4 ms·
So that I don't make unfounded claims I had to do a bit of research on the Android app permission model. Source: https://developers.google.com/android/guides/pe
by sha666sum 10y ago
So that I don't make unfounded claims I had to do a bit of research on the Android app permission model. Source: https://developers.google.com/android/guides/permissions https://developers.google.com/android/guides/permissions
> Google Play services automatically obtains all permissions it needs to support its APIs--your app won't normally need to request permissions to use them. However, your app should still check and request runtime permissions as necessary and appropriately handle errors in cases where a user has denied Google Play services a permission required for an API your app uses.
I'd say this constitutes a loophole in the Android app permission model and Google as well as other app developers have a mutual interest in using it so that their apps get as many permissions as possible. It has practical benefits too, though: querying Google Play services for your location info, rather than independently looking it up, saves battery life. Google certainly has financial interest in it - their position in the middle gives them analytics data and keeps developers dependent on Google API's. I don't think there are many F-Droid apps that are dependent on Google Play services.
It's likely also easier for the developer to use Google's API rather than provide their own implementation, which is of course what Google wants. It just comes at the expense of the user.
I suppose the solution is to tighten the app security model, at least on an opt-in level, as I can't imagine the average user being interested in being queried for even more permissions. I think apps should require permission to interact with other apps (such as Google Play services), and most of all they should require permission to access the internet. I can't imagine Google championing this cause, though.
- vmateixeira 10y agoThanks for your elaborated response :) I had understood how it could be placed according to their business model but wasn't considering benefits for their phone's OS ecosystem (battery saving) which is also clearly important. I don't like this coming at users expence though. People don't actually know what they're sharing and there seems to be no concern and will about informing them in a practical and functional way. We already know that EULAs, Disclaimers, etc are broken as they miss their main target: informing clearly the common individual. It's a shame companies are continuing to explore this more and more. I can also foresee this app security model ending up a big mess if we consider mantaining old android versions app permissions model compatibilities plus all of what it is becoming.