30 ms·
Just out of curiosity, when an android app is updated, how are permissions handled? Do you receive a prompt to allow new privileges, or does it assume you appro
by maxjg 16y ago
Just out of curiosity, when an android app is updated, how are permissions handled? Do you receive a prompt to allow new privileges, or does it assume you approve of it already?
You bring up an astute point on the vague "network access" permission, but there's really not an easy answer to this. How would you fix it? Ask the developer to simply say what the access will be used for? In an malicious app, they'd obviously just lie. Short of actually displaying what data an app is sending, I don't see an easy answer.
- eli 16y agoYes, if an update requires new permissions, it must be explicitly approved again and cannot be auto-updated.
- there 16y agofroyo (finally) has an automatic update feature, so most apps update on their own. i have noticed a few that say they require manual updating, but i didn't know if it was due to a download failure or if it was for a changed set of permissions. it does show you the full permission list again before updating manually. How would you fix it? Ask the developer to simply say what the access will be used for? In an malicious app, they'd obviously just lie. Short of actually displaying what data an app is sending, I don't see an easy answer. maybe show a list of domains it's allowed to resolve/contact? i guess that wouldn't make it any easier for most users to decipher though. i think a lot of free apps require network access just to download ads; maybe there is a better way (in the android api) of handling that to segment it away from full-blown network access? maybe have a set of permissions common to each category? it's expected that a web browser app has access to do a lot of things, but if you have an app in a wallpaper category that requires those same set of permissions, it should be raising a red flag somewhere. perhaps apple's app review process wasn't so crazy after all...
- papertiger 16y agoMaybe treating any ad network component as a "sub-app" with separate permissions would make it more obvious when a request for network access is unwarranted. As to how something like that might be implemented... I have no idea. I suspect people would ignore it anyway.