Re: Permissions, certificates, and devices' questions

[email protected] Tue, 8 Jul 2008 02:12:53 PDT
Newsgroups gmane.comp.java.sun.kvm
Message-ID <[email protected]>
yarmobile,

To expand on what Shawn said:

I think the most effective is to follow multiple approaches. 

1. Many modern phones allow the user to customize security settings for a particular application. It's not very user friendly and you need to provide instructions but it is the best option in terms of functionality and cost (for you). Signing the application in this case typically adds the option of "never ask" in addition to "ask once" ... so this might be desirable depending on your situation.

2. Signing with Thawte or Verisign may not buy you a whole lot since many phones don't recognize applications signed that way as being the the "3rd party trusted domain". The UTI cert by Java Verified has much more reach as it is currently in over 300 phone models. But I agree, the Java Verified cost model is not ideal - however, you may want to check with them as I believe there are making changes to the program.

How do we get this fixed? The problem is that what is happening in this space is that some (not all) device manufacturers and operators are using security mechanism to impose business models on developers. So it's a business problem, not a technical issue. And these are harder to solve - especially in a consistent manner across the industry.

As Shawn mentions there is the idea of a non-profit Developer Alliance that could create some pressure on the industry to address some of these problems. But the devil is in the details and the Developer Alliance has not taken off just yet.

Sun is also involved in working a number of these issues behind the scenes - as announced at JavaOne and you should hear more over the coming months. But due to the nature of the problem don't expect quick and easy fixes ... ;-(

-- Terrence
[Message sent by forum member 'terrencebarr' (terrencebarr)]

http://forums.java.net/jive/thread.jspa?messageID=284980

===========================================================================
To unsubscribe, send email to [email protected] and include in the body
of the message "signoff KVM-INTEREST".  For general help, send email to
[email protected] and include in the body of the message "help".