Live data from Hacker News

Wikipedia Android app now requests identity permissions

plus.google.com

31–40 of 43 posts

Re: Wikipedia Android app now requests identity permissions

#31
post #2

This reads to me as an overreaction. Sure, it's important to be vigilant about the permissions you give apps, but it's also important to understand the underlying OS and permission layers. TLDR: If you're concerned about your privacy, upgrade to Android 6.0 There's nothing wrong with Wikipedia letting you manage your Wikipedia account using the app. They're using the Account Manager API, which is the right way to app…

Does Android 6.0 let you feed fake data to apps requesting useless permissions?

Re: Wikipedia Android app now requests identity permissions

#32
post #2

This reads to me as an overreaction. Sure, it's important to be vigilant about the permissions you give apps, but it's also important to understand the underlying OS and permission layers. TLDR: If you're concerned about your privacy, upgrade to Android 6.0 There's nothing wrong with Wikipedia letting you manage your Wikipedia account using the app. They're using the Account Manager API, which is the right way to app…

TL;DR: Many Android devices don't have the option for arbitrarily upgrading at the user's option. You're limited to OS updates if and when your vendor can be arsed to get around to it. The versions of Android on which this permission are required are precisely those on which it's a security issue. Ergo: don't use the permission. Wikipedia's app describes what their intent is. Last time I checked, a large number of so…

> Last I checked, Google had registered something over 3 billion Android user identities. Relying on that large a population to 1) trust individual software authors with 2) no specific code of conduct or review process and 3) have a high level of familiarity with permissions systems, architectures, and peculiarities of specific releases strikes me as a good working definition of "unreasonable expectations".

What would the alternatives be (given 3 billion user identities)?

Re: Wikipedia Android app now requests identity permissions

#33
post #31
post #2

This reads to me as an overreaction. Sure, it's important to be vigilant about the permissions you give apps, but it's also important to understand the underlying OS and permission layers. TLDR: If you're concerned about your privacy, upgrade to Android 6.0 There's nothing wrong with Wikipedia letting you manage your Wikipedia account using the app. They're using the Account Manager API, which is the right way to app…

Does Android 6.0 let you feed fake data to apps requesting useless permissions?

For legacy apps (that lived in a time before per-permission user-controlled configuration), yes. http://arstechnica.com/gadgets/2015/10/android-6-0-marshmall...

I don't know that it lets you tune what fake data is fed; the intent of the feature seems to be to make it possible for legacy apps to run in M at all, not to fuzz the metrics an app author might be collecting.

Re: Wikipedia Android app now requests identity permissions

#34
post #17

Earlier quoted context omitted.

Less than 5% of phones currently run Android 6.x. I don't really think that's a fair "requirement" to give to people, given that many people are otherwise prevented from getting a Marshmallow update not because of the age or model of their phones, but because the carrier has prevented it.

It has nothing to do with fairness. The Android permission model prior to 6.0 was terrible. If you care about this stuff, then you'll want to use 6.0 or newer (or a non-Android phone with similar capabilities). It may not be fair that the phone you bought recently can't upgrade to 6.0 because Android OEMs are terrible, but the facts remain.

Besides, if you really care about this stuff, you bite the bullet, root your phone, and install an alternate OS that allows for permission faking and more graunular control.

As much as people on HN seem to hate to admit it, the average consumer does not care sufficiently (or have enough to hide) for the ability to do fine-grained permission control to be valuable to them, so it's a niche feature. Most apps from big vendors can be trusted; the maximum-harm case isn't the common case. On the plus side, in a couple years (when the average Android comes with M pre-installed), users will have the ability to do fine-grained control whether or not they care. That's an improvement.

Re: Wikipedia Android app now requests identity permissions

#35
post #7

Earlier quoted context omitted.

Less than 5% of phones currently run Android 6.x. I don't really think that's a fair "requirement" to give to people, given that many people are otherwise prevented from getting a Marshmallow update not because of the age or model of their phones, but because the carrier has prevented it.

then we get into the whole "at what point do we stop supporting windows xp for real this time guys" argument though..

That decision is generally made by the app vendor. Apps in the Play Store declare a minimum OS version they compile / run against.

Re: Wikipedia Android app now requests identity permissions

#36

Earlier quoted context omitted.

TL;DR: Many Android devices don't have the option for arbitrarily upgrading at the user's option. You're limited to OS updates if and when your vendor can be arsed to get around to it. The versions of Android on which this permission are required are precisely those on which it's a security issue. Ergo: don't use the permission. Wikipedia's app describes what their intent is. Last time I checked, a large number of so…

> Last I checked, Google had registered something over 3 billion Android user identities. Relying on that large a population to 1) trust individual software authors with 2) no specific code of conduct or review process and 3) have a high level of familiarity with permissions systems, architectures, and peculiarities of specific releases strikes me as a good working definition of "unreasonable expectations". What woul…

A system far more like Debian's in terms of app development/provisioning, and user-centric protections.

A dev-compensation system not dependent on advertising.

https://plus.google.com/104092656004159577193/posts/2eg1rG6k...

Re: Wikipedia Android app now requests identity permissions

#37

Why not just use the Wikipedia website?

Last time I used the app it didn't support 'Find in page' or pinching to zoom. The web site is great and just works for what I want to use it for. The only thing that's annoying is that when sections of the article are collapsed 'Find in page' doesn't work (which is obvious, but annoying).

Wikipedia's mobile site really is a usability disaster, with low-density tables and most of the content hidden by default. I've always had to scroll down and switch to Desktop to do any serious reading. It's as if the interface was designed for the first-gen iPhone, and subsequently abandoned.

At one point, pages had a "Permanently disable mobile site" link at the bottom, but they scrapped that back in 2012.

Re: Wikipedia Android app now requests identity permissions

#38

Earlier quoted context omitted.

> Last I checked, Google had registered something over 3 billion Android user identities. Relying on that large a population to 1) trust individual software authors with 2) no specific code of conduct or review process and 3) have a high level of familiarity with permissions systems, architectures, and peculiarities of specific releases strikes me as a good working definition of "unreasonable expectations". What woul…

A system far more like Debian's in terms of app development/provisioning, and user-centric protections. A dev-compensation system not dependent on advertising. https://plus.google.com/104092656004159577193/posts/2eg1rG6k...

Sorry to say: Debian's has advantages, but is a pain in the ass. The focus on security and reliability in packages means both stable and unstable tend to be so far behind head that I rarely find things I want to try are directly supported by the available binaries. Which is not to say Debian's approach is bad for its purposes; I just wouldn't want to use a smartphone app ecosystem designed like that.

Advertising is trickier to wrestle down. I'm not sure in an ecosystem where advertising is allowed, a race to the bottom isn't to be expected, and best of luck banning it entirely.

Re: Wikipedia Android app now requests identity permissions

#39

Earlier quoted context omitted.

A system far more like Debian's in terms of app development/provisioning, and user-centric protections. A dev-compensation system not dependent on advertising. https://plus.google.com/104092656004159577193/posts/2eg1rG6k...

Sorry to say: Debian's has advantages, but is a pain in the ass. The focus on security and reliability in packages means both stable and unstable tend to be so far behind head that I rarely find things I want to try are directly supported by the available binaries. Which is not to say Debian's approach is bad for its purposes; I just wouldn't want to use a smartphone app ecosystem designed like that. Advertising is t…

Rather than respond to what you think I might have written, how about actually reading the suggestion and responding to its points. This would be more valuable to both of us.

Re: Wikipedia Android app now requests identity permissions

#40

Earlier quoted context omitted.

Sorry to say: Debian's has advantages, but is a pain in the ass. The focus on security and reliability in packages means both stable and unstable tend to be so far behind head that I rarely find things I want to try are directly supported by the available binaries. Which is not to say Debian's approach is bad for its purposes; I just wouldn't want to use a smartphone app ecosystem designed like that. Advertising is t…

Rather than respond to what you think I might have written, how about actually reading the suggestion and responding to its points. This would be more valuable to both of us.

People only ever respond to what they think other people have written; such is the nature of communication.

If you mean respond to the multi-paragraph G+ post: too many pieces to dedicate time to at this juncture. I misunderstood what you meant by the Debian model "in terms of app development" to refer to package creation / maintenance approach. If you mean these three elements:

Putting user interests first

Seeing specific limitations on app capabilities

Promoting Free Software in all possible cases

... Then I think from Google's standpoint, it's probably understood that they are covering #1 already (item 1 in https://www.google.com/about/company/philosophy/), #2 ought to be covered by M's security model, and #3 is a bit of a non-starter for a commercially viable app store (though Android certainly doesn't preclude it, as evidenced by F-Droid and other alternate app stores).

Post reply on HN