Good. Now, if only permissions could be granted temporarily (e.g. "allow for this session", which auto-revokes after 5-60 minutes of not using the application), it'll be perfect.
> We will also enable encryption of Android backups with a client-side secret.
Is this about BackupManager? Awesome if so. (BTW, have anyone ever heard of any alternative BackupTransports, besides Google Drive?)
> Android P also gives the user control over access to the platform's build.serial identifier by putting it behind the READ_PHONE_STATE permission.
IMHO, they should've really split that in two different permissions and deprecate READ_PHONE_STATE. Device identifiers (including SIM card identities) and phone state ("someone's calling") are two different things.