3 ms·
Virtually every non-trivial Android application has these permissions, none of which are even important enough for the system to prompt you for permission. The
by dstaley 5y ago
Virtually every non-trivial Android application has these permissions, none of which are even important enough for the system to prompt you for permission. The only interesting one is "pair with Bluetooth devices" which is how the Exposure Notifications system works.
- studentrob 5y agoUsers expect to see the requested permissions.
- kuschku 5y agoAll these permissions are granted without ever being shown to the user, due to being in the "other" category. If you install this app normally, Android will never ask you for permission, but just silently grant these permissions.
- studentrob 5y ago> The permission modal says this [0]. [0] https://news.ycombinator.com/item?id=27558825 https://news.ycombinator.com/item?id=27558825
- kuschku 5y agoOn Android 6.0 (2017) and later, there is no permission modal if all permissions are in the "other" category, as they are in this case. Android 6.0 introduced requestable permissions, were critical permissions had to be requested (and could be denied) at runtime. At the same time it removed all modals for non-critical permissions.
- fwn 5y ago"full network access" is a hugely important permission. My cynical side believes that the reason for it not being as visible as other permissions is that platforms profit from the ad-driven app model, which itself heavily relies on an apps ability to access the internet. That could also be why stock roms do not allow users to disable full network access on a per app basis. (...like, for example, the camera permission.)
- londons_explore 5y agoIt's actually not disableable because there are so many ways to bypass it. For example, just trick a user into clicking a hyperlink to another app like a browser which does have full internet access, and you have successfully exfiltrated any data in the URL.
- labawi 5y agoSeems like a weak excuse. I mean sure, you could do that, but it would be complicated, conspicuous, tiring for the user and you would still only get one-sided occasional transfer. It could exfiltrate data, albeit suspiciously, but it wouldn't work for ads .. which are the likely motivating factor. Other motivating factor may be tracking, which google and vendors want to do, but I'm not sure what the stance would be on others tracking their users.
- schmorptron 5y agoYeah, this also seems like the most logical reason to me. If your business depends on people seeing ads in apps, why give them the possibility to circumvent them?