because of course.

It's only since a year ago that the original promise of computers has started to be realized.

whalabi • today at 3:35 PM

.

➕ show 1 reply
keybored • today at 9:18 AM

Modern-day idealistic software manifesto: Just AI sellouts like the rest of us.

ScanMyTerms • today at 12:46 PM

[flagged]

marowa-labs • today at 9:56 AM

[flagged]

henrydoughty • today at 5:33 PM

[dead]

vatsalupadhyay • today at 9:41 AM

[flagged]

GnosiWorks • today at 8:33 AM

[dead]

dmdiefjeidnn • today at 3:55 AM

I always find these ideas funny. Been working with computers for decades and never once have I thought software “malleable”. Maybe back when I had to actually type the program into my Speccy to get anything to work… but then again it wasn’t a “let’s make software malleable” situation, it was more of a “this is how we can distribute software right now” type of thing.

Software was never malleable. User agency is a tale you tell yourselves to try and justify your rose-tinted glasses. Could things be better in computer world? Absolutely. But you could’ve ask us the same way back then and the answer would still be “absolutely”.

➕ show 4 replies