16 ms·
Tell HN: Google does not list application permissions in the Play Store any more
https://postimg.cc/6y3Z9yjY https://postimg.cc/6y3Z9yjY
They had implemented that already a while ago, then reverted the behaviour, and now implemented it once again.
It seems as if it was not "enabled" for everyone yet, however.
They hid the permissions with each version better and better and apparently decided now, users don't need them at all.
- simonsarris 4y agoThat seems OK since it still asks you as it needs them when running an app, and "prunes" permissions away from apps that you do not use often. Lots of apps only need specific permissions if you use specific parts of the app. And apps are much larger (one app does more things) than they were 5-10 years ago. Eg you can use some apps as a camera, but never as a photo editor, and get use out of it by only giving some specific permissions (camera), forever.
- datalist 4y agoWhat about standard permissions? The user is never prompted for them.
- dotancohen 4y agoWhat are standard permissions in this context?
- codethief 4y agoNetwork access, for example
- mdp2021 4y agoSince when network access is standard? Access to filesystem is not, use of hardware components but for display and speaker is not, internet access is not... Maybe you are referring to the exploitation of "intents" to exchange with networking enabled applications?
- kuschku 4y agoNetwork access requires no user approval. The only place you could find it before granting it to an app was via the permissions list in the play store.
- uranium 4y agoSame with "run at startup" and some other important ones; there's no way to deny it once installed.
- kikokikokiko 4y agoThis is why having a firewall installed is essential in every android phone. Afwall+ does the job. My phones are all rooted but if I'm not mistaken it works on non rooted phones as well.
- uranium 4y agoNope, it requires root, as it should, really. Anything that can mess with networking at a low level needs root; there's no Android permission that I know of that lets you get down to iptables level.
- mdp2021 4y agoThere do exist "noroot" Android firewalls; I am not sure how they work (I think by somehow becoming interfaces - like "noroot" packet sniffers), but very probably not through `iptables`. There are products on GitHub; I am looking at NetGuard (from, I think, Marcel Bokhorst aka M66B - the project has many forks). The .md says, «The only way to build a no-root firewall on Android is to use the Android VPN service».
- mdp2021 4y agoOk, let us clarify the matter a little. An Android application requires "permissions" to do "anything past the basics"; permissions have to be declared in the "Manifest" file. There are (simplifying) two main types of permissions: "normal"¹ and "dangerous, runtime"²; the former only need to be specified by the programmer in the Manifest; the latter also need direct confirmation from the user at a requester prompt. This implies that "normal" permissions are granted by the user implicitly with the action of installing the application. Which means, that it is _quite important_ that the user sees the permissions list beforehand, before installation. -- ¹"Normal": BLUETOOTH, INTERNET, VIBRATE... ²"Dangerous": READ_CONTACTS, RECORD_AUDIO, SEND_SMS...
- retox 4y agoThis change was when I stopped downloading from the Play store. Prior to that you could easily see that the compass or flashlight app you were going to install needed network access, something that set off alarm bells given the state of malware back then.
- Gigachad 4y agoIt was a bit of a pointless permission because literally every app requested it. The android permissions system very quickly fatigued users in to accepting everything. The new model is much better. Allow the user to actually deny the important permissions but just accept that network access is what apps do now.
- rrrrrrrrrrrryan 4y agoI agree this is a better set of defaults, but there should be a toggle in the settings someplace, even deep in the developer mode settings, that gives users control over more granular permissions and allows them to choose which permissions to auto-grant and/or auto-deny.
- dotancohen 4y agoThough I agree with you, why is this level of detail demanded of mobile apps but not of desktop apps? I would love to be able to sandbox desktop apps as well.
- mdp2021 4y ago> literally every app requested it No, not every application requested network access. And surely not a small number of users checked if a calculator or a sound recorder did, and, also checking the developers' justifications for including specific permissions, decided their (dis)trust.
- Dig1t 4y agoYou are right, but that doesn't seem like a good excuse to remove that information from the Play Store completely. It would be trivial for the Android APIs to require that all permissions requested programmatically are also present in the manifest. This would continue to give user's a picture of what the app could/would request. They could just change their play store listing from "Required permissions" to "Permissions this app can request". This is similar to the "nutrition label" approach that the Apple App Store has.
- djbusby 4y agoIIRC it's already in the manifest.
- abeyer 4y agoYup, you must _both_ put the perms in your manifest, and then _also_ request them at runtime now (at least for many "sensitive" ones... not sure if there are exceptions for any others.) Google's docs are very clear that apps are meant to explain the need for perms, and the impact of denying them at runtime... I'd love to see the play store to also provide publishers a way to specify what the impact/loss of features is if you deny them at runtime. Trustworthy publishers would love this, and the non-trustworthy ones... ¯\_(ツ)_/¯
- morder 4y agoI'd prefer to avoid even downloading apps if they ask for permissions that aren't necessary. To hide that just makes me never want to use the play story anymore.
- is_true 4y agoThis clearly isn't OK. I want to choose between an app that asks for what it needs to work and an app that ask everything it can, before installing it. It's a dark pattern.
- ece 4y agoThe new data safety section lists things that look like permissions as well. Should permissions be clearly listed in the new data safety section? I think it would be more helpful that way.
- bagacrap 4y agoDon't you have more context to understand and grant the permission request at runtime? For example a banking app might want access to the camera for depositing checks, but until I'm actually depositing a check it might not be clear why it would want to use the camera.
- is_true 4y agoYou can ask later, too. But be clear upfront, I want to compare choices. Not many choices in that case in which you install the app your banks has.
- thaumasiotes 4y ago> That seems OK since it still asks you as it needs them when running an app, and "prunes" permissions away from apps that you do not use often. No no no no no, this is a total catastrophe. I can't understand how it got implemented at all. I just missed a birthday notification from my calendar app because Android "helpfully" removed the app's ability to create notifications! After all, I hadn't opened the calendar app in more than six months! Infuriatingly, I caught the original message telling me "hey, we just noticed that your calendar shouldn't be allowed to send you reminders" and I tried to restore the permission, but that doesn't seem to have worked. Whoever designed and implemented this "feature" shouldn't be trusted to put on pants.
- mdp2021 4y ago> and "prunes" permissions away from apps that you do not use often Certainly agreed: a system should never "take the initiative" and replace you in decisions. I am seeing cars that act along the lines of "Ah, you turned off the air conditioning, so I'll proactively open the windows": this clearly indicates that some manufacturers have embraced decadence and nihilism, they "have given up" and "want to watch the world burn" (unless they are simply underage savages).
- jfim 4y agoYeah that feature is complete garbage. The intent is laudable (reducing permissions for unused apps) but the implementation of getting a notification every once in a while with a ton of permissions removed is awful. Combined with the fact that Google seems to be sending more notifications for all kinds of junk nowadays makes it even easier to fail to notice that.
- lupire 4y agoAndroid documentation says that if the permission is auto removed, you'll get a permission prompt next time a notification is sent.
- nybble41 4y agoFully agreed. What's worse, even if you painstakingly go through all your apps and disable this anti-feature—since there no global setting—it just gets turned back on the next time the app is updated. Putting aside the abysmal UX, automated systems should respect clearly-expressed user preferences.
- uranium 4y agoOne of the permissions I'm really reluctant to grant is "run at startup". As far as I know, that's granted at install time, not prompted for, and there's no way to disallow it. Is there now going to be no way to know if I'm granting that or not?
- lupire 4y agoWhat's wrong with run at startup?
- flaviut 4y agoMy calculator doesn't need to run at startup. There's nothing useful it could do in that situation, the only possible reason is to download ads, track me, or just pointlessly waste battery. Ditto for a wide range of apps. Pretty much everything that isn't a messaging app.
- uranium 4y agoExactly. Tracking me, wasting my resources, etc.
- lostgame 4y agoWhy is this okay? I wouldn’t download, e.g.; a video game that would ask for my contacts or location. Why should I have to download and wait for the app to install before I know what permissions it’s asking for? Furthermore - what’s the possible purpose of removing this information when it was already there?
- lupire 4y agoHere's a reason: if you never download it, you can't give it a 1-star review.
- martin_bech 4y agoProbably because all apps are now required to target the latest api, which means most permissions are done by user prompts, and not just by downloading the app.
- deleted 4y ago[deleted]
- blip54321 4y agoI hate installing and uninstalling apps. And overly permissive apps are a good sign they're not my friend in the first place.
- skykooler 4y agoGiven that modern apps are dozens or hundreds of megabytes, on a slow connection I'd really like to avoid having to download the app just to learn it requires permissions it doesn't need.
- MBCook 4y agoThe iPhone has worked like that (to various degrees) for a long time. But Apple still added their privacy label things to tell me if an app is going to try to track my location. I don’t want to download a clipboard helper of some kind and find out it’s going to ask for my GPS coordinates. I want to know ahead of time.
- shadowgovt 4y agoI believe Google is addressing that concern via the new Data Safety block. This is a better approach for the goal, because if there's one thing they learned from years of offering the permissions list, it's that users can't convert the concept of "app permissions" into a good mental model of "What data the app can collect on me." They just aren't on average savvy enough. So the Data Safety info answers the question users actually care about without added complexity of pretending the average user is a developer who groks what permissions mean.
- izacus 4y agoPrivacy labels are something very different and Play Store has (or will soon have?) that as well.
- hbn 4y ago> They had implemented that already a while ago, then reverted the behaviour, and now implemented it once again. This is, among many other reasons, why I finally dropped Android after the better part of a decade. The constant A/B/C/D/E testing makes every single thing they put out feel like it's a constant state of beta testing. It's to the point where you don't even know what to expect when you do something as fundamental as opening the app store. You'll seemingly have some kind of server-side flag activated one day that gives you a totally new UI in an app you use every day, hiding things or removing features you rely on. Then maybe in another few days it'll be back to how it was. Not only do they not seem to value their users, they actively punish you for being one of their users, jostling you around between new UIs or even entire services that are always worse than the last.
- deleted 4y ago[deleted]
- devit 4y agoJust don't use proprietary applications (or don't expect them to serve you).
- hbn 4y agoI switched to an iPhone and I'm using proprietary applications, but ones that don't randomly change their UI on a regular basis whenever some nameless product manager decides they want to use me to gather some new engagement metrics by rearranging UIs on my phone
- shrimp_emoji 4y agoNo, they just entomb you into a comfy walled garden where it's only easy to do what Apple lets you do and where you hope some change made by some nameless product manager/CEO autocrat doesn't force you to buy more expensive hardware.
- shadowgovt 4y ago
- dvh 4y agoIn latest Gboard update, in the what's new section on play store is "no information from the developer".
- bornfreddy 4y agoLineageOS. Or Murena, if you can't be bothered to install it yourself. And then use f-droid, or if it's not available there, Aurora store. As seen on computers, OS is too important to be left to companies - if you value your freedom of choice and privacy, that is.
- DoingIsLearning 4y agoI am very much fed up and ready to get on board with you but one thing that holds me back is photo quality. Nowadays camera sensors are only half the story and most of the iphone-like photo quality is achieved in software. Have we reached a point where non-OEM apps can deliver something comparable to the market expectations from big manufacturers? I am ok with narrow combinations e.g. if you use app X on Hardware Y you have amazing photo results. Is there something along those lines that anyone can recommend?
- joecool1029 4y agoThere's a whole GCam (Google Camera) modding community that manages to get image quality that's often better than what non-pixel OEM vendors offer. These ports usually work on LineageOS (and other ROMs) This site has a large collection of models and the config files generated for each device: https://www.celsoazevedo.com/files/android/google-camera/ https://www.celsoazevedo.com/files/android/google-camera/ I think they link to some Telegram channels too where people share the kinds of photography they get with the modifications.
- DoingIsLearning 4y agoThat is exactly the type of answer I was looking for, thank you.
- fartcannon 4y agoThis brings up a slightly tangential question I have. Is other peoples photography like other peoples dreams? In that no one cares about it unless they're in it.
- 4y ago
- t0bia_s 4y agoAurora store does. Also F-Droid. I did not use play store over 3 years and I'm not miss anything.
- givemeethekeys 4y agoI hope Tim Cook succeeds in convincing our government that privacy is important.
- sofixa 4y agoIf you have to rely on people like Tim Cook ( who is anything but a regular person and could literally afford to have a hand crafted phone and OS build for himself) to convince your government of something for your benefit, something is wrong. And btw, a huge amount of Apple's "privacy" schtick is pure marketing combined with gatekeeping. Oh no, we couldn't allow users to have the choice where to install an app from, or how to pay for it, because privacy and not because we like our tax.
- givemeethekeys 4y agoI don't have time to try to convince Congress about privacy. But Tim does - in fact he recently wrote a letter in hopes that it'll add some weight to the cause. Whats wrong with relying on people who have the means to get shit done if they're clearly capable and willing?
- beninsydney 4y agoThe first issue is Apple's vision of privacy requires absolute trust in them and providing them with access to all your data so they can leverage whatever parts they decide is useful for their software. The second issue is Apple facilitated the modern form of having no privacy - apps with discrete access to all our private data, tracking us in real time, using APIs Apple designed, using an approval process Apple cheaped out on, and they have profited immensely from this state of affairs. The third issue is Apple is often at odds with consumers, there is an entire Wikipedia article about their litigation from when they fucked people who buy ebooks, tech workers they employed, parents who let their kids play iOS games, people who bought laptops with butterfly keyboards, developers they chose to compete with, they often do things contrary to our interests and rights. https://en.wikipedia.org/wiki/Apple_Inc._litigation https://en.wikipedia.org/wiki/Apple_Inc._litigation
- 4y ago
- maxerickson 4y agoI don't remember, was the information contained in the permission similar to the information provided as data safety? https://play.google.com/store/apps/datasafety?id=com.google.android.apps.maps&hl=en&gl=US https://play.google.com/store/apps/datasafety?id=com.google....
- josephcsible 4y ago"Similar" is subjective, but there were a lot of permissions that definitely aren't listed there.
- binkHN 4y agoThis is truly a sad state of affairs—I really hope this was just an oversite as a result of the new Data Safety section they have been rolled out as I frequently used this permission list to determine if I was going to install an app or not.
- dblohm7 4y agoI still miss the good old days of Android when apps didn't automatically receive the internet permission. Now get off my lawn.
- Groxx 4y agoI've been running netguard for this reason, yeah. Many have no need for internet access. As a bonus, the DNS-based adblocking works extremely well. Not perfect, but dramatically better than nothing at all.
- simpss 4y agofirefox supports ublock origin on android :)
- kikokikokiko 4y agoAfwall+ is your friend. No app should ever get internet access unless it's needed for it to work.
- lizardactivist 4y agoSomething else I noticed was removed a while ago was info on underlying kernel version etc.
- derevaunseraun 4y agoI see people in the comments trying to justify this change because the apps need to request for permissions, but WHY exactly would google want to get rid of this info? What benefit does it bring to the user, if any? If anything, it harms the user by preventing them from seeing what permissions apps will access in an easy to read format. Why did google even decide to do this in the first place? My best guess is it makes users more likely to let an application access permissions after they've gone ahead and installed it, generating more ad $$$ in the process. But is there any other reason?
- deleted 4y ago[deleted]
- daveoc64 4y agoI know one long-running complaint about Android's permission system was that when you installed an app you were shown all of the permissions that are declared in the manifest, without any way for the developer to explain why they are used or when they would be applicable. Permissions like READ_PHONE_STATE make it sound like the app wants to access every phone call you make, when all it really wants to do is pause your music when you answer a phone call. The combination of runtime permissions for most things, and the de-emphasis of permissions in the Play Store has reduced this as a pain point. It's also easier to introduce optional features - using things like contacts, location, or Bluetooth if the user wants to give permission at runtime.
- andrekandre 4y ago> Permissions like READ_PHONE_STATE make it sound like the app wants to access every phone call you make, when all it really wants to do is pause your music when you answer a phone call. true, but that can be solved with a bit more metadata from the developer (usage description) right?
- LightG 4y agoSomeone just make an open source app store which solves this. Can't be trusted to these idiots / money-hungry project managers / behemoths * delete as appropriate * Sorry, maybe there is one but I've not investigated and it's .... rant time.
- Groxx 4y agoWhile it is much less of a concern with runtime permissions that are optional.... yeah, I greatly dislike this too. In particular because not everything is a runtime permission. E.g. I like to know that [apk X] has no internet or file permissions at all - it rules out nearly all practical ways to leak your information. And google just keeps taking more and more steps to hide that information from me.
- bscphil 4y ago> E.g. I like to know that [apk X] has no internet As far as I know (please correct if this is wrong), there's no such thing as an app with no Internet permissions. All apps can access the Internet without permission, and only additional uses of the Internet (e.g. seeing your WiFi AP name) require special permission. AFAIK the "Internet" permission many apps requested was actually for this more advanced usage - just to hit a REST endpoint or something required no permission at all.
- daveoc64 4y agoThe internet permission is separate, and without it an app can't connect to the network: https://developer.android.com/reference/android/Manifest.permission#INTERNET https://developer.android.com/reference/android/Manifest.per... It's so commonly requested though, that virtually every app does have it.
- Groxx 4y ago(extremely) commonly requested, and granted implicitly for I-don't-know-how-long-but-it-is-a-long-time. But for quite a while you could still read the permissions list in the play store, and see if it used it. And adding the permission would still give you a warning on upgrade (outside the play store anyway). Both of those (I believe) are gone nowadays. It's obviously going to be requested by most, but its absence can be extremely relevant, e.g. https://play.google.com/store/apps/details?id=keepass2android.keepass2android_nonet https://play.google.com/store/apps/details?id=keepass2androi...
- mdp2021 4y ago
- anonymousiam 4y agoOne of the things I really liked about the Android custom ROMs (Cyanogen, etc.) was that they allowed you to revoke some app permissions, but still run the app. Google will never allow users to choose because it conflicts with their own business (user data collection and targeted marketing). Now they aren't even letting you know how much information the app collects until you download and install it.
- deleted 4y ago[deleted]
- bagacrap 4y agoMost Android app permissions are granted at runtime as of Android 6 which was released in 2015.
- nybble41 4y agoUnfortunately apps can refuse to run if you don't grant them the permissions they requested. A better system than simply allowing or denying the request would be to sandbox the app so that it appears to receive the permission but doesn't get access to any useful capabilities. Empty or synthetic calendar / contact list data, Internet access which is somehow never available, camera and microphone which only report darkness & silence, etc. Ideally the app would have no way to tell that it's been sandboxed.
- postalrat 4y agoAnd this is what some tech people here instead of PWAs.
- beninsydney 4y agoUgh. I really liked that "nutritional label" because the advance warning tells me upfront if the developer values my private data. I would prefer app stores be similar to health warnings on cigarette packets, because predatory data collection and billing practices are so entrenched.
- andrekandre 4y ago> I would prefer app stores be similar to health warnings on cigarette packets, because predatory data collection and billing practices are so entrenched. yes, exactly but on the other hand (and just a guess) but likely "conversion rates" were lower with the labels.... so off they go
- deleted 4y ago[deleted]
- heavyset_go 4y agoNo need to worry, apps on the Play Store are protected by Play Protect™! /s
- hugey010 4y agoCould this be because every privacy relevant permission, except internet access, now requires a manual approval dialog? Why list every permission when it's only used for specific feature X which is requested upon usage?
- andreareina 4y agoBecause a lot of these apps claim such and such permission is required and won't run until you grant the permission
- nybble41 4y agoThat sort of thing should be called out in (1-star) reviews. The Samsung Gear app is like that, for example. You need it if you want to tweak the settings for their Galaxy Buds headset (the ambient sound level, for example), but on first startup it prompts for what appear to be all the permissions needed for every kind of Samsung device, including things like smartwatches—calendar, contacts, notifications, the works. If you deny any permission the app refuses to start, even though none of that is necessary for the task at hand. My workaround was to install it and then immediately disable all Internet access (airplane mode), adjust the settings, and then purge the app from the phone before turning the network back on. Fortunately the settings are persistent even without a constant connection to the app. I think that should be sufficient to avoid any unwanted data leakage, but it's a lot of work for relatively minor benefit, and the process must be repeated any time the settings need to be adjusted.
- no-reply 4y agoHonest question, how many of us read permissions after scrolling through the description and then download ? It might make sense if you have metered bandwidth, not otherwise. I first try to find an ad-free app, install it and then see if it asks unnecessary permissions and go from there.
- CSMastermind 4y agoI always read the permissions and have decided not to install applications several times because of it. I'm very likely an outlier but I'm still curious about the reasoning behind this change.
- nsv 4y agoI always look at the permissions for apps I use.
- khyryk 4y agoIf I open up a basic text note app and I see basically every single permission listed, I get an idea of the mentality involved in the creation of the app. I specifically prioritize apps that ask for fewer permissions.
- jeffdubin 4y agoYes. I check permissions on every app before I install it. Or, at least I did until that was recently taken away. There are some permissions given to apps without a user prompt, e.g. start at boot. If there are five similar apps with similar functionality and ratings, I'll typically choose the one asking for the least permissions. And if I notice an app looking for excessive permissions (e.g. location) with no good reason why (e.g. a terminal app), that'll give me a clue that there's a ton of data being collected. Once upon a time, a giant percentage of a device's user base was tech-savvy early adopters. But with billions of devices having been sold, 99%+ of Android users have very little interest in details like permissions. But when these details are taken away... when I can't see permissions, when apps I use lose features because of new, restrictive Play Store policies, and when Android continues down this road of "privacy" without insight into exactly what my phone is doing... well, if I wanted this, I'd have chosen an Apple device.
- RootKitBeerCat 4y agoIt’s like installing an app on your computer; your giving the app permissions to your computer… there’s so much Google can’t control that it’s dumb to blame them here… I’m not saying “every end user should be wary of their apps and test them all”, but basically… what’s the alternative? Build your own mobile os, and then side load and very every apk?!
- qwery 4y ago> there’s so much Google can’t control that it’s dumb to blame them here I think it's pretty clear that the Google Play Store is something that only Google can control.
- est 4y agoAndroid should abandon the current permission mode Everything should be permitted by default, however, the user can choose to return blank, fake or real data.
- ajvs 4y agoAKA XPrivacyLua
- nokya 4y agoI think it's good news. I don't see why they should be more transparent on this: nobody cares, and the very rare users who actually care about these things would not trust that information anyway.
- dontbenebby 4y agoAfter all that research presented at fancy conferences about this topic, why would they then erase what little trust they had built up by making this change?