4 ms·
> The android app for olympics allows the developers to get all your contacts, listen to your microphone, wifi & bluetooth device connections, location, files.
by AnssiH 5y ago
> The android app for olympics allows the developers to get all your contacts, listen to your microphone, wifi & bluetooth device connections, location, files. It starts at startup, can hide and reorder itself, can REMOTELY download files and trigger all kinds of tracking and spoofing.
Most of those trigger a specific Android permission popup at runtime to grant access when actually needed/used. The app doesn't them just by the user installing it.
- wishawa 5y agoThis is correct. And it is normal practice for not-truly-native apps (apps using React Native, Ionic, etc.). By declaring every permission in the manifest, they can add new features that would require those permissions without by just updating the javascript code over the air (no play store update / google play review needed).
- Larrikin 5y agoIt's not standard anymore. Google has started requiring lengthy documents you have to fill out justifying the more sensitive permissions and will stop letting you publish if they find things you have left out. This applies to new and old apps. They've become a liability to leave in. Basically killed the entire beacon industry since some people used those to track exact location.
- wishawa 5y agoI’m using the [Expo SDK](https://expo.io https://expo.io) and it declares a whole bunch of permissions yet goes through review fine without any explanation.