3 ms·
If they forgot to add "read contacts" in their application manifest, then the code that tried to read the contacts would ALWAYS fail. Even on the simulator, whi
by SomeCallMeTim 15y ago
If they forgot to add "read contacts" in their application manifest, then the code that tried to read the contacts would ALWAYS fail. Even on the simulator, which is rooted.
It would be nice to allow or deny an app "optional" permissions (selected as optional BY the app) at run-time. It would NOT be nice for users to be able to do this willy-nilly. With the dozens of possible permissions, you'd have millions of potential combinations a particular user could enable or disable, and you'd need to be sure your app worked with any combination.
But worse than that is the fact that a lot of apps are monetized by ads, and disabling "INTERNET" permission would prevent ads from downloading. If I'm trying to make a living off of my app, I don't want to make it easy for people to get it for free. Some people will anyway, of course, but no need to make it easy.
- falling 15y ago> If they forgot to add "read contacts" in their application manifest, then the code that tried to read the contacts would ALWAYS fail. Even on the simulator, which is rooted. I meant the Android OS developers (which is what happened with iOS here), not the 3rd party developers.
- SomeCallMeTim 15y agoThey didn't forget. [1] String READ_CONTACTS Allows an application to read the user's contacts data. String WRITE_CONTACTS Allows an application to write (but not read) the user's contacts data. So yes, if they HAD forgotten, then Android would have the same security hole. But it doesn't, because they took security seriously. [1] http://developer.android.com/reference/android/Manifest.permission.html http://developer.android.com/reference/android/Manifest.perm...