4 ms·
I don't understand technology behind app approval, code review, etc. But, would this happen in the iOS app store? Given their more stringent approval process?
by poundy 16y ago
I don't understand technology behind app approval, code review, etc. But, would this happen in the iOS app store? Given their more stringent approval process?
- ergo98 16y agoAn application in the Apple app store purported to be a flashlight app but was actually a tethering application: There was no secret binary obfuscation or amazing hacking, it just simply said "I am A" while actually being B. That should give insight into the depth of analysis that occurs with Apple's curation: they are concerned about functionality overlap and other high level things, and there are zero guarantees that the application does what it says it does. On Android there are very granular permissions, and an application cannot do anything -- like getting your coarse or fine position -- that it wasn't specifically granted rights to, however like the article mentions it's hardly difficult to social engineer an explanation for why the right should exist. And of course, sometimes benign apps do need far reaching rights in a way that causes user security fatigue. Barcode Scanner, for instance, scans barcodes and looks up products, yet on install it demands -- all or nothing -- that it have access to your contacts. That concerned me greatly, but I later learned that it can also generate barcodes for your contacts. Android security can be improved. For instance apps should have optional right requests. I would say no to contacts on Barcode Scanner, for instance, and it should live without that right, just as I would say "no" to a game where I don't use geolocation matching for if it wants positional data. There should also be the option for an "on use" right setting, where, for instance, whenever it asks for my fine position I have to individually grant that right, which is the one thing that iOS does right. This is ultimately simply an installer issue -- the reality is that apps already can probe to see if a given right is available, and can enable/disable functionality based upon it. All that is needed is for the installer to provide the boolean. Overall, though, I feel far more secure with the granular permissions model of Android than with the all-or-nothing (aside from fine position) iOS model.
- StavrosK 16y agoI don't have an Android device, but what you describe is half-way to a fantastic OS. If each application could specify some text for a permission, the installer could then display it to the user ("This application wants to access your contacts for the following reason: Generating barcodes for contacts") and the user could check/uncheck what he wanted. Obviously, almost everyone would just press "accept" all the time, but users could become more and more educated about security (it's not that hard to grasp that an app needs access to contacts), and that security model would possibly be the best of both worlds.
- jsz0 16y agoI'm sure it could get past the App Store approval but launching the app is going to prompt the user to allow location information to be sent. Depending on the application this would raise some red flags for the user. Most importantly there's no downside to not allowing location so the user isn't punished for saying no in the same way that an Android app simply won't install if you don't accept the laundry list of permissions it requests.