3 ms·
That’s not perfect either. It’s granular from the developer point of view, but it’s not for the user: when you install an app you either grant it all the permi
by falling 15y ago
That’s not perfect either.
It’s granular from the developer point of view, but it’s not for the user: when you install an app you either grant it all the permissions it requires (before you have a chance to actually run the app and see what it does) or you don’t install it at all.
With the iOS model (asking permissions when the app uses them) I can install an app, deny it permission to use my location and it will still work for everything else.
Also, how would that solve the problem if the Android developers forgot to add the ”read contacts” permission in the SDK? They would still have to update the software to add it.
- SomeCallMeTim 15y agoIf they forgot to add "read contacts" in their application manifest, then the code that tried to read the contacts would ALWAYS fail. Even on the simulator, which is rooted. It would be nice to allow or deny an app "optional" permissions (selected as optional BY the app) at run-time. It would NOT be nice for users to be able to do this willy-nilly. With the dozens of possible permissions, you'd have millions of potential combinations a particular user could enable or disable, and you'd need to be sure your app worked with any combination. But worse than that is the fact that a lot of apps are monetized by ads, and disabling "INTERNET" permission would prevent ads from downloading. If I'm trying to make a living off of my app, I don't want to make it easy for people to get it for free. Some people will anyway, of course, but no need to make it easy.
- falling 15y ago> If they forgot to add "read contacts" in their application manifest, then the code that tried to read the contacts would ALWAYS fail. Even on the simulator, which is rooted. I meant the Android OS developers (which is what happened with iOS here), not the 3rd party developers.
- SomeCallMeTim 15y agoThey didn't forget. [1] String READ_CONTACTS Allows an application to read the user's contacts data. String WRITE_CONTACTS Allows an application to write (but not read) the user's contacts data. So yes, if they HAD forgotten, then Android would have the same security hole. But it doesn't, because they took security seriously. [1] http://developer.android.com/reference/android/Manifest.permission.html http://developer.android.com/reference/android/Manifest.perm...