Mobile UX Design: Ways to Ask Users for Permissions
uxplanet.org
uxplanet.org
1. Given only the most basic of assurances (assuming an app tells you anything at all), you have to trust that some software you just downloaded is going to do exactly what it claims, and only what it claims.
2. By requiring the user to grant permission at a prompt, we are pretty much guaranteed to not ask questions very often and have coarse granularity. Apps can therefore count on easily gaining more access than they really need, rather than having to try really hard to work within serious limitations.
3. Data is rarely structured in a way that allows it to expire meaningfully. For instance, I cannot guarantee that an app has access to a particular contact for exactly 1 second while it transmits a message, and then “loses” that information; in reality, the app can probably upload my entire contacts database anywhere in the world and continue to do so for months at a time.
An example of a better model might be to force everything to go through the user and to require applications to sign their data. For instance, if an app wants to send my friend an E-mail, maybe they can’t: maybe they have to give me text that is signed by them, and then I send it, ensuring that the correct message is sent but that the E-mail address itself is not shared.
That email example might work in specific examples, but requiring the user to be a constant gatekeeper would get very tiresome quickly , particularly when it comes to things like GPS and Camera access.
Many apps choose not to use this functionality, because they want to own the UX for contact picking or taking a picture, and most users don't know about the privacy difference between sharing a Uri with a grant permission flag, and granting access to contacts.