22 ms·
Everyone knows all the apps on your phone
- deleted 2y ago[deleted]
- smallnix 2y agoNice analysis. Google should take notice. Do worldwide used apps do this too?
- einszwei 2y agoFrom the article - Facebook, Instagram, Snapchat, Subway Surfers, and Truecaller use this too
- OutOfHere 2y agoIf Google truly cared about privacy, each app would run in its own strict jail, and permissions would be faked by default. Also, easy malware by Israel or anyone else would not be a thing. As it stands, apps know everything I am doing, and I get targeted spam email rather immediately.
- brunoqc 2y ago> apps know everything I am doing I think I call bullshit on this. But I agree that they could do way more and that they don't seem to care.
- JumpCrisscross 2y ago> If Google truly cared about privacy Have they even been pretending on this front?
- Speedy218 2y agoThey put in a lot of work to make it seem like they do believe it or not, I'm not sure how well it is working out for them though.
- amelius 2y ago> I don’t even know where to begin unpacking this madness. How is knowing whether I have the Xbox or the Playstation app installed on my phone essential to their Swiggy's core functionality? Probably has to do with feeding adtech's hunger for personal information, or fingerprinting maybe (not sure if that's a thing in the context of phone apps).
- einszwei 2y agoJust wow. I assumed that Google patched this few years back but guess they left a few backdoors.
- dhosek 2y agoI would pretty much assume that any Android phone is a massive privacy leak and security risk. I’d hope that an iPhone is better, but I’d be wrong.
- gruez 2y agoIt's probably an oversight than a "backdoor". They already have a "frontdoor" in the form of a permission that's pre-granted to them by the OS, so there's little need for them to devise backdoors like the android.intent.action.MAIN query that the blog post mentions.
- iamnotarobotman 2y agoI just don't trust Google anymore. They are not the same as they were years ago and have just declined in general. Play Store Review and everything takes weeks sometimes and I can't tolerate that.
- rkagerer 2y agoCan you see in the Play store before installing an app exactly which other apps it's allowed to talk to? Can you see it on your phone and override?
- gruez 2y agoNo, not in any straightforward way, although you can theoretically: 1. download the APK from a mirror site 2. disassemble it to get the android manifest 3. inspect the android manifest to check for the things the blog post discusses
- marcodiego 2y agoWell, things are particularly more complicated on my case: I don't use google services and only install apps from f-droid.
- cheschire 2y agoCan windows apps (not installed from the MS store) enumerate through the window titles of all open windows? How hard would it be for an app to monitor all of your web traffic based on the title alone? Legit question. ChatGPT isn't super helpful here since it agrees with everything when I'm really looking for someone to say why this isn't really feasible in the real world.
- gruez 2y agoMost windows apps aren't sandboxed, so them being able to grab window titles is the least of your worries. Any program can steal your login sessions and passwords if they wanted to. https://xkcd.com/1200/ https://xkcd.com/1200/
- facile3232 2y agoAre you essentially discussing like a keylogger? I can't imagine windows intentionally keeps the plaintext password anywhere longer than it needs to be.
- gruez 2y agoObviously there's no way for a malicious program to grab your login credentials that you've entered into an incognito tab that have been closed. There might not be sandboxing, but viruses can't timetravel yet. However that's not going to be much of a defense when many users use password managers, and are terrible at detecting malware (so it's only a matter of time before their passwords are keylogged).
- misnome 2y ago> viruses can't timetravel yet _Windows Recall to the rescue!_
- halfcat 2y ago> I can't imagine windows intentionally keeps the plaintext password anywhere longer than it needs to be. Can’t tell if serious or not [1]. Also any program can read any saved password out of Windows Credential Manager. https://en.wikipedia.org/wiki/Mimikatz https://en.wikipedia.org/wiki/Mimikatz
- dTal 2y agoAnother fantastic reason to strictly only install apps from F-Droid.
- JohnFen 2y agoHow does that address the problem? Does F-Droid do some sort of additional screening to keep out apps that do this?
- marcodiego 2y agoFirst, f-droid only accepts OSS apps, so the incentives for spyware is simply not there. Second, anti-features are explicitly marked on f-droid. Third, f-droid apps are curated like a very rigorous linux repo.
- JohnFen 2y agoBeing an OSS app is not sufficient protection. Most OSS apps aren't terribly misbehaved, but some are. Being OSS in and of itself is not anything like a guarantee with this sort of thing. > Third, f-droid apps are curated like a very rigorous linux repo. Yes, I know. My question is is this one of the things they're screening for?
- johntitorjr 2y ago[dead]
- dandersch 2y agopackages on f-droid list all required permissions explicitly, and the mentioned permission seems to be listed as "query all packages: Allows an app to see all installed packages.". It doesn't mark the app as having "anti-features", but you can at least make a more informed decision this way.
- JohnFen 2y agoThat's pretty cool, but the article says that most apps that are doing this sort of thing aren't using the query all packages permission and instead are using the facility to provide a specific list of apps they're checking for, which is not permission-gated.
- zx8080 2y ago> For extremely specific use cases such as file managers, browsers or antivirus apps, Google grants an exception by allowing QUERY_ALL_PACKAGES permission, which provides full visibility into installed apps. Why would browser need to enumerate the installed apps? Why?!
- Borealid 2y agoWhen a user visits a play.google.com URL Google wants to be able to show either an "install" or a "launch" button contingent on whether the app is already installed. In other words, blame Google product management.
- lurking_swe 2y agothis doesn’t make sense and sounds like an excuse IMO. Instead of the browser enumerating all apps, why can’t it check when you visit a page if the current page (ONLY the current page) is installed as an app?
- jerbear4328 2y agoHow would the OS know if the app that the browser is querying about is actually the current page? For all the OS knows, the user might be quickly visiting a ton of play.google.com pages for the top 1000 apps on the app store.
- heavenlyblue 2y agomake it into a system dialog?
- LordShredda 2y agoBut God forbid users learn how to use their device. All of this could be prevented by having the users manually pick the application instead.
- 2y ago
- andsoitis 2y ago> everyone knows all the alls on your phone On Android phones. iPhone doesn’t have this privacy deficiency.
- piyuv 2y agoRight, only Apple knows, but it’s ok, they’re the good guys
- andrei_says_ 2y agoDefinitely not “good” but I’m still to see anything remotely resembling the complete disregard for privacy and security typical for the adtech-driven android ecosystem. Just a different business model, not a display of moral values. Sure, Pegasus exists but I don’t think it is commodified yet.
- jmb99 2y agoIgnoring the sarcasm... What evidence is there/can you present that Apple is making use of this information in a negative way? How can Apple not have a list of installed apps on your phone while maintaining basic functionality (automatic updates, reinstalling apps from backup, etc)?
- PaulRobinson 2y agoSort of. They have a list of apps you've bought/installed through app store, and they can figure out what you've deleted based on what your phone is pinging for update checks on. If they went beyond that, or disclosed that knowledge, or allowed an app to get that manifest without your permission, it would destroy their brand image built around privacy, in a way that would cause long-term irreparable damage. They decided to not comply with laws compelling them to add back doors to optional encryption on iCloud storage, rather than tarnish that image, because they know how valuable that trust is. You can dump on Apple all you want, but compared to Google who plead with people to use their browser and phones to improve adtech surveillance they can monetize, I think they're doing OK and are a lot more trustworthy.
- criddell 2y ago
- avsteele 2y agoIf they just audited apps and banned companies from the app store for abuse it would do a lot to curb this behavior. This is feasible, there just aren't THAT many popular apps at any given time.
- whatevertrevor 2y agoThey could start by at least closing the MAIN intent filter loophole.
- Tmpod 2y agoIt requires root, but you can block/spoof this with an LSPosed[1] module such as XPrivacyLua[2]. I hear there's also the closed-source AppOps[3], but I've never used it. [1]: https://lsposed.org https://lsposed.org [2]: https://github.com/M66B/XPrivacyLua https://github.com/M66B/XPrivacyLua / https://github.com/0bbedCode/XPL-EX https://github.com/0bbedCode/XPL-EX [3]: https://appops.rikka.app https://appops.rikka.app
- dheerajvs 2y agoI've not heard of XPrivacyLua, which is by the same author of the excellent NetGuard[0], which I've been using for years. Interestingly XPrivacyLua is not supported anymore and the pro companion app will be removed from the Play store by Google because it uses the permission QUERY_ALL_PACKAGES.[1] [0]: https://github.com/M66B/NetGuard https://github.com/M66B/NetGuard [1]: https://xdaforums.com/t/closed-app-xposed-6-0-xprivacylua-android-privacy-manager-unsupported.3730663/page-325#post-87086407 https://xdaforums.com/t/closed-app-xposed-6-0-xprivacylua-an...
- Tmpod 2y agoIndeed, it is a shame. However, XPL-EX is a fork (though with much internal code (re)written at this point) with even more capability, while maintaining the familiar and simple UI. Seems pretty neat!
- solardev 2y agoPrivacy issues aside, it's kinda cool reading about how Indians use their phones, and also how they use English. I'd never heard "beyond the pale" before, and I'm still not sure what the idea of "multiple Indias" means when some of them are Mexico and some are Africa...? I've also never heard of the majority of the apps being analyzed or tracked. Must be such a different world out there.
- rashidujang 2y agoFrom the context, what I gather was meant by the idea of "multiple Indias" was the socioeconomic status of different demographics in India and their app usage. The presence of specific apps gives a tell to which demographic they belong to. In other words, the richest demographic used certain apps and was equated to folks in Mexico, followed by the less rich equated to folks in Indonesia and the poor to Sub-Saharan Africa.
- milesrout 2y agoBeyond the pale is commonly used in English. A pale is a stake, and it means beyond the boundary (set out by a fence with stakes, hence the phrase) of what is acceptable. It gaines popularity in the mid 19th century. It may be related to the term "the Pale" which referred to the better controlled more Anglicised part of Ireland around Dublin, but there isn't enough evidence to be sure of this. Certainly not an Indianism anyway. >I'm still not sure what the idea of "multiple Indias" means when some of them are Mexico and some are Africa...? Is it not pretty obvious? It is like the phrase "middle America". It doesn't literally mean a different country. It means different wealth categories: the Indians that when considered as a whole are economically equivalent roughly to Mexico, those roughly equivalent to Indonesia (poorer) and those roughly equivalent to Sub-Saharan Africa (poorest). There are ~1b Indians that are still so poor they aren't realistically in the market for your startup app if it wants its customers to ever spend anything, there are ~300m Indians that could be in the market for some apps, but probably mostly free ad-funded ones, and there are ~150m Indians that are quite a good market because they will happily spend money on something that provides value. I got all this just from reading the post btw.
- 2y ago
- DevKoala 2y ago> How is knowing whether I have the Xbox or the Playstation app installed on my phone essential to their Swiggy's core functionality? How will knowing if I have the Naukri or Upstox app help them deliver groceries to my doorstep? It is for fingerprinting purposes
- wutwutwat 2y agofingerprinting is the best case scenario
- _heimdall 2y agoWhat's the worst case, in your opinion?
- hattmall 2y agoTargeting and profiling. Reselling the data.
- _heimdall 2y agoMaybe I'm wrong, but that feels pretty similar to fingerprinting. Usually that's why online services try to fingerprint you, for advertising and data revenue.
- deleted 2y ago[deleted]
- DevKoala 2y agoThat is what the fingerprinting is for.
- YetAnotherNick 2y agoFingerprinting is just for identifying user, not getting user data. You can potentially resell things like app usage to credit rating company.
- captn3m0 2y agoThe ACTION_MAIN loophole has been written about before: https://commonsware.com/blog/2020/04/05/android-r-package-visibility-holes.html https://commonsware.com/blog/2020/04/05/android-r-package-vi... Google refuses to patch this. I wonder what would happen if you submit it to the Android VDP as a permission bypass. There’s also this SO question by the author about the bypass: https://stackoverflow.com/q/79527331 https://stackoverflow.com/q/79527331
- nexle 2y agoThanks for the link, seems like the loophole is already there since the introduction of the package visibility restriction, and almost everyone and their mother knows how to bypass this restriction. > Google refuses to patch this While I don't believe Google engineers are not aware of this widely used loophole, do you have any source that they refused to fix it?
- AznHisoka 2y agoThat loophole was published 5 years ago, it hasnt been fixed since. Do you need someone from Google to explicitly write an official note, notarized, indicating they are refusing to fix it?
- ignoramous 2y ago> refusing to fix it Google addressed similar isolation concerns (without breaking a tonne of APIs in incompatible ways) with Private Space and Work Profile: https://source.android.com/docs/security/features/private-space https://source.android.com/docs/security/features/private-sp...
- deleted 2y ago[deleted]
- whs 2y agoIf it's a security issue fix, they should release it in one of the monthly security patch. I also think that private space do not fix the underlying issue. If you have four apps and you don't want them to know about each other you can put one of them in main profile, work profile, app locker and you run out of profile for the last one. The way app locker work doesn't scale to tens of sandbox.
- billfruit 2y agoSome apps like Obsidian needs permission to access every file on the device. It is surprising Obsidian isn't getting called out on that very much.
- wkat4242 2y agoIt's because it stores the files there so you can sync them with other permissions. And also that your notes aren't deleted like they would be if they were stored in the internal app storage. There's more granular options for filesystem access available but if you implement them you limit yourself to the latest Android releases. According to Exodus it has no trackers and it's an open source app also so you can see what it does (though tbh I didn't check that for the mobile one) If there's apps to call out there's way worse than Obsidian.
- billfruit 2y agoObsidian isn't open source by most reports. Surely Obsidian do not to see all files on the device, it only really needs to see the files the user needs it to see.
- danparsonson 2y agoThere isn't a permission for that though - it's all or nothing. I agree that it should be more granular; each app should really have its own scoped file storage area by default, with "access anything" being reserved for file browsers, backup software, etc.
- billfruit 2y agoAndroid already has support for scoped storage. So it is not clear why Obisidian needs the whole file system permission.
- wkat4242 2y agoYes but only later Android versions. If you start supporting those you need to move to the corresponding API level and that means to drop support for older ones. They probably don't want to do that yet. This one is Android 10 and up, and the Android 10 version of scoped storage was quite basic IIRC so you probably want an even later one. I guess they still want to support older phones.
- hnburnsy 2y ago>For extremely specific use cases such as file managers, browsers or antivirus apps, Google grants an exception by allowing QUERY_ALL_PACKAGES permission, which provides full visibility into installed apps. 'Extreme' my a*. My bank app has this permission, as well as my camera app, contacts app, clock app, Google Home, and on and on. My bank app was moved to an old iPad because of this.
- silenced_trope 2y agoyea I used to work for an advertising network and every game that implemented the Android SDK ended up with this permission, it was a way that we used to not show ads for games that the user already had on their phone
- djrj477dhsnv 2y agoAnyone know if GrapheneOS has protection against this?
- switch007 2y agoIt doesn't afaik. Only indirectly through multiple profiles I was kind of surprised https://discuss.grapheneos.org/d/13302-query-all-packages-permission-in-grapheneos https://discuss.grapheneos.org/d/13302-query-all-packages-pe... https://discuss.grapheneos.org/d/7800-how-to-mitigate-identifiability-from-google-accessing-installed-apps/9 https://discuss.grapheneos.org/d/7800-how-to-mitigate-identi... Later For the wider audience: though don't take this as GrapheneOS doesn't care about privacy. I'm sure there are reasons (I didn't read all of the linked threads) and it gives you plenty of other protections and tools - eg profiles, ability to disable all network access by app etc
- fph 2y agoA rationale from the core developer [1]: > I'm sure there are plenty of system APIs providing this information too, and I don't just mean APIs designed to directly provide the information. > It's not useful to prevent directly getting a list of installed applications without preventing detecting which applications are installed, so this specific feature request has to be rejected. It would have to be part of a larger, much more comprehensive feature preventing apps from finding other apps. That implies outright preventing communication with non-system components which is a much different approach to applications and rules out a lot of things. [...] > The request should be for preventing apps from discovering which apps are installed, since anything less than that has no privacy / security value. There's no point in disallowing access to a list while not preventing discovering which apps are installed anyway. The open issue to restrict app visibility is [2]. [1] https://github.com/GrapheneOS/os-issue-tracker/ https://github.com/GrapheneOS/os-issue-tracker/ issues/149#issuecomment-553590002 [2] https://github.com/GrapheneOS/os-issue-tracker/issues/2197 https://github.com/GrapheneOS/os-issue-tracker/issues/2197
- djrj477dhsnv 2y ago
- johntitorjr 2y ago[dead]
- nickvec 2y agoJust curious, why was this targeted specifically at Indian apps?
- epistasis 2y agoThe tag line for the blog is "tales from indian web rabbit holes."
- wcfields 2y agoThe author is probably Indian based upon the blogs subtitle of “ tales from indian web rabbit holes. “
- gopkarthik 2y agoBecause the substack's author focuses on Indian web. From their description: "tales from indian web rabbit holes."
- aaron695 2y ago[dead]
- bustling-noose 2y agoVery simple: Big companies like Swiggy and Zepto will mine the F out of your data. Some of it is for their benefit but some of it they could sell in the future. These so called founders are really just another wolf of app street looking to pump and dump. So when they do dump, or when some VC comes with money, they don’t just sell their app they sell it as a whole package of data and analytics that some company can use to sell their product or something VC can leverage to sell their stock to someone else. It’s not that difficult. As far as smaller apps go these apps outsource their development to people who come with ‘packages’ to develop and maintain their app. These packages are the same logic as above but it’s just that they come from some template so you might be asked for location permission or camera or microphone by some really random app that has nothing to do with it. While the quality of iOS is degrading, some of these things are really important and simply work better on iOS.
- 6510 2y agoIf nothing is done why not require competing apps be uninstalled?
- deleted 2y ago[deleted]
- daft_pink 2y agoiPhone users reading this like…. I love my iPhone.
- vanderZwan 2y agoIf the article explained why iPhone was worse than Android at something they'd be like "whatever, I love my iPhone" so I don't see how that statement adds any new information.
- hu3 2y agoI read some hours ago a comment to the effect of "whatever, I don't expect Apple to be good with AI so it's okay for Siri to suck since forever, I still love my iPhone"... I can't help but be amused at a comment defending a 3 trillion USD company technical incompetence.
- daft_pink 2y agoI’m not sure that’s true. I wish there was a foldable version of the iPhone. I just think better privacy and security controls and stricter app guidelines are a reason people choose the iPhone over Android, so this really isn’t a surprise to people that have been paying attention. It’s the tradeoff we make for the walled garden approach, but I think it makes sense for a smart phone and less so for a general purpose computer.
- turblety 2y agoI still, will never understand the need for native "Apps". To this day, I have never seen an "App" that couldn't simply have been a website/webapp. Most of them would likely be improved by being a webapp. The only benefits I can see of "Apps", are the developer get's access to private information they really don't need. Yeah, they get to be on the "App Store". But the "App Store" is a totally unnecessary concept introduced by Apple/Google so they could scrape a huge percentage in sales. Web browsers have good (not perfect) sandboxing, costs no fees to "submit" and are accessible to everyone on every phone.
- zer0zzz 2y agoThe most basic app, a notepad, I often prefer native. When I go between google keep or notion to apple notes I can tell the difference. If the text is long enough, the web apps just can not load the content. Just to confirm: I dumped all of my notes from my insanely large apple notes (about 16000 lines of text) and pasted them into Google Keep, Notion, Google Docs. With the exception of Google Docs the rest of them flat out froze and I had to kill my browser. Stop trying to tell us that the browser is the answer to everything when most web apps cant do the job of Notepad.exe or vi
- turblety 2y agoSorry, I couldn't recreate this. I just built a tiny texteditor app: https://65cd02a1-8f00-47cb-b1d1-231493de5fc2.paged.net/ https://65cd02a1-8f00-47cb-b1d1-231493de5fc2.paged.net/ Tried putting 20k lines into it. Loaded instantly, allowed me to scroll and edit flawlessly. But I get your point. I'm on a pretty decent 2022 iPhone, and I'm sure at some stage I would run into a performance hit. But not at 20k lines.
- eknkc 2y agoNote taking apps generally do formatting, markdown like stuff or at least linking to urls in the text etc. You cant slap a plain text field and assume that emulates the actual experience in any way.
- 2y ago
- zer0zzz 2y agoMy solution to this is to use the apps that come with my phone and avoid relying on anything else. Problem solved. I use signal, uber, MyChart (for my doctor), and some apps for banking but that is about it.
- cyb0rg0 2y ago[flagged]
- nindalf 2y agoIs this an LLM generated comment, but in the style of a different website? I’d suggest tweaking the prompt.
- waveringana 2y agothe cheap models love hashtags
- nindalf 2y ago> Beyond the usual categories, I see there are checks for apps like Tamil Calendar, Odia Calendar, Qibla Direction Finder, mandir apps, astrology apps. They know what they’re doing. This loan app is profiling people on the basis of race (Tamil, Odia) and religion (Qibla Direction Finder is used by Muslims, mandir apps by Hindus).
- photonthug 2y ago> It's worth acknowledging that there are some legitimate reasons for an app to check which other apps are installed on your phone. For example, an app might check which UPI apps are installed to show relevant payment options. Nope! Nope, nope, nope. If you're wondering how we got into this situation.. well, it's exactly stuff like this. Weird to see someone who's digging into it at all also making excuses for it. No one ever said "I want to avoid a single extra click once every other month, so I guess I better irrevocably open my data/phone/life up completely to megacorp forever". And they certainly did not say this about tinycorp. People just absolutely suck at adversarial thinking, and good guys need to do it for them before bad guys can. Do you want organized crime blackmailing your politicians about dating apps and infidelity? Do you want to make it easy to do large scale targeting of ${vulnerable_people} the next time the cultural or political climate shifts? Come on. Anyway shouldn't the phone OS itself handle this rather than apps launching apps?? If not.. just let people pick a payment option, and then throw an error if the option is not available.
- qwe----3 2y ago> "I want to avoid a single extra click once every other month, so I guess I better irrevocably open my data/phone/life up completely to megacorp forever" Nah, it's super annoying when I click on a link and don't get redirected to the native app. This happens way more then once a month. Web experiences are much worse for many things.
- photonthug 2y agoCool but the attitude of “bring on the dystopian future as long as it’s more convenient for some people some of the time” is still confusing to me. Do you imagine that leaked information like this has never gotten someone killed before, and never will in the future?
- hollow-moe 2y agoGood, because this is what Intents are for. No app needs to know all your installed apps to launch them with a link.
- 2y ago
- Yaggo 2y agoThe title should read: "Everyone knows all the apps on your Android phone"
- DeathArrow 2y ago>Please remember the next time you casually install an app on your Android device, this information is being broadcast to the whole world. Data brokers will use it to profile you, cross-reference it with data about you from other ad networks and eventually it will be used to decide how much you’ll be asked to pay the next time you order a samosa. Who are those data brokers? Are they publicly known? Do they have an API where a business sends customer ID, mail or something and get an spending profile that helps adjusting price for a particular customer? I know this sounds evil. But didn't banks and insurance companies collaborate to profile their customers since tens of years ago? That is not similarly evil?
- DeathArrow 2y agoTLDR, want privacy, don't use Google products.
- weinzierl 2y ago"the one that blue tick twitter accounts living in certain pin codes of Bengaluru passionately discuss amongst themselves for a week every year" To someone embarrassingly unfamiliar with Indian culture, what does it mean?
- moi2388 2y agoThe PowerPoint he talks about and is displayed the line below it
- weinzierl 2y agoI know but that does not clarify the connection between blue tick, certain pin codes and a certain week in the slightest. Sure, these are probably all hints to affluent members of society but I was hoping for a more detailed explanation.
- banqjls 2y agoBlue tick/check = verified Twitter accounts, from when Twitter staff chose who to give the blue tick and only gave it to journalists, technologists, etc that the twitter staff wanted to amplify. Nowadays a blue check simply means you purchased premium, but we remember the original meaning. This is not an Indian thing. PIN codes = postal codes.
- weinzierl 2y agoYes, the interesting question is which PIN codes is the author hinting at and which week of the year and why. This is what I want to know. I think I can figure out the rest myself. But while we are at it: What is the significance of a cow trading app. Is it used by people who treat cows as sacred or the opposite?
- Slitted 2y agoI’m sorry but I have to bring this up: are these comments bait? The questions are a little too naive yet purposeful.
- ErigmolCt 2y agoThis is equal parts fascinating and horrifying
- tmtvl 2y ago...On Android. I'm sure I don't have that problem on my Ubuntu Touch phone (if only because there are hardly any apps for it).
- nolist_policy 2y agoInteresting, how does Ubuntu Touch sandbox apps? Does it have one-time permissions (like Android)?
- tmtvl 2y agoI actually don't know, I was just making a joke about the dearth of applications on UT. I'd expect it to have Snap-type sandboxing, but the Security and Privacy section of the settings app doesn't tell me much.
- surmoi 2y agoExodus Privacy will let you know about this kind of Android apps you should avoid installing https://exodus-privacy.eu.org/ https://exodus-privacy.eu.org/ Swiggy is actually a small player in terms of permissions requested, with 'only' 47 Compare it to Weibo with 104, Wechat with 93, Facebook with 85, Snapchat with 71 (granted those apps may offer additional services that require some additional permissions, but they are definitely not worth giving them all your data...)
- deleted 2y ago[deleted]
- graemep 2y agoThe HSBC UK Android app look s at what apps you have, and refuses to run if you have apps with certain permissions (such as an alternative launcher) and now refuses to run if you have any apps from outside the Google app store. I have complained about this here before, but the end result was that I asked for a hardware security device and use the website instead.
- switch007 2y agoThat's beyond absurd. Sounds par for the course with HSBC!
- odiroot 2y agoInterestingly FirstDirect app (also part of HSBC) has no such problems. It even ran on my previously rooted phone.
- qbane 2y agoTired of apps using shady, fragile tricks to refuse to work and claiming that you are "secured" by them
- fudged71 2y agoThat's pretty funny, right? They have to spy on you to tell you what else you are using could be spying on you. Do they happen to say this data is not transmitted to the company?
- bpbp-mango 2y agoandroid lmao
- Tewboo 2y agoIt's true, our phones are like little windows into our lives. The apps we have reflect our habits and interests.
- TekMol 2y agoSo I downloaded a few dozen Indian apps I could think of on top of my head and started reading their manifest files How do you download apps from the Android app store and read their manifest files? Does this mean one could make a website that lists all those manifest file, so the users could decide against using apps that use this loophole?
- Etheryte 2y agoYes, it's called alternative app stores and there's quite a few of them around.
- TekMol 2y agoHmm.. how do the apps from the Android app store get into the alternative app stores? And how do you know they are the same app and not altered?
- Explore4526 2y agoYou can get APKs for each installed app
- turrini 2y agoI don't know if it is just me but I run every class of app in isolated "islands" (like work profiles) on Android. Browsers, banking apps, social media, instant messaging, tools, etc. Almost everything is isolated from another non related group.
- olejorgenb 2y agoHow?
- anonym29 2y agoYou don't have to sacrifice your privacy to use Android. GrapheneOS is a tremendous alternative, and even if you still need some Play Store applications, you can install a GMS compatibility layer and Play Store in either a secondary profile (recommended) or your main profile (not recommended) without granting Google unfettered control over your entire operating system. This compatibility layer offers a better reduction in attack surface and stronger hardening than microG. Alternatively, you can continue with the standard setup, accepting that you’re willingly providing companies with an unprecedented level of access to your personal data. It’s puzzling that many seem more concerned about breaking a familiar routine than about the risks associated with sharing every detail of their lives with companies that, in turn, share that data with one (or more) hostile government(s). There is certainly a lot of justified concern about government overreach and abuse of power on HN. It remains difficult to understand why many with these warranted concerns do nothing to adopt a more coherent and rational approach — such as merely attempting to protect their personal data by not deliberately and voluntarily feeding it entirely to companies that are secretly coordinating with the very same hostile governments these people claim to seriously fear and detest.
- Explore4526 2y agoThe problem is GrapheneOS is Pixel only. They are prohibitively expensive, especially in India where the mobile market is very crowded and you get Snapdragon 8s gen 3 for ₹25k.
- anymouse123456 2y agoIME, Apps usually represent an overly generous amount of contempt for the people who use them. At best, it's a designer's hubris (mixed with contempt) like, "You want to select some text out of your SMS message? I've decided. NOPE." But mostly we're treated with contempt simply because we're an annoyance that is obstructing the goal of serving the actual customer (advertiser) who is paying for the work. App Stores are no mystery. They are a funnel for rent-seekers and adtech info brokers. If you think they are intended to benefit you in any way at all, you are badly mistaken.
- bloomingeek 2y agoPerhaps crazy question: is it a good idea to have two phones now? One for making calls only, with as many apps as possible removed. And another phone for email, web surfing, photos, etc...? edit: Oops, I left out texting. Which phone for that?
- monsieurbanana 2y agoYou still make calls with your phone?
- bloomingeek 2y agoOf course, amazingly that's one of it's best features, enabling you to actually speak to a real person. (it's a type of personal connection that fleshy robots have, for some reason, derided.) But I digress, excusing your bad form of answering a question with a question, I am interested in your opinion of the possible conundrum of the two phone idea.
- monsieurbanana 2y agoMy bad, I didn't knew you wanted a serious answer, I should have known that some people would seriously consider having three separate phones for texting, calling and everything else. For a serious answer then: Rather than segregating phone calling vs the rest, if you want to go to the hassle of maintaining multiple phones, I would put sensitive apps (i.e. bank apps) separated from the rest. But ultimately it depends on which threat model you are trying to mitigate. Most people would worry about protecting their financial information. If you are worried about possible backslash from a fascist state, you shouldn't use normal phone calls at all and switch to a privacy app. OTOH, a dedicated phone just to make phone calls makes sense if your threat model is your significant other.
- subscribed 2y agoIf you don't need ANY apps on your main number, good dual-Sim feature phone (but be extremely picky, some are utter trash). The for all the smart stuff, Pixel 6 with GrapheneOS. You can confine various "classes" off apps to dedicated profiles, so they'll never know of each other, and you get a vastly improved security (multiple releases in the month) and significantly improved privacy.
- RKFADU_UOFCCLEL 2y agoThis is to be expected though, a phone platform isn't exactly Tor Browser. The big API as with any platform will have plenty of ways to fingerprint people even without this one example, unless the developers went far out of their way from the beginning to build prevention in. Much like how on UNIX you can see what processes everyone is running and their command lines.
- napierzaza 2y ago[dead]
- aucisson_masque 2y agoThat's why I like hacker news. I found this article yesterday and posted it on reddit android, here : https://old.reddit.com/r/Android/comments/1jmwg4w/everyone_knows_all_the_apps_on_your_phone/ https://old.reddit.com/r/Android/comments/1jmwg4w/everyone_k... 0 upvote, comment filled with what is either depressed sad people or just bots. Here it's top 2... With mostly interesting comment. Some subreddit are more dead than other but r/android got to be one of the worst.
- hnuser123456 2y agoThe subreddit is mostly younger folks more aligned with the "fanboy" attitude, they downvoted because it was a critique of Android. Hacker news understands the concept of constructive criticism.
- aio2 2y agoI wouldn't say understand, but better understands
- SV_BubbleTime 2y agoExactly this can be seen here if the discussion is about climate. Even better understands might be pushing it. “Better tolerates”
- touristtam 2y agoIt also helps that you need to have a certain _rank_ to be able to downvote on here, as opposed to the default rights you get on reddit.
- wruza 2y agoThread success is hit and miss. You can post and there's crickets, or you can post and people pile in. If you click the "past" link under the title, there's a thread from 2 days ago, completely dead.
- diggan 2y ago> Some subreddit are more dead than other but r/android got to be one of the worst. Yeah, I'm not sure what exactly is going on with reddit but if dead-internet theory would hold anywhere, it seems to be there. Besides, all the topic/subject subreddits seems moderated by people who hold a vested interest in the topic/subject, to the detriment of their community. I made a submission which went into details about the proprietary license that Meta's Llama is under, and what exactly that license means, and it was removed manually by the moderators of r/LocalLlama without any reasoning + they refuse to answer why it was removed even after trying to understand the rules of the subreddit better. I'm guessing when the last "reddit purge" happened where they replaced a bunch of community moderators with employees from reddit, most of the platform was sold to companies to moderate their own spaces, unfortunately.
- zkiihne 2y agoI used QUERY_ALL_PACKAGES among other things for my app Limit Buddy (https://www.limitbuddy.com https://www.limitbuddy.com). It would be impossible to make the app without it. But for more normal use cases there's no reason to have it. Apple has a much more robust solution privacy wise with their ScreenTime API but it makes an app like Limit Buddy much harder to build.
- therealmarv 2y agoIt's a known fact in the rooting community because some banking apps searching for root only apps! If you root (I advice against doing that) and have LSPosed installed you can hide apps to be seen by every other app with Hide My Applist (HMA) [1] or HMAL (which I like more because it is more minimalistic) [2] [1] https://github.com/Dr-TSNG/Hide-My-Applist https://github.com/Dr-TSNG/Hide-My-Applist [2] https://github.com/pumPCin/HMAL https://github.com/pumPCin/HMAL
- whalesalad 2y agoandroid* phone
- HackerThemAll 2y agoThank you Google's "top talent" Android devs for this permission system full of loopholes.
- aussieguy1234 2y agoIf I have Uber, but multiple competing apps on my phone and I grant Uber permissions to see that, will I get cheaper rides?
- nsonha 2y agoAndroid is so broken, each app query should be explicitly approved by user, instead of by reviewer like this.
- BGizzle 1y agoEveryone knows all the apps on your Android phone