Live data from Hacker News

We can't check the app permissions on Google Play anymore

bluespace.tech

81–90 of 121 posts

Re: We can't check the app permissions on Google Play anymore

#81

Earlier quoted context omitted.

> Don't apps prompt when they access things now? For some permissions, but not all of them. For example, they don't for Internet access. > Why must I say no to this every time I open the app? Doesn't Android have a "don't ask again" option for permissions?

> For some permissions, but not all of them. For example, they don't for Internet access. Then why does this "Permission" exist? When will it ever be false?

Because if an APK doesn't declare that permission, then it still can't access the Internet.

Re: We can't check the app permissions on Google Play anymore

#82

Earlier quoted context omitted.

Not presented in the App Store; both android and iOS still have a permission system, but you need to download the app before you can see what permissions the app has asked for.

In iOS you see what permissions are requested when the app needs them and, you know, requests them from you with a dialog. That seems good enough?

The issue at hand is seeing what permissions the app wants before you download it, in the App Store

Re: We can't check the app permissions on Google Play anymore

#83
post #57

Earlier quoted context omitted.

In the example of Kakao, it lists the contacts permission as optional and the app will install and open without it. But it won't let you past a nag screen without it first verifying that you have given it access to your contacts. Really anything involving personal data should be up to the user. Especially something like your contacts.

As much as I have a problem with Apple’s monopolistic control over the App Store, one benefit is that behaviour like this doesn’t make it past review. I’d love to see a button on the contacts permission window to give the app a list of AI generated fake contacts. (And fake GPS coordinates, and so on). Philosophically, your phone should be your user agent. It should act on your behalf, not on behalf of some tech compa…

Xiaomi's newer phones do have this functionality, albeit in a rudimentary form (only empty list is returned so the app can still detect it given how few people have empty contacts).

Re: We can't check the app permissions on Google Play anymore

#84
post #47

The dynamic permissions are not a replacement. Some users would never even install apps that asked for too many static permissions on the Play page. But now, if an app seems to meet their needs and they aren't sure, some of them will go ahead and install it just to try it out. How much can one run hurt after all? Due to unresolved questions or sunk cost dilemmas, they may even grant dynamic permissions. How much can…

What they really need to do is to simulate data for permissions that are rejected. For example, if I reject location permissions, then play back a random GPS trail in a randomly selected city on the planet, complete with simulated error and drift. If I reject Wi-Fi scanning, then show a constantly changing set of fake access points. If I reject camera, then play back some cartoons or deepfaked video as a camera devic…

Fake user data is the kryptonite of surveillance capitalism. I just want my browser to click on everything all the time whether I’m there or not.

Re: We can't check the app permissions on Google Play anymore

#85
post #47

The dynamic permissions are not a replacement. Some users would never even install apps that asked for too many static permissions on the Play page. But now, if an app seems to meet their needs and they aren't sure, some of them will go ahead and install it just to try it out. How much can one run hurt after all? Due to unresolved questions or sunk cost dilemmas, they may even grant dynamic permissions. How much can…

What they really need to do is to simulate data for permissions that are rejected. For example, if I reject location permissions, then play back a random GPS trail in a randomly selected city on the planet, complete with simulated error and drift. If I reject Wi-Fi scanning, then show a constantly changing set of fake access points. If I reject camera, then play back some cartoons or deepfaked video as a camera devic…

If you do that, some users are going to land in a weird purgatory where they’ve denied camera permissions to their camera app or something, and be completely unsure of why the app is acting strangely or how to fix it

Re: We can't check the app permissions on Google Play anymore

#86

Earlier quoted context omitted.

This would be trivial to detect by the app and they would just block you anyway.

There's two ways Google could solve that: either make better fake data that isn't trivially detectable, or make a rule that trying to detect that gets your app banned from the store.

That would be a fun challenge: given access to all sensors except for the camera, write an app that creates fake camera data.

If Google worked on that, results could be fairly creepy for those who store their data in their cloud. They can probably infer what you look like from your photos (you’re the one appearing in selfies most), know what weather it is locally, know that you’re, for example, looking at the Eiffel Tower, and maybe even have a photo from 2 minutes ago made by another user from the same place.

I think Google certainly could make a fake address book that’s creepy for many users by looking at the address books they have.

Re: We can't check the app permissions on Google Play anymore

#88
post #48

What they really need to do is to simulate data for permissions that are rejected. For example, if I reject location permissions, then play back a random GPS trail in a randomly selected city on the planet, complete with simulated error and drift. If I reject Wi-Fi scanning, then show a constantly changing set of fake access points. If I reject camera, then play back some cartoons or deepfaked video as a camera devic…

This would be trivial to detect by the app and they would just block you anyway.

Detectable, maybe. Trivial, definitely not.

Re: We can't check the app permissions on Google Play anymore

#89

The dynamic permissions are not a replacement. Some users would never even install apps that asked for too many static permissions on the Play page. But now, if an app seems to meet their needs and they aren't sure, some of them will go ahead and install it just to try it out. How much can one run hurt after all? Due to unresolved questions or sunk cost dilemmas, they may even grant dynamic permissions. How much can…

> Some users would never even install apps that asked for too many static permissions on the Play page. This, so much! Like 90% of the apps on Play ask for an insanely excessive amount of permissions. It was the #1 indicator for sorting out garbage apps. Example: Some time ago I needed a kitchen timer app (stock one had some issue). The great majority of them wanted permissions like contacts, access to my files, GPS…

“and on top of it internet”

is internet a permission?

I've never seen that in any menu or prompt. I don't think Android has this. Which is a shame bc i mostly use offline apps and would love to know if an app is all offline

Understandably, I don't think Google cares about the offline use of their OS. It doesn't align with their business interests

Re: We can't check the app permissions on Google Play anymore

#90

It's unfortunate that regulators have largely overlooked privacy in smartphone apps amidst all the other concerns they have over such platforms.

The permissions list on the play store was completely useless from a privacy standpoint. Even power users could to just about nothing with the info. The situation now where you approve or reject permissions as they are used in the app is vastly better than the original android model of being shown a wall of text with the options to either give away all of your data and security or not install the app.

I remember the situation where Google used to bundle permissions in illogical ways. it's been too long to remember specifics but it essentially meant an app had to request the ability to access unnecessary things and required the dev to explain in the release notes as to why.
Post reply on HN