4 ms·
Isn't this post just asking for something that has already been implemented in iOS and in later versions of Android?
by SlashmanX 11y ago
Isn't this post just asking for something that has already been implemented in iOS and in later versions of Android?
- xeromal 11y agoIn android, I get granular permissions requests. Some apps manage to function when I deny access which is pretty impressive. It's definitely heading that way on Android.
- mikeash 11y agoYes, and that's now pointed out in an update at the bottom. The overall idea is still important, though. Even if the OS supports granular permissions, that doesn't mean the app does. I've seen apps ask for irrelevant permissions and then refuse to proceed if you deny them.
- kaoD 11y agoJust a random thought: would feeding dummy data solve the issue? E.g. an app requests contacts, OS returns seemingly-innocent randomly generated contact information. Or app requests to send an SMS, the OS informs the app the SMS was sent, but it wasn't. Is there any permission where dummy data would still be easily detected or produce inconvenient (for the user, not the developer) results?
- pmalynin 11y agoInternet access over SSL with key pinning, any attempt to feed dummy data can be easily detected.
- chipperyman573 11y agoThere's XPrivacy if your android is rooted, you can chose to deny, allow or fake. http://forum.xda-developers.com/xposed/modules/xprivacy-t2320783 http://forum.xda-developers.com/xposed/modules/xprivacy-t232...
- mikeash 11y agoIt would be better for the user if the app cooperated. For example, if you disable microphone access, it's better if the app says you can't make voice calls, rather than attempting them and failing strangely. You could also end up in an arms race if fake data became widespread. Bad apps will try to detect the fake data and insist that you actually enable the relevant permission. It might not be easily detected but I'm sure it would be detectible somehow. Much better would be to shut down apps that act badly when refused inessential permissions. Of course, that's kind of hard, so faking it probably has a useful role to play.
- JoshTriplett 11y agoNo need to return randomly-generated contacts; just hand the app an empty contact database. Likewise, tell the app that you just don't have a location fix. For requesting to send an SMS, tell the app that there was a failure to send the SMS (for reasons unrelated to permissions). Act as though you have no signal.
- wlesieutre 11y agoI wouldn't be surprised to see apps choke up and crash with an empty contacts database. It goes to inspect your contacts, tries to read the first one alphabetically, and fails to handle "There is no first contact." It shouldn't happen, but you could say the same about any untested edge-case bug.
- cmdrfred 11y agoI concur, maybe give the user an option?
- profmonocle 11y ago> I've seen apps ask for irrelevant permissions and then refuse to proceed if you deny them. On iOS I believe this is grounds for App Store rejection unless the permission is critical for basic functionality. (e.g. a GPS app can refuse to continue if the user denies the location permission, but if it wants access to your contacts it has to gracefully handle you saying no.)
- CaptSpify 11y agoWhich is funny, because quite a few Google apps crash if you don't give them the right perms. At least, IME Edit: Oh, you said IOS. Nevermind. I'm an idiot
- anonymoushn 11y agoIt looks like they're implemented in Android if the developer opts in. So scummy developers can still require your contacts before letting you play a match-3 game, but the Spotifies of the world can let users deny access to photos. Ideally I would be able to give an empty contact list to the match-3 game, tell it I'm located in Antarctica, and so on, but it looks like the options for the match-3 game will still be all or nothing.
- soylentcola 11y agoAlso, while some applications are more important than match-3 games and may not offer alternatives, there's always the option to simply not install the app if it follows bad practices regarding permissions. If I'm looking at a time-wasting game with plenty of alternatives out there, I just cancel the download/install if it asks for some low level permission without a reasonable explanation of why it wants it. And if it's a "good" or otherwise valuable app, chances are the developer will explain why the permission is being requested. There aren't really any must-have mobile applications I'm aware of that request permissions that are both irrelevant to the function of the program and break the app if I deny access.
- junto 11y agoCool. I didn't know this. How can you change the existing permissions on an app that is already installed in Android?
- Fargren 11y agoStarting on Marshmallow (Android 6.0) you can to the Apps section on Settings and change the permissions for each app. Disclaimer: I don't have an updated android device at hand, the instructions may be less than 100% accurate
- porpoisemonkey 11y agoGo to Settings > Apps then click on the application and go to Permissions. (Works on my Android 6.0.1 device)
- CaptSpify 11y agoalthough yes, it took an embarrassingly long time for them to implement this.