9 ms·
We can't check the app permissions on Google Play anymore
- phnofive 4y agoReferenced previous discussion that this was going away from early June 2022, 167 comments: https://news.ycombinator.com/item?id=31698148 https://news.ycombinator.com/item?id=31698148
- yieldcrv 4y agoright, since the popup for permissions is in the app when its requested I would like more permissions to be different than all or nothing though. I wish you could segregate contacts. like, if I don't tell people around me that I know a high ranking official, why should a random app just because one of us uploaded our contact list.
- cowtools 4y agoI agree. An inportant one for me ia the filesystem. Why can't I segregate Whatsapp to a single directory?
- thaumasiotes 4y agoWell, that would imply one of two things: - Whatsapp keeps all its internal data in your Photos folder. - Whenever you want to send someone an image, you need to manually copy the image from wherever it is to the Whatsapp folder.
- admax88qqq 4y agoNonsense. Selecting a file to share without giving access to all files is already a solved problem via file pickets.
- iggldiggl 4y agoThe basic use case works, but quite a few things beyond that are broken. None of the various sandboxing attempts (not just Android, but everything) properly handles multi-file file formats [1], so that alone is very much not a solved problem!. Keeping an LRU list for files that were opened from outside of your own app becomes needlessly complicated [2]. Access gained that way isn't directly compatible with things expecting classic File API access (and sometimes those things are outside of your immediate control, like external libraries and even parts of the Android framework itself), and unfortunately the easiest workaround to that problem is just copying the file into your own private storage. [1] As far as I'm aware, only macOS attempts to at least handle related files that only differ in their file extension, but even that still doesn't cover more complex file formats like playlists, or HTML or DWG files or whatnot that can reference arbitrary other files. [2] If the same file is shared via different apps, the way things have been implemented on Android it becomes more complicated for the receiving to check whether those two incoming file shares actually refer to the same underlying file or not. Plus for an LRU list to make sense you need to try persisting the file permissions so you can still access the file later on [3] and also especially take care not to leak those permissions when you clean up the LRU list. [3] Which also leads to some strange scenarios like when you switch to a new file manager and uninstall the previous app, all LRU entries in other apps that were originally opened via that previous file manager now suddenly become invalid.
- arsome 4y agoGoogle "solved" this by making storage access between apps no longer a thing: https://developer.android.com/about/versions/11/privacy/storage#scoped-storage https://developer.android.com/about/versions/11/privacy/stor... 3rd parties solved this with optional Storage Isolation: https://play.google.com/store/apps/details?id=moe.shizuku.redirectstorage https://play.google.com/store/apps/details?id=moe.shizuku.re...
- joecool1029 4y agoGoogle made scoped storage mandatory in Android 11 and later[1], this can restrict to just the app's own directory but people usually want to share media from outside the app's directory so they request the additional access. [1] https://source.android.com/devices/storage/scoped https://source.android.com/devices/storage/scoped
- Spivak 4y agoI mean Apple still manages to list all IAPs even those only happen on prompt. The thing users want isn’t what permissions the app could possibly request, but what permissions are required to use what specific features of the app.
- jahnu 4y agoAbsolutely! And if the features are at all usable/trial-able or need an in app purchase, and is useless without. I feel tricked so often. Currently I need to install an app and try it before I can have much idea if it does what I need. Reviews are of limited use. I very much appreciate apps where I can trial or subscribe for a short period for a small price. If they do what I need I always end up buying or not cancelling the sub. This sounds a little contradictory (too tired to word it better right now) but I hope the general feeling is conveyed.
- taeric 4y agoUsers don't want to have to understand a permission model to use an app.
- david_allison 4y agoThat's only for 'dangerous' permissions as defined by Android. As an example: NFC is defined as a 'normal' permission.[0] As far as I'm aware [not an expert here], there's nothing stopping an app developer from updating their app with the ability to steal credit card/passport information (if the card is tapped against the phone). [0] https://developer.android.com/reference/android/Manifest.permission#NFC https://developer.android.com/reference/android/Manifest.per...
- Gigachad 4y agoCredit cards can not be duplicated wirelessly. I’m not familiar with passports but if they can then I’d say that’s a flaw of the cards rather than phone permissions. It’s possible to read nfc cards from quite a distance with a high power reader.
- david_allison 4y agoDo you have a source on that [credit cards]? From a casual further inspection, there are videos on YouTube which demonstrate this: https://www.youtube.com/watch?v=K_6oMZb8UOI https://www.youtube.com/watch?v=K_6oMZb8UOI
- Gigachad 4y agoSomeone else can probably give the technical details but from my understanding, all but the most primitive NFC cards use a challenge/response system rather than just an ID. So there is no way to actually clone the secret stored internally as this is never transmitted. I'm willing to bet that video is just plain fake. Especially given it only has 2k views.
- david_allison 4y agoI'd put stock in the video, it's using https://github.com/devnied/EMV-NFC-Paycard-Enrollment https://github.com/devnied/EMV-NFC-Paycard-Enrollment which seems reasonably popular.
- jeffdubin 4y agoI want to know if an app will launch itself on device startup, and I can't see that any longer with "data safety". There are other permissions that are now similarly hidden. I appreciate that less tech savvy Android users might benefit from a simplified view, but I wish they'd give the advanced user an option to view details (and, ideally, the ability to reject ANY permission).
- paradite 4y agoI publish both Android and iOS apps regularly, this is just Google getting to feature parity with Apple. Apple had data safety, Google now has it. Apple didn't show permissions, now Google also doesn't. Presumably most people don't really care about permissions anymore.
- xnx 4y agoAndroid still has permissions
- manchmalscott 4y agoNot presented in the App Store; both android and iOS still have a permission system, but you need to download the app before you can see what permissions the app has asked for.
- happyopossum 4y agoIn iOS you see what permissions are requested when the app needs them and, you know, requests them from you with a dialog. That seems good enough?
- unlaxedneurotic 4y agoIt's the same for Android.
- magnio 4y agoSame with Android.
- LeoNatan25 4y agoIt’s not. It would save me from so many predatory apps if I knew they’d require contact and calendar access, for example, for a utility app.
- manchmalscott 4y agoThe issue at hand is seeing what permissions the app wants before you download it, in the App Store
- beninsydney 4y agoIt's unfortunate that regulators have largely overlooked privacy in smartphone apps amidst all the other concerns they have over such platforms.
- Gigachad 4y agoThe permissions list on the play store was completely useless from a privacy standpoint. Even power users could to just about nothing with the info. The situation now where you approve or reject permissions as they are used in the app is vastly better than the original android model of being shown a wall of text with the options to either give away all of your data and security or not install the app.
- bornfreddy 4y ago> The permissions list on the play store was completely useless from a privacy standpoint. Even power users could to just about nothing with the info. This is not true. I avoid apps that require unreasonable permissions. I don't expect regular users to know what is reasonable or not, but hiding this information would definitely make installation process less convenient for me. Then again, I no longer use Google Play store and I install very few apps anyway, so maybe I'm not exactly their target user.
- beninsydney 4y agoThe permissions list allowed you to make a better-informed decision before you download the app, even though you can't change what permissions an app requires you could shop around for apps without specific permissions. This was never incompatible with ad-hoc approving or rejecting permissions either.
- Gigachad 4y agoThis only works for utility apps which are really the minority of apps that users install. There is only one app to access my bank account, there is only one app to stream netflix on, there is only one app to access government services on. Outside of flashlight and QR scanner apps, there is basically nothing the user can action aside from completely rejecting the wider service over some ambiguity in the permissions list.
- ggm 4y agoin unix, xattr and setfattr drive me crazy. As a PM, I do sometimes realize that the UX drive here would be "lets just remove these extended attributes, people hate them" instead of thinking about what they do, and how people (mis)understand them. I think Android permissions are like xattr. its the noise behind chmod, it shows up in odd ways like when you can't move or delete a setuid file, or in ls -<flags> contexts if you tickle it right. its the nitty gritty, the details. Not "does this s/w respect my privacy" but "of 100+ distinct attributes, data items about 'me', can I atomically grant/deny access or apply some conditionality to them" So I think the same thing about AWS Privs. My god, theres a million of the suckers. Do I want Amazon to simply remove the pane? God no. I just want to understand it better. Why can't google "do both" and have a path to see these, but feature-parity with Apple and simplify it on the surface?
- kornhole 4y agoI know this doesn't help the average user, but https://exodus-privacy.eu.org/en/ https://exodus-privacy.eu.org/en/ does their own analysis of apps and lists permissions and sensors. You can check here first. There reports are integrated into the Aurora Store.
- bb88 4y agoHonestly, these days I feel like it's dumb to deploy on a platform you have no control over, unless you have enough money to pay lawyers to get Google's/Apple's attention.
- webkike 4y agoI don’t think this comment is relevant to the discussion, which is google removing the permissions list for apps on the play store.
- lovelearning 4y agoThe dynamic permissions are not a replacement. Some users would never even install apps that asked for too many static permissions on the Play page. But now, if an app seems to meet their needs and they aren't sure, some of them will go ahead and install it just to try it out. How much can one run hurt after all? Due to unresolved questions or sunk cost dilemmas, they may even grant dynamic permissions. How much can one run hurt after all? So this will manipulate a percentage of reluctant users into data-providing users by hiding a reason for their reluctance. I'm inclined to suspect it'll benefit Google's ad impressions business and that's the actual motivation, not "feature parity" with Apple.
- russdill 4y agoOn a related note, I don't understand why apps are permitted to require you to enable certain permissions or refuse to run. What is the point of giving users control of their privacy if large popular apps are a able to essentially opt out of the optional part. I'm looking at you Kakao.
- axelthegerman 4y agoAgreed for optional permissions, but not sure what you'd expect a browser to do that doesn't have internet access or a camera app that is not allowed to access the camera
- patates 4y agoAllow you to open the app still and go through the menus, maybe you just want to export your data? Maybe you want to check the T&C again (which should be available offline from the menu)? Perhaps you wanted to see the design/ergonomics of the app before allowing it? It could be a thousand reasons. Photo app can display "No camera permission granted, click here to setup" instead of the visor or something, and the browser can also inform the user of the situation with a static page. It's like proper exception handling: Do not just close the app, fall back gracefully and allow the user to retry.
- russdill 4y ago
- MrThoughtful 4y agoWhat I always found very confusing is that apps on Android can either read all of the SD drive or nothing. Wouldn't the normal approach to gate applications from each other be to give each one the right to access a single directory? The way it is, all apps want to "READ_EXTERNAL_STORAGE" so they all can read all the data I save.
- lupire 4y agoIncorrect. Apps have private storage and shared storage, separate from fill disk access. https://developer.android.com/training/data-storage https://developer.android.com/training/data-storage
- MrThoughtful 4y agoThat is not what I see on the page you linked to. It says "READ_EXTERNAL_STORAGE when accessing other apps' files on Android 11 (API level 30) or higher" So, as I understand it, a user has no way to allow an app to read only from a single directory on their SD card.
- BoorishBears 4y agoRead further: > To give users more control over their files and to limit file clutter, apps that target Android 10 (API level 29) and higher are given scoped access into external storage, or scoped storage, by default. Such apps have access only to the app-specific directory on external storage, as well as specific types of media that the app has created. If you really want to get into the weeds, previously you could work around scoped content requirements with the manifest property "requestLegacyExternalStorage" But it's not respected if your app targets the latest version of Android, and new uploads have to target a recent enough version that the loophole is closed. Legacy apps will be unaffected though.
- tadfisher 4y agoThis is being clamped down on, at least for apps on the Play Store. How it works now is the app has unfettered access to its own internal and external storage directory, and can prompt the user to select another one to give access for saving additional data. There are some rough edges for implementors, though; for example, getting your content to show up in media player apps requires usage of a completely separate API, you can't just save data in the Music or Pictures directory.
- kulshan 4y agoI teach digital literacy courses for seniors. The Play Store is such a nightmare for me. What used to be a lesson on basic app installation has now become a safety lesson on how to be careful in the Play Store. It's a minefield of scammy apps.
- BLKNSLVR 4y ago... with a percentage cut to Google to "curate" said minefield as effectively as it resolves developer queries as to 'why banned?'. Is the App Store much better?
- sebazzz 4y agoThis is similar to either the Microsoft Store or Apple App Store (can't recall). You used to be able to see what in-app purchases were available, to determine if you weren't ripped off downloading this app. Now you can't.
- bpye 4y agoApple's App Store still shows a list of in-app purchases, not sure about the Microsoft Store.
- encryptluks2 4y agoMicrosoft Store is the worst. It is like something designed by an incompetent third-grader.
- josephcsible 4y agoDoes anyone know of a workaround for this that doesn't require you to install/update the app in question first?
- ulfbert_inc 4y agoAurora store client
- dhzhzjsbevs 4y agoI don't think I've checked permissions on the play store in ages. Don't apps prompt when they access things now? Speaking of which, anyone from Spotify around? Could you kindly take your request for control over Bluetooth and shove it up your fuckin arse? Why must I say no to this every time I open the app? No means no.
- josephcsible 4y ago> Don't apps prompt when they access things now? For some permissions, but not all of them. For example, they don't for Internet access. > Why must I say no to this every time I open the app? Doesn't Android have a "don't ask again" option for permissions?
- dotancohen 4y ago> For some permissions, but not all of them. For example, they don't for Internet access. Then why does this "Permission" exist? When will it ever be false?
- josephcsible 4y agoBecause if an APK doesn't declare that permission, then it still can't access the Internet.
- hulitu 4y agoWhy would an APK want to access the internet ? (why my Phone app needs internet access ?)
- dotancohen 4y agoBut why make it a "permission" then, if it is automatically granted? It should just be part of the regular API.
- iggldiggl 4y ago
- dheera 4y agoWhat they really need to do is to simulate data for permissions that are rejected. For example, if I reject location permissions, then play back a random GPS trail in a randomly selected city on the planet, complete with simulated error and drift. If I reject Wi-Fi scanning, then show a constantly changing set of fake access points. If I reject camera, then play back some cartoons or deepfaked video as a camera device. The app should never have to know its permission request was denied.
- teruakohatu 4y agoThis would be trivial to detect by the app and they would just block you anyway.
- josephcsible 4y agoThere's two ways Google could solve that: either make better fake data that isn't trivially detectable, or make a rule that trying to detect that gets your app banned from the store.
- Someone 4y agoThat would be a fun challenge: given access to all sensors except for the camera, write an app that creates fake camera data. If Google worked on that, results could be fairly creepy for those who store their data in their cloud. They can probably infer what you look like from your photos (you’re the one appearing in selfies most), know what weather it is locally, know that you’re, for example, looking at the Eiffel Tower, and maybe even have a photo from 2 minutes ago made by another user from the same place. I think Google certainly could make a fake address book that’s creepy for many users by looking at the address books they have.
- netheril96 4y agoDetectable, maybe. Trivial, definitely not.
- Kim_Bruning 4y agoThis is one reason I switched to F-Droid a while ago. Among other things, F-Droid is very strict about reporting potential anti-features, which (ironically?) makes me much more comfortable installing apps from that app-manager.
- kramerger 4y agoF-droid has one big anti feature itself: it tries to trick you to download their store app when all you want is to get the APK. Gives me 2015 sourceforge vibes
- Kim_Bruning 4y agoThe main page at https://f-droid.org/en/ https://f-droid.org/en/ pretty much seems to be about the app, so I don't feel particularly tricked. Thank you for pointing out that you can get APKs direct from the site too. That could be useful sometime!
- thekingofrome 4y agoThe best alternative is to use Aurora Store. It's also the only way to use the Play Store without a Google account connected to your device.
- bluecalm 4y agoMy idea to improve the issue is the following: an app asks for permissions and you as a user get two choices: grant the permission or grant mock permission. Mock permission gives access to some random data that like stock contacts/stock photos/whatever. Every app is required to work correctly with the mock data or is removed from the store. You could even have mock folders in the photo app or mock contacts on your phone so you as a user can see how the app works on those without giving it access to the real stuff. Example: a parking app asks for access to your contacts and ability to call, you give it a mock permission. It just works. When it tries to call someone you see info: "app XYZ calls mock contact A". When it tries to read your contacts it just gets a stock list. If it tries to tell you it needs real contacts you report it to Google and it gets removed.
- leandot 4y agoThere are still ways to get gplay permissions - e.g. see https://42matters.com/docs/app-market-data/android/apps/by_permission https://42matters.com/docs/app-market-data/android/apps/by_p... (note: i'm affiliated, but I believe it's relevant to the topic).
- tveita 4y agoIt would be interesting to look at historical data for permissions - what permissions are apps adding in the last few months compared to further back? Could make for some nice graphs and a blog post if you happened to have that data lying around :) I expect a lot of crapware authors are currently adding permissions that they've wanted to but couldn't justify to their users, now that Google has stripped their users of visibility and recourse. E.g. last time I looked at this a lot of obvious crapware was requesting the "ACTIVITY_RECOGNITION" permission for God knows what reason - a permission that can't be denied by the user. As a rule Google only gives users the option to disable a permission after it has been widely abused, or maybe not even then. It's downright hostile to take away one of the only ways users have to spot spyware before they install it.
- est 4y ago"Permission" system is broken to begin with. Every app should get all the permissions they want, but the user could choose what kind of data to actually provide, none, some, all or even fake. see also: XPrivacyLua