3 ms·
The OS should still allow users to install and run applications without going through an all-or-nothing permission approval process. The API should just provid
by redahs 11y ago
The OS should still allow users to install and run applications without going through an all-or-nothing permission approval process.
The API should just provide the application with blank data for each data source for which permission has not been explicitly granted.
Ex: address book with 0 people for contacts, silence for microphone, black screen for camera, north pole for GPS location, etc.
That way users can opt out of specific functionality of an application which does not provide them with any value while still opting into and utilizing the functionality of an application which does provide them with value.
- moftz 11y agoI do like your idea of feeding null data to the app however I think blacklisting permissions would be better than having to whitelist everything. When I install an app on my phone (versus from my computer), I typically need the app now. Having to go through and whitelist everything would be a pain. Have an option in the OS settings for default, global blacklists that are always applied unless you specifically whitelist for that app. Your global blacklist might look like: No Microphone No Location You install something like Snapchat. This requires camera, mic, contacts, and location. You start Snapchat but the OS pauses to tell you that null data will be fed to the app since it requires things that are blacklisted. You can either dismiss the notification or have the option to open up the local permission checklist. This would allow you to check off the things you may want to add like access to the mic or deny permissions you don't have globally blocked like contacts. You go through and give it access to the mic but block access to contacts. Now Snapchat has implicit access to the camera (since there is no rule about it), explicit access to the mic (as per local rules), explicit block to contacts (as per local rules), and explicit block to location (as per global rules). Now you can record videos with sound but not let it know where you are or who you know while still keeping a global blacklist that everyone must follow. One important thing, under no circumstance would apps be allowed to know the the OS is blocking access to certain things. This would open up the ability for an app to complain that it needs something and just refuse to run.