3 ms·
The sandbox has been good in that it hasn't let the Windows model of apps running rampant with admin privileges do whatever they want with your data. It's mostl
by problems 10y ago
The sandbox has been good in that it hasn't let the Windows model of apps running rampant with admin privileges do whatever they want with your data. It's mostly prevented cross-app data access.
But that's not where it stops. You see, there's still plenty of great data they can grab when you blindly click accept on that permissions dialog. Contacts are grabbed by many applications, unique device identifiers, loading your app with ads, even grabbing GPS location are pretty much standard practice now.
These practices which used to be labeled spyware or adware and hunted down and removed are now the norm.
These apps grab this data and then throw it out onto the open internet, often over unencrypted connections to parties who you don't know or trust, who are often unrelated to the app developer almost entirely, most often just so some advertiser knows you play a certain game or live in a certain city.
It depends on your definition of security - if it's strictly clicking on an ad and getting malware - it's great - but if it includes things like leaking contacts, locations and identifying information - it's terrible. XPrivacy is the only solution I've seen to really hit back at it.
Rooting your device does NOT immediately lose all sandbox benefits. It only selectively bypasses it. If you don't approve EvilMalware to bypass the sandbox - it still can't break out.
As for Android Pay? Go ahead and use it. Rooted or not, to my understanding, you're not liable for fraud on it, your credit card company will still reverse transactions no problem.