Bonum Certa Men Certa

Featuritis as Threat to Computer Security

posted by Roy Schestowitz on Jun 10, 2024

Featuritis

They say too much of a good thing can be bad for you. And "apropos OpenSSH," an associate said, "I suspect traces of Microsoft in that growing mess".

Like Mesa and Linux, Microsoft has in effect infiltrated (by payment) OpenSSH, which puts it at risk. They add Windows code to otherwise-simple and relatively secure bits of software to "extend" them to platforms with NSA back doors.

Here are some old articles about creeping featurism, featuritis, or feature creep [1, 2, 3].

Featuritis, also known as feature creep or creeping featurism, refers to the phenomenon in technology wherein a product does many things poorly rather than doing one thing well. At the very least, features will be “hidden” from the user among other features. In UX terms, this might manifest as poor information architecture, but it could lead to an unusable product.

When I think about avoiding featuritis I’m thinking about minimalism. What’s my MVP? How does “less is more” apply to my design? Of course, there are a certain number of affordances and features that belong to this product, but it’s my job to make sure users are not overwhelmed by a product that is poorly thought out.

1. Describes a systematic tendency to load more chrome and features onto systems at the expense of whatever elegance they may have possessed when originally designed. See also feeping creaturism. “You know, the main problem with BSD Unix has always been creeping featurism.”

2. More generally, the tendency for anything complicated to become even more complicated because people keep saying “Gee, it would be even better if it had this feature too”. (See feature.) The result is usually a patchwork because it grew one ad-hoc step at a time, rather than being planned. Planning is a lot of work, but it's easy to add just one extra little feature to help someone ... and then another ... and another.... When creeping featurism gets out of hand, it's like a cancer. The GNU hello program, intended to illustrate GNU command-line switch and coding conventions, is also a wonderful parody of creeping featurism; the distribution changelog is particularly funny. Usually this term is used to describe computer programs, but it could also be said of the federal government, the IRS 1040 form, and new cars. A similar phenomenon sometimes afflicts conscious redesigns; see second-system effect. See also creeping elegance.

“Creeping featurism is the tendency to add to the number of features of a product, often extending the number beyond all reason. There is no way that a product can remain usable and understandable by the time it has all of those special-purpose features that have been added in over time.”

― Donald A. Norman, The Design of Everyday Things

K.I.S.S. (Keep It Simple, Stupid) is essential for real security and outsourcing is the very opposite of security because it is compromising oneself based on trust in some unverifiable, inauditable entity, i.e. the antithesis of self-determination. It is imperative that we collectively reject the doctrine of fake security, wherein people controlling their computers is "sideloading". This morning we mentioned this in relation tom CAs.

Other Recent Techrights' Posts

IBM + NDA = Laid Off Workers Saying "Thank You" for the Layoffs
The important thing is, for now, more people become aware of it
Monsieur Claude Sahl, Part of the Administrative Council of the EPO (Which Fails to Administer the EPO), Has Been There For Over 30 Years
They have basically built themselves a very expensive palace in Bavaria (Germany), in which to grant European monopolies to billionaires and companies that aren't even European
Open Letter to the Administrative Council of the EPO Calls For Action as Salaries Decrease (Just Like Patent Validity)
Based on what I heard and spoke about with journalists, they accept there is a substance abuse problem at the EPO's management
Links 08/12/2025: "Leaving Intel" (Exodus Continues) and Ways "to Civilize Digital Life"
Links for the day
Gemini Links 08/12/2025: Earbuds and Offline 'Smartphones'
Links for the day
Books About Bubbles
calling things "AI" and "AIs" can mislead the reader
Links 08/12/2025: Slop Failing and Windows Users Won't 'Upgrade' Due to Slop
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, December 07, 2025
IRC logs for Sunday, December 07, 2025
IBM's Mass Layoffs Will Continue Until Morale Improves
From recent hours
Links 07/12/2025: Political Catchup, Conflicts, Environmentalism
Links for the day
Gemini Links 07/12/2025: "Lazy Saturday" and Kubernetes With FreeBSD
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, December 06, 2025
IRC logs for Saturday, December 06, 2025
Links 06/12/2025: Science, Hardware, and Slop Fatigue
Links for the day
Contact Your National Representatives (Delegates) at the EPO, Here Are All the E-mail Addresses
We'll say more about this next week
Hopefully Slopwatch is Dying
Some of the offending sites we used to keep abreast of descended into a lull
Links 06/12/2025: Panic in the Slop (Chatbots) Industry and Perplexity Sued by New York Times for Plagiarising Articles Under Guise of "AI"
Links for the day
European Patent Office Issues: Points to Raise or Factoids to Share With Delegates of the EPO's Administrative Council
use their native language/tongue
European Readers, Get Ready to Contact Your National Representatives (Delegates) in the EPO's Administrative Council
Perfect timing might be Sunday or Monday
Why We'll Continue Our IBM/Red Hat Focus in 2026
There will be many more departures not only later this month but also next month
Links 06/12/2025: Slop's "Jeopardy Phenomenon" and RAM Shortage
Links for the day
Gemini Links 06/12/2025: Memories, "Sweetness and Burn", and Hope
Links for the day
Every Site That Uses Clownflare Had Worse Downtime/Uptime Record Than Ours
And the same goes for Azure and AWS
Software Freedom Conservancy (SFC) Does Not Work for Freedom, It Works to Secure the Massive Salary of Its President And Executive Director
We must be very effective then
Why (and When) I Become an 'Activist' Against Corruption and Abuse
The dictatorship bans criticism of the dictatorship. That's when there's a deadlock.
EPO Call for Action: Get Ready to Contact Your National Delegates, We Need to Remind Them That They Represent People
Today or tomorrow we'll publish contact details for national representatives in nearly 50 European nations
Links 05/12/2025: More Restrictions on Social Control Media and Slop, "Hype Can Turn to Backlash"
Links for the day
Like With Red Hat and Other IBM Acquisitions, the RAs (Layoffs) Seem to Already Extend to HashiCorp
Of course it is possible that HashiCorp staff just got PIP'ed or saw the writings on the wall and left [...] IBM is just a dying giant
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, December 05, 2025
IRC logs for Friday, December 05, 2025