7 ms·
i wish i could refuse to give android apps certain permissions yet still install them. i don't want angry birds to ever be able to charge me money and certainly
by dododo 16y ago
i wish i could refuse to give android apps certain permissions yet still install them. i don't want angry birds to ever be able to charge me money and certainly not read all my SMS messages. i simply won't upgrade.
for other apps, i just have to not install them; it doesn't seem like i can give feedback to app developers about this.
- drivebyacct2 16y agoUnfortunately this change would require changes to the platform that would break all current applications. I find it funny, Android informs you as to what applications can access and people are more leary, even when the developer is up front about it. On other platforms, the user never has a chance to even be skeptical at all.
- marcc 16y agoIn defense of other platforms, apps can't read your text messages, email, etc. Sure, there are ways to do it using private APIs, etc, but if you get caught, you get removed. Android is wide open, and knowing that it's trivial for someone to write an app which reads my email/SMS is scary. That said, the iOS SDK certainly lets a developer read my address book without informing me. You'd think Apple would put something up, like a permissions screen or at least something to let me know this is happening.
- tomjen3 16y agoNot really. Android is sometimes used on tablets that can't send SMSs, or you could be out of range or even in airplane mode. Just return the same error code you would if there was a physical problem and continue.
- drivebyacct2 16y agoUm no... the application would not just receive the same error code unless Google specifically set it up just for that permission, and that strategy wouldn't work for any other permissions. Think about it, the manifest specifies that the application will have access to whatever it asks for... the application would just crash when the VM/kernel denies it access to other applications data or some system permission because the user is given the ability to override it. Not having an active connection to receive an SMS is a completely unrelated and irrelevant point. I find it really super awesome that this is downvoted. Yes, an application that expects a permission to be available, randomly not being able to access is sure to not cause problems. Not just -1 too, we really have to ram this post into the ground, no reply, just watched my karma drop like 10 points. I expected better. Keep it coming guys, teach me my lesson without actually replying!
- SoftwareMaven 16y agoI think there is a middle ground. Certainly, there are going to be some permissions an app can't function without (e.g. you can't have a phone dialer work that doesn't have access to the phone). On the other hand, there are permissions that are purely optional to an application (such as the afore-mentioned SMS). It would be better to specify "required permissions" and "enhanced feature permissions". I require the phone permission to run. I can use the SMS feature to make your experience better.
- drivebyacct2 16y agoI'm not saying it is a bad idea. I really like it in fact. I really don't think it will work as smoothly as (apparently everyone) seems to think. Android wasn't built to have this feature... and I'm not sure that even this middle ground could be done in a way that doesn't break many existing applications.
- wzdd 16y agoI don't think it would work either. Take an app that needs, say, wake locks, Internet access, and SMS access. Say further than none of them is strictly required. Now imagine that users can deny this access on a per-permission basis. Now instead of having one app to test, you have 2 ^ 3. It's not as easy as using existing error codes, because some of these things normally don't break -- in which case it would be excusable to have fairly basic error handling. Displaying a message and allowing the user to restart the app is a fair distance (in terms of app complexity) from being required to produce an app that not only keeps running but does "the right thing" for all possible degradations of required permissions. EDIT: I don't meant to sound pessimistic. I do really like the idea, but it seems like it would make the dev / test cycle a lot longer.
- SoftwareMaven 16y agoI agree it would take longer. I disagree that it would be 2^3 times longer (I don't actually believe you meant that, but it could be inferred from your comment). The app would have to be written such that "is feature X available", not "is permission X available." Then, if I don't actually have all of the permissions I need for feature X, the whole feature isn't available, rather than trying to code for each permission. It is really no different than having a web app continue to work as JavaScript capabilities degrade from "Chrome" to "IE 6" to "NoScript".
- saurik 16y agoExactly! People install software onto other systems every single day onto systems that do not have capability-based security (including iOS, for the record, which gives application a lot of implicit access to data like your address book), and they never think twice about trusting it, but as soon as you mention what is available to the app, even with an explicit and well reasoned statement about why you are getting access to something you aren't using, people (like this poster) get /angry/, not just confused but /angry/, and start taking positions like "I will not install your software at all"... it's pure madness.