3 ms·
That’s a good point, but the behaviour I’m talking about is enforcing the optionality of those functions in order for the app to work. I might be wrong about t
by milderworkacc 5y ago
That’s a good point, but the behaviour I’m talking about is enforcing the optionality of those functions in order for the app to work.
I might be wrong about this (not a dev, just play one on the internet) but Apple has the power to say that in order to submit an app to the App Store, user location/contacts/photos/whatever must not be required to be turned on for the app to work. ie. Apple enforces your ability to use WhatsApp without giving up microphone access.
Without that model, yes, permissions are still granular. But WhatsApp can tell you to turn all of them on, or you can’t use the app. To me, that’s not a meaningful difference to the “just don’t install it” crowd’s preferred suggestion.
- DenisM 5y agoWorst case Apple can feed those apps a random location, supplemented with a random film roll and address book.
- g_p 5y agoThis approach sounds a lot like that used by XPrivacy, and its successor, XPrivacy Lua, both for rooted Android with the Xposed framework. They allowed you to spoof responses to a huge range of API calls that revealed sensitive data, by hooking function calls in the underlying OS, and returning arbitrary or random values, which could be a subset of the full valid set of values. That approach works pretty well if you test it robustly and ensure your dummy responses are valid according to the API spec. Something I always feared was that apps would try to detect this and refuse to run if you didn't have any contacts or photos, or had folders on your SD card that they could not access, but I'm not aware of this ever really having materialised, beyond banking apps and some online games using Google's device attestation, which didn't really play nice with the Xposed framework.