Live data from Hacker News

Google announces Android for Work

googleforwork.blogspot.com

41–50 of 174 posts

Re: Google announces Android for Work

#41

> a dedicated work profile that isolates and protects work data Oh wow, can this be used to just create a separate profile for every app? That way I can run Uber or Line without giving them every permission to everything? This is the biggest reason I do not install apps. Every "famous" app requests so many permissions it's just stupid. And not to mention the weirdness of some of them, like "WiFi Device Information".…

Isn't there an app that restricts these permissions? I believe your phone has to be rooted for it to work though.

Yeah, but I have a Huawei Mate 2, which, last I looked, had some really obscure rooting instructions. Most steps consisted "download this random exe and give it admin permissions". Plus you have to email Huawei and ask nicely for the bootloader unlock code.

And, rooting doesn't help the majority of users. Whereas protection from spying would. But Google, perhaps accidentally, seems intent on making permissions less visible and has no problem with devs requesting every permission. And since so many major apps do this, users have no effective recourse.

MS and Apple got this one so much more right.

Re: Google announces Android for Work

#42
post #31

I suggest that anyone considering sharing a personal device with work activity (other than basic phone calls and messaging, e.g. "I'll be in late") think twice. Comes a security concern or conflict, someone's probably going to want access to the whole thing. If you want me to do "your work" on a phone -- particularly as an employee as opposed to as an independent contractor utilizing their own resources as defined in…

Would secure-wiping the phone if involved in a legal discovery process be considered destruction of evidence? Does your advice apply when you're only using, say Exchange, as your only entry point (e.g. on iOS devices?) - in this case, all discovery can be done server-side. I find it hard pressed to think this issue hasn't been covered more rigorously.

Part of my argument is that, when you as an individual are on one end of an argument about this with a substantial business/corporation and/or the government, you are going to have a rather difficult time, regardless of what is "right" and "lawful".

Better to be able to hand the device over and say, "Have at it."

Also, if there is some breach of security and a question about whether you facilitated it, through activity or through negligence, better to be able to say/demonstrate to the other party: "It's the organization's device, and the organization's / the organization's IT department's responsibility to maintain it."

Re: Google announces Android for Work

#43

Earlier quoted context omitted.

CyanogenMod's Privacy Guard is useful for dealing with this situation. There is a setting to enable it by default on newly installed apps. No matter what permissions the app says it requires, you are prompted when it actually requests them and can deny them at will or permanently.

When you deny them, roughly how often in your experience does this cause the app to crash or display an error?

I think it can return valid data, like empty sets or fake data. So apps shouldn't crash at all.

Re: Google announces Android for Work

#44

I suggest that anyone considering sharing a personal device with work activity (other than basic phone calls and messaging, e.g. "I'll be in late") think twice. Comes a security concern or conflict, someone's probably going to want access to the whole thing. If you want me to do "your work" on a phone -- particularly as an employee as opposed to as an independent contractor utilizing their own resources as defined in…

I'm a stickler about this. Beyond answering the odd phone call or message, I have a hard time seeing it as anything but the company unfairly attempting to externalize costs onto their employees.

Just like you give me a work computer to do work related tasks on, the same should go for mobile devices.

My employer used to be rather liberal but recently started clamping down on security. They wanted us communicating in the company chat on our phones so we installed the chat app. But now with the security clamp down they want to set security requirements on anything that accesses potentially sensitive information, meaning they want to dictate the security policy used on our personal devices. I told them to go stuff it, if its a choice between no work stuff on my phone and letting them set the policy on my devices, I'll go without access to work stuff. I'm not going to play that game with you, yes I'm willing to be That Guy that takes a stand on this.

The real irony is that my security policy at home is more strict than the one at work, but they conflict somewhat and I'm not willing to reduce my home security to accommodate them.

Re: Google announces Android for Work

#45

Earlier quoted context omitted.

CyanogenMod's Privacy Guard is useful for dealing with this situation. There is a setting to enable it by default on newly installed apps. No matter what permissions the app says it requires, you are prompted when it actually requests them and can deny them at will or permanently.

When you deny them, roughly how often in your experience does this cause the app to crash or display an error?

In my experience, the apps I've used don't crash. The biggest problem I've seen is me getting frustrated with an app for not working as advertised. Then I remember that I've enabled privacy guard and the app must not be getting some info it needs from the OS.

Re: Google announces Android for Work

#46

> a dedicated work profile that isolates and protects work data Oh wow, can this be used to just create a separate profile for every app? That way I can run Uber or Line without giving them every permission to everything? This is the biggest reason I do not install apps. Every "famous" app requests so many permissions it's just stupid. And not to mention the weirdness of some of them, like "WiFi Device Information".…

CyanogenMod's Privacy Guard is useful for dealing with this situation. There is a setting to enable it by default on newly installed apps. No matter what permissions the app says it requires, you are prompted when it actually requests them and can deny them at will or permanently.

Wow, just like iOS.

Re: Google announces Android for Work

#47
post #6

I love the name "Google Play for Work."

"Google Play for Work" is as bad as "Playstation" is good. They really shouldn't let this awkward branding stuff happen.

I worked on Windows Live Mobile for Windows Mobile. Thankfully it was renamed.

Re: Google announces Android for Work

#49
post #27
post #14

Earlier quoted context omitted.

Actually that's the reason I use iOS

I honestly don't understand why this is down-voted, more "sandboxed" apps is one of the reasons I use iOS as well.

Just for the sake of clarity, do you mean that there are more apps that are sandboxed on iOS or that all apps have a higher level of sandboxing on iOS?

Re: Google announces Android for Work

#50
post #37

Earlier quoted context omitted.

Not if it is encrypted.

If your device is rooted, and by that I mean real rooted (bypassing SELinux), then it can get the encryption keys as at some point the data needs to be decrypted and viewable by you.

No you'd still need the crypt key to decode the data. Why do you assume this is stored on the device?
Post reply on HN