Live data from Hacker News

Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

eff.org

191–200 of 207 posts

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#191

Earlier quoted context omitted.

"billions of applications that would simply stopping working". So what? The user can just re-enable the app's access to whatever it was trying to fetch. I don't buy the "millions of apps simply stop working" line. If the apps stops working because it was blocked trying to access my address book, then the app developer should have done better to expect the unexpected when fetching anything from outside the application…

No, because people coded to the API they were given. They got permission through the application's manifest, as specified by the documentation. They coded to standards. Dynamically revoking permissions breaks that contract. It sounds like you are more familiar with web frontend programming. I'd caution you that Android app development has differences that are important to this discussion.

>> "Dynamically revoking permissions breaks that contract."

While I'm no expert in native app dev, it's interesting to see so many people are so confident the apps will break under those circumstances, without actually any first hand experience.

I would likewise caution anyone putting forward this idea, that unless you've seen the effect revoking permissions has had on your app, or another app, then anything you put forward in this discussion is hearsay.

I'm not jumping on the meme train about millions of apps crashing due to permission revoking. Google should just include the feature, and have it default to off, with appropriate warnings about tripping some apps when switched on. It doesn't need to be a complicated thing.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#192

Earlier quoted context omitted.

Stupidity and malice are frequently indistinguishable by an outside observer.

Hmmmmmmm, perhaps, but I'd suggest that: Stupidity is negligence. Negligence is selfish. That makes it malicious. Its willful which ever way one chose to spin it. IMHO, such phrases are not much different to ones like "what do you have to hide?". They are designed to look like one thing, confuse and win a point, while hiding the fact that something appalling is going on. Its the language of confusion to control. Its…

Stupidity is negligence.

False, in general. If you want to assert someone is using stupidity as a cover, you need evidence. I don't believe that should be the default hypothesis.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#193
post #14

If you have root you can still enable it with market apps.[0][1] However something like this needs to be integrated tightly like iOS and apps need to be aware they may not receive requested permissions. I still use App Ops in Kit Kat and it silently breaks apps all the time. Apps expect to be able request information (e.g. contact details) and crash or stall when they can't. In that respect, LBE Privacy Guard[2] was…

You don't need root for that first app! I've been using it just fine without root. The description tells you what extra features you get with root, but you can handle the privacy issue without.

Yes you do need root for that first app if you have android 4.4.2 - which is what the whole discussion is about.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#194

This is one area where iOS stands head and shoulders above Android. I used to run Cyanogenmod and I remember deciding to not upgrade the Facebook app because doing so would have required giving it a slew of permissions, including the ability to "directly call phone numbers". By contrast, in iOS, I can choose which apps have access to my location, contacts, etc. I know that Apple's track record when it comes to privac…

Do not expect Google to implement it anytime soon, due to the massive app breakage potential. Android's permission system looks good on the surface. However, there are so many required permissons nowadays that many users do not even check them anymore. And you can revoke specific permissions on an app by app basis. On iOS, developers are told not to rely on certain permissions being available, such as location. Some…

This is somewhere where android fragmentation is truly an issue. iOS didn't have granular switchable permissions a couple of versions ago but as the OS moved forward so did the apps.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#195
post #14

If you have root you can still enable it with market apps.[0][1] However something like this needs to be integrated tightly like iOS and apps need to be aware they may not receive requested permissions. I still use App Ops in Kit Kat and it silently breaks apps all the time. Apps expect to be able request information (e.g. contact details) and crash or stall when they can't. In that respect, LBE Privacy Guard[2] was…

XPrivacy (FLOSS, uses Xposed framework, mostly fakes data instead of cancelling access, if possible) works for me: http://forum.xda-developers.com/showthread.php?t=2320783

It has some rough edges like asking me to check permissions after every (auto)update, even if app hadn't requested any new permissions, but allows relatively fine-grained (API function-name-level) permission control. Root permissions are only required to install Xposed, after Dalvik's runtime's hooked no root's required.

Oh, and "pro" features are useless (you can just build your own version from GitHub sources to enable export, and sharing is completely awkward without any UI to see what happened), but I still donated. Disclaimer: I have no affiliation to this project other than using it on my phone.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#196
post #75

Earlier quoted context omitted.

> Whatever, fuck Google. Well this is going to be productive. I'm pretty sure Google isn't out to put all of its users through a meat grinder. For one thing people have been way off the handle about Google touching anything. At all. This article only mentions an accident that lasted one day. So it's "fuck Google" after everything, still, again I guess.

Right on, right on. While I like the potential of this app, the millions of devices with billions of applications that would simply stopping working with its introduction mean it will need a carefully orchestrated rollout. HN readers might be comfortable with "ever beta" technologies, but the other 99% of users are not (and it's odd that smart people fail to appreciate this).

> millions of devices with billions of applications that would simply stopping working

[citation needed]

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#197

Earlier quoted context omitted.

How would anyone know it was not official until Google said it wasn't meant to be released?

What sort of official feature is hidden and can't be accessed via any user interface provided by the vendor?

What sort of "we never meant to release this" feature would get merged into stable tree and even get into the production builds that get shipped on the actual retail hardware?

I thought if feature's meant to be solely experimental it'd just sit in a separate feature branch.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#198
I have to admit, the EFF has just lost a chunk of support from me over this. Google never released this feature - you needed to install some 3rd party app to expose the settings, this alone is enough for anyone of any intelligence to know they are doing something not intended for the general public.

Seriously EFF, get your act together please. I do want to support you, but not like this.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#199
post #169

Earlier quoted context omitted.

Re. proper keyboards - the market says otherwise. There have been plenty of Android phones with hard keyboards but they've not sold in sufficient quantities to make it attractive. If there was a market for it, people would be making them, if you disagree with that they what are you doing on here, your fortune awaits... Also worth seeing kids who've never used a physical keyboard to any great extent. I've seen them do…

> There have been plenty of Android phones with hard keyboards but they've not sold in sufficient quantities to make it attractive. They haven't sold because they've sucked. They had low-quality displays, crappy software, slow SoCs, and barely enough memory to be usable. The only keyboard phone left is BlackBerry, and that's not selling, well, because it's a BlackBerry. There is a huge market for regular keyboard cel…

Funny enough, the best keyboard on an Android device that I ever used wasn't even an Android device. I had an HTC Touch Pro 2 (Windows Mobile 6.5) that could be cajoled into running Android, and typing on it was a _joyous_ experience. Sadly it finally died, and besides that it was getting to be ludicrously out of date.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#200

Earlier quoted context omitted.

If you put software into the wild - you have released it. Just because the cycle has sped up, you didn't document it properly, and your QA failed, does not mean you didn't release it. I'm not taking sides here, but you have to call a spade a spade.

> If you put software into the wild - you have released it. Even by that definition Google never released it. You needed a 3rd party app to access the feature, Google's software alone was not enough. Google didn't fail here, they flat out never released it. Or perhaps you could argue that they failed by not releasing it (or something similar), but that's different story.

So they released an unsupported publicly accessible API?
Post reply on HN