5 ms·
I really hope Google fixes Android's broken security model. As the owner & user of an Android device, I should be able to configure feature access on a per-app
by kakuri 13y ago
I really hope Google fixes Android's broken security model. As the owner & user of an Android device, I should be able to configure feature access on a per-app basis. It's ridiculous that you have to either grant an app all requested access, or just don't install it. You should be able to install it, but choose which features to grant access to and which to deny.
- salman89 13y agoWhat if core features of the app rely on the permissions? Is the onus on the app developer to build checks for permissions or on the user to realize the app isn't working the way it should because they disabled some permissions?
- moron4hire 13y agoI see nothing wrong with making developers check for features before using them. Should be used to it, with the variability of platforms.
- vasco 13y agoThe app would define core features and nice-to-have features. The user would be able to disable the nice-to-haves. Admittedly this just pushes the problem one layer down because Facebook would just make everything part of the core and force people to install. And now the user would have the burden of trying to figure out what was going on.
- atesti 13y agoThe best use case for oneself would be if missing features are emulated with dummy data using some app-firewall tool. The phone should give any app no chance of finding out, whether e.g. address book access was granted, but instead show fake data. Of course this would soon be a cat and mouse game if Google really implemented it for everyone: Developers like WhatsApp would check the address book data whether it is statistically sound and if not they would request you to grand access for real, etc. All the permissions only required for ads (like position, IMEI, full internet access, reading sms, reading address books) would also just have the app terminate if it's not possible, just like today they check for rooted devices based on tools like bash or they check for modified hosts files that block ads.
- jyap 13y agoOn iOS the onus is on the developer.
- krschultz 13y agoAs a full time Android developer, I can tell you that wouldn't be a burden. First off, there are already lots of places you have to handle compatibility based on the version of the phone, intents available from other apps installed on the phone, or capabilities (even something as basic as a phone can't be guaranteed if you support tablets). Obviously you can turn small things on and off in a block of code with if statements, but you can handle major changes with the Fragment model. If you have a drastically different UI due to a missing intent/permission/API feature you can actually ship the app with 2 different Fragments and decide which one to show at runtime. As an aside, I turned off auto-updating for Facebook and will not upgrade from here. Too many permissions, too intrusive to the UI. I have deleted Facebook from my phone before and I'm fine without it now.
- Zigurd 13y agoAs an Android app developer, I agree with this and it would not be a great burden. Developers would only need to add handling for security exceptions, and, perhaps, an explanatory error message. It is almost unavoidable that this happens. As Android is used more in enterprise settings, permissions such as access to contact databases would have to be selectively granted, and controlled by mobile device management systems.
- drdaeman 13y agoTo not break existing apps, denied request could just success, but return sensible but completely bogus data (no contacts, no apps running, connected to "default" WiFi network with BSSID 02:00:00:00:00:00, etc.)
- nrlucas 13y agoIt's going to be tough to convince every app developer to have their applications work in those circumstances. I would imagine some permissions which are core to the application would be required. Of course, then we are back at the start when app developers mark all their permissions to be core.
- Zigurd 13y ago"then we are back at the start when app developers mark all their permissions to be core" It should always be the user's or administrator's choice. There really is no such thing as a "core" permission. Of course some apps become a nullity without some access, but an unhandled security exception in those cases could result, for example, in a more-detailed system message asking if you want to uninstall the app, since you have decided against giving it permissions that the developer has decided are essential. This would also alert you to when a non-location app was trying to sneak a look at where you are.
- moron4hire 13y agoOf course, they would probably just compensate by making the entire app useless without the track-u permissions enabled :(
- utopkara 13y agoIt won't solve the problem. The default response will be to simply refuse to run at all. And, for an app like facebook, which has the upper hand, it is not a big deal that the user doesn't like it.
- micampe 13y agoOn iOS I can deny permissions one by one: I can deny the Facebook app to access my location, contacts and photos. It runs just fine without all of those.
- timmy-turner 13y agoThere could also be an option to provide the app with fake data instead of telling it to not have any permissions, e.g. an empty address book, empty list of currently running apps, a fake network access which actually routes the data through a proxy and so on.
- bookwormAT 13y ago"There could also be an option to provide the app with fake data instead of telling it to not have any permissions," Some guys from Cyanogen released a proof on concept a while ago. You could install any Android app and select which permissions to "mock". Anyway, I think the permission system in Android makes sense the way it is. It forces app developers to declare what they want to do on you system, but the install process stays simple and straightforward. On Windows and OS X, we used to give every app the "do whatever you want with my computer" permission for years. On Android you risk a shitstorm of bad reviews if you fail to explain the reasoning for permissions to users. And Google can use the permission list and double check apps with critical permissions for malicous behaviour.
- mtgx 13y agoNot sure about that, but Android 5.0 is rumored to use SE Linux (or SE Android I guess), which I believe is based on a more extensive permission model.
- paxswill 13y agoI can't find the precise announcements right now, but I'm pretty some portions of SEAndroid are already integrated with Android as of 4.2 (maybe 4.1).
- drdaeman 13y agoGoogle was asked for this myriad times. I guess, they won't fix it unless something extraordinary happens (like a huge privacy-related scandal). Apps on Google Play are throughly infested with ads and analytics and whatever. On desktop we used to call this kind of applications "spyware", frown upon them and let antivirus software block those on sight. On tablets, this is a norm of life.