4 ms·
Here is the actual research paper that this news story is based on: http://appanalysis.org/tdroid10.pdf http://appanalysis.org/tdroid10.pdf Also addressing the
by meelash 16y ago
Here is the actual research paper that this news story is based on: http://appanalysis.org/tdroid10.pdf http://appanalysis.org/tdroid10.pdf
Also addressing the point by ergo98 http://news.ycombinator.com/item?id=1744151 http://news.ycombinator.com/item?id=1744151, a single anecdote does not a convincing argument make. iOS's approval process has a number of explicitly stated goals, one of which is preventing what is happening in this case. So mentioning one app that happened to sneak by the approval process for a short amount of time is meaningless for drawing any real conclusions.
In general, having all the permissions of an app determined at install time seems very flawed to me (whether or not those permissions are optional). Why not ask for permission, when necessary, during the app use, so the user knows exactly what is requiring those permissions? That model is used by desktop apps, and it is the way I would implement it. The up-front permissions model is like sites that ask for your email first before they allow you to read their content- generally scams.
- ergo98 16y ago>Also addressing the point by ergo98 The reply button is available for your convenience. >a single anecdote does not a convincing argument make It isn't an anecdote. People submit binaries to Apple, and they either do static and dynamic code analysis, or they don't. I have never heard about them rejecting an application based upon such analysis, and in this case we know that it was an incredible deviation from the stated purpose. But let's assume they do start doing such analysis -- because they have such a limited runtime security check, to circumvent it is trivial obfuscation. Of course developers needn't even bother with that. The reality is that we have no frigging clue what apps in the App Store are doing -- Android is an open enough, transparent enough ecosystem that it is an easy, obvious target for researchers. No one, to my knowledge, is doing similar analysis of the iOS market.
- meelash 16y agoIf I understand your point correctly, it can be summarized as "Applications are probably doing whatever the heck they want on iOS too, we just don't know about it." If that's not your general idea, please correct me. There are at least two problems with this statement: 1) You are contending that Apple is in an equally powerless position to prevent apps from deviating from stated purposes. Yet even the app in the anecdote you brought as an illustrative example has been removed by Apple. If any other iOS app was found to be in violation by anyone, and Apple found out about it, it could be removed immediately. In contrast, the apps tested in this research paper will likely still be in the Android marketplace one year from now, and because people don't read the news, they will likely be as popular. 2) I don't think it's really that difficult to do similar analysis on the iOS market at all. Just connect to the internet via a router with some kind of packet sniffing. Obviously, until someone actually does it, we're just guessing- you're guessing that apps on iOS are just as bad, and I'm guessing otherwise- but to blame the lack of information on iOS not being transparent enough for researchers doesn't seem accurate.
- ergo98 16y ago"If I understand your point correctly" You don't. "You are contending that Apple is in an equally powerless position" No, I'm not. "Yet even the app in the anecdote" It isn't an anecdote.