3 ms·
The manifest has ACCESS_FINE_LOCATION. When you run the application, the developer actually displays a popup saying to grant the permission so it can do BLE sca
by x1sec 3y ago
The manifest has ACCESS_FINE_LOCATION. When you run the application, the developer actually displays a popup saying to grant the permission so it can do BLE scanning to connect to the hardware device.
Of course they neglect to say they will also use the permission to collect your GPS co-ordinates.
Then the AMap location services SDK goes further collects MNC, MCC, LAC and CELL IDs (CGI) and Wifi SSIDs. Here I think the battery app developer does not even know this is happening, they use AMap SDK to obtain the GPS data only. It took me quite some time to figure this out (documented in part 2[1]).
Will also note the manifest has CAMERA, IMAGE_CAPTURE, ACTION_VIDEO_CAPTURE, RECORD_AUDIO and MODIFY_AUDIO_SETTINGS. I have not seen where/how they are used (yet). The code that included strings requesting various permissions (In the AMap SDK code) uses string obfuscation to conceal what it is doing. Likely to trick automated static code analysis tooling.
Note:
> Alibaba state “in 2018, Amap became the first Chinese maps service to navigate a path to 100 million daily users”. [2]
How are Google allowing this SDK to be used in developer's applications?
[1] https://doubleagent.net/2023/05/22/a-car-battery-monitor-tracking-your-location-part2 https://doubleagent.net/2023/05/22/a-car-battery-monitor-tra...
[2] https://www.alibabacloud.com/customers/autonavi https://www.alibabacloud.com/customers/autonavi
- varenc 3y ago> The manifest has ACCESS_FINE_LOCATION. This seems like the problem? And it explains why the app can upload your GPS coordinates directly after querying the Android location APIs. According to the developer docs, Bluetooth apps should only request ACCESS_FINE_LOCATION "if your app uses Bluetooth scan results to derive physical location". And if they assert that they don't use BT to derive location then the user won't be prompted with a location permission dialogue, just a bluetooth one. This app isn't deriving location from Bluetooth alone? But I'm guessing it has an embedded map inside that shows your location, and that's why it needs ACCESS_FINE_LOCATION. Meaning it's unrelated to Bluetooth. From reading the docs linked by the GP it seems that for Bluetooth communication only purposes an app shouldn't request that permission.
- x1sec 3y agoThanks for this: I've updated the post with a note on 'if your app uses Bluetooth scan results to derive physical location'. I highly doubt this is why they use ACCESS_FINE_LOCATION for this purpose. Rather it's an opportunistic way to get users to accept the permission - they tell users to accept it to get Bluetooth working when the app is first installed. I wonder how many other apps on the Google Play store do this. We can't expect the every day user to read and comprehend Google's developer documentation.