Live data from Hacker News

Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

eff.org

131–140 of 207 posts

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#131
post #94

Earlier quoted context omitted.

I think the article is a tad misleading here, and I think your first link is going to add to the confusion. The ability to revoke permissions was built right into the System Settings app, but the ability to access it was hidden from view. Custom roms would usually add a link to it, and apps like AppOps by ColorTiger (your first link) was simply a pointer that would trigger that view to activate (I'm glossing over the…

The pointer has been dereferenced, if you will. I do not think dereferenced means what you think it means.

Holy shit, I feel like an idiot. Still, thanks for pointing it out.. keeps me humble.

Kids, if you're curious what we're talking about, look up dangling pointers in C, which is what I should have 'referenced' in the first place.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#132

Earlier quoted context omitted.

Right on, right on. While I like the potential of this app, the millions of devices with billions of applications that would simply stopping working with its introduction mean it will need a carefully orchestrated rollout. HN readers might be comfortable with "ever beta" technologies, but the other 99% of users are not (and it's odd that smart people fail to appreciate this).

"billions of applications that would simply stopping working". So what? The user can just re-enable the app's access to whatever it was trying to fetch. I don't buy the "millions of apps simply stop working" line. If the apps stops working because it was blocked trying to access my address book, then the app developer should have done better to expect the unexpected when fetching anything from outside the application…

The point is not to protect apps that are overreaching, by intent or just sloppy permissions, but to reduce the chance of unexpected behaviour to the customer (or if you're tinfoil hat , "the product").

The implementation on the part of the developer may be tiny, but you still have to have give those companies time to make and test the changes. Look what happens when companies move the Send button or whatever on their UI-- I tidal wave of internet bile comes rolling in. An app developer might appreciate a heads up before deluging their inbox/tracker with complaints and 1 star reviews.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#133

There is another point here, one I think even more important and more disconcerting. Google released an entire feature of their Android OS BY ACCIDENT. W...T...F?! How do you release a feature "by accident?" By having awful quality control? How does that make me feel about the rest of their Android OS now? Either this, or they're lying through their teeth in an effort to cover up. In either case, it's evil.

From the comments, it sounds like the preference pane was hidden and had to be enabled by installing 3rd party software. Having experimental features in software that are hidden (but included for testing in limited situations) is not surprising, nor WTF worthy.

This is exactly the case. Someone noticed it somehow (source / activities dump, I forget) and figured out how to launch it. And last I saw it wasn't actually removed, it just had stronger permissions on what was allowed to launch it, which broke all existing launchers. There may or may not be a new way to launch it.

Meanwhile, the source code keeps moving more and more towards having a real runtime-permissions-manager. Honestly I think they'll have something soon, but probably not before 4.5 or 5.0. In the meantime, I've been loving XPrivacy, it's probably more granular than anything they would release anyway (and I've had exceedingly few crashes, blocked data is faked not broken).

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#134
post #96

Earlier quoted context omitted.

My only complaint is iOS apps know if the permission is denied, so every time you switch to them they can ask you to enable permissions which is annoying (Facebook messenger). I wish they just returned no data.

That might work for contacts, but what does it mean to "return no data" for location services or bluetooth? In those cases isn't "no data" indistinguishable from "disallowed permission"?

"Couldn't get fix" and "no devices found", respectively?

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#135
post #5

Earlier quoted context omitted.

every time I open facebook messanger with gps enabled, I see it querying my location. I hate it so much. Would love to be able to turn that off

Have you tried not opening it? Seriously, if you use any of facebooks stuff, you clearly value something they offer more than your privacy. Everybody, and I'm not just talking about the HN crowd, knows how bad Facebook is when it comes to privacy.

This is the sort of sad comment that continually amazes me. Facebook is am important part of the social life of millions (billions?) of people. It isn't feasible to go away from it. It's completely reasonable to have a requirement to use Facebook while not wanting it to be an ass about stuff like constant GPS fixes.

Yeah, sure, don't use Facebook. You're the guy who butts into conversations to tell everyone how you don't own a TV, aren't'cha?

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#136
post #72

Earlier quoted context omitted.

I'm not sure how things have changed yet either, and I certainly think Device Tree is an important step forward from each and every board having its own (mostly identical) code in the kernel tree. But you do still need the dts, so while it makes device support easier, it doesn't solve the problem of discoverable hardware and you still need board specs etc, either from the original manufacturer or reverse engineered.

So the next step is convincing manufacturers to put the .dts at a predictable location on a small flash or EEPROM.

I wish you the best of luck in convincing MS to make it easier to install linux on their phones, and convincing embedded system builders to spend extra on hardware.

Either way, I was talking about what we have now, and even if we have device tree now it doesn't solve this problem without other pieces to the puzzle. And that's without even getting on to the mess of closed source graphics drivers that exist in the arm world.

Please don't think I'm trying to say we can't have a situation like the OP wants, I'm just trying to explain why we don't.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#137

> When asked for comment, Google told us that the feature had only ever been released by accident — that it was experimental, and that it could break some of the apps policed by it. Oh, it would definitely break some apps. Considering it would introduce new uncertainty. It's still an amazing feature.

Yeah, because checking return codes and error values is overrated Thanks Google, for making my phone less secure .

By allowing you to install software they make your phone less secure. Better buy a feature phone ASAP!

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#138

I'm probably going to turn in to that old guy with tin foil who can't play any games because nobody supports his choice of platform, but I really miss when computers were devices you could buy and then put your choice of OS on. Phones are pretty much just little ARM computers, why the hell don't I just install Ubuntu, Firefox OS, Android, WinPhone, Symbian, whatever? I could format a microSD card to boot from and go…

Re. proper keyboards - the market says otherwise. There have been plenty of Android phones with hard keyboards but they've not sold in sufficient quantities to make it attractive. If there was a market for it, people would be making them, if you disagree with that they what are you doing on here, your fortune awaits... Also worth seeing kids who've never used a physical keyboard to any great extent. I've seen them do…

> If there was a market for it, people would be making them, if you disagree with that they what are you doing on here, your fortune awaits...

This is incredibly disingenuous because of the high barrier to entry on cellphone manufacturing.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#139
post #110

Earlier quoted context omitted.

Stupidity and malice are frequently indistinguishable by an outside observer.

All the more reason to pause before ascribing malice as the motive.

I don't know. Personally, I would rather be regarded as evil than stupid.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#140

Earlier quoted context omitted.

Right on, right on. While I like the potential of this app, the millions of devices with billions of applications that would simply stopping working with its introduction mean it will need a carefully orchestrated rollout. HN readers might be comfortable with "ever beta" technologies, but the other 99% of users are not (and it's odd that smart people fail to appreciate this).

"billions of applications that would simply stopping working". So what? The user can just re-enable the app's access to whatever it was trying to fetch. I don't buy the "millions of apps simply stop working" line. If the apps stops working because it was blocked trying to access my address book, then the app developer should have done better to expect the unexpected when fetching anything from outside the application…

No, because people coded to the API they were given. They got permission through the application's manifest, as specified by the documentation. They coded to standards. Dynamically revoking permissions breaks that contract.

It sounds like you are more familiar with web frontend programming. I'd caution you that Android app development has differences that are important to this discussion.

Post reply on HN