Of all the things to not copy from iOS, of course privacy is the one that they decide to skimp out on. I'm glad they've started to catch up, but they have a ways to go yet.
Of all the things to not copy from iOS, of course privacy is the one that they decide to skimp out on. I'm glad they've started to catch up, but they have a ways to go yet.
Annoyingly I now need to "Request Desktop Site" to use messenger or else it tries to get me to install the app. The artificial friction they're put in place has pushed me ever closer to just deleting my account.
Unless you can audit the code, or someone you trust has, who knows what our devices are doing.
Or you can do it the way FB does it, by asking for permission to access all your pictures and build your own non-standard picker...
Because ultimately, developers don't really need to care. Too many users don't understand the implications at all. And if it's for example a messenger that all your friends use, you don't really have much of a choice than to trust it, if you want to talk to your friends.
http://www.plash.beasts.org/powerbox.html
Note: I'm using this link just to explain the concept rather than endorse anything on the site. It was top of Google results.
Don't you have your friends in a private contacts list/address book? Isn't it trivial to send a photo attached to an email? What is the problem?
Note: I do not and never have used facebook, genuinely don't understand what the deal is here.
The functionality is no different to iMessage. I don’t know why this happens. It just does.
With email, you have to explicitly select recipients. You're essentially saying "here are my photos, I think they are relevant to you specifically". The onus is on the sender to figure out what's good for the receiver, and it's considered rude to send many frivolous or irrelevant messages. Think of how you grumble when you unsubscribe from some company's mailing list - this is an example of this social norm.
With Facebook, you say "my photos are here, anyone may look at them if they want". Figuring out whether the content is relevant is now the job of the receiver, not the sender. Facebook's UI is well aligned with this role: unlike email, where you must explicitly download attachments and mark messages as read, on Fb image previews are displayed inline and to never see a message again you must only scroll past it. Advertisements aren't considered intrusive, it's just content from another source that is (in theory) just as easy to ignore. The social dynamic is very different, and so it's used to send a different sort of message than email.
Edit: ok maybe around 40, not 75. But point still stands, it’s indirect communication rather than remembering about that cousin of an auntie’s grandparent’s nephew’s sister-in-law that I met ten years ago.
Custom ROMs unfortunately can't really do much to implement the latter, they'd have to break compatibility with the whole Android ecosystem, which Google knowingly built this way.
The problem is that not many users understand the implications of just granting permission, so developers don't really need to care.
And this dialog that Android opens is roundabout the shittiest, least usable piece of software I've seen in a long while, so for an developer it actually can pay off to ask for full permission and then build your own file selector even if you have no malicious intentions.
Others here have mentioned that iOS also supports basically this the same way as Android, though presumably they have not quite managed to make their file picker quite as shitty.
And then, well, browsers have worked like this since forever. So, presumably Firefox OS works/-ed like this, too.
I do agree it would be nice to have “Just once” on pretty much every permission dialog. Apple’s change to mandate an “Only while using the app” on location info after Uber’s location tracking fiasco was a good step in this direction.
Instead, apps that want to steal your pictures request access to all of them.
Side note, there was also a project at one point to create Web Intents. I wonder what the web would be like if that had worked out.
But yes! It exists, and most applications could pretty easily use it instead.
But most of it seems to be laziness / misunderstanding. And Android's broadly terrible documentation does not help this at all. E.g. a huge number of apps that want external storage permissions just use it to store external caches outside your system partition, which is very nice for people with an SD card / limited internal space. Many companies don't seem aware that this no longer requires any permissions though - you can store internal and external data in your app-sandboxed folders by default.
If you don't request camera permission, you can still open the camera with an intent. This is great!
If you do request camera permission, and you are denied, you can't use that intent either. https://blog.egorand.me/taking-photos-not-so-simply-how-i-go...
I honestly can't tell if it's this way to be intentionally hostile to users, or by accident, or if they honestly think this is a positive quality.
Usually I hate the in-app cameras, because they're not optimized for my device. They're usually slower, have no flash control, no zoom, no manual exposure options, etc. I'd almost always prefer to use a dedicated camera app instead.
Because of this permissions decision, if an app wants to bake in a camera thing (nearly every app that might ever touch the camera does, even if e.g. only for a QR code reader or something), I can no longer choose. The app can't open my camera app when it makes sense.
That appeared in 4.3, hardly accessible. Was made somewhat more accessible in 4.4 and then was patched out in something like 4.4.1 or so. I presume, some Google exec got to know of it and demanded it removed.
Starting with Android 6, there's the new permission model, meaning that a similar screen is added to the settings of each app, but it doesn't show when an access happened (or at least it does not for me on Android 8.1).
If you don't know why it's illegal: WhatsApp uploads all of your contacts to their server. Granted that their ToS are not themselves ruled illegal at some point, it is on you to get a written permission from all of your contacts that they are okay with you uploading their data to WhatsApp's servers.
So, unless you block access to all of your contacts or actually ask every single one of your contacts for written permission, it's illegal. With selective contact access, you could at least attempt to only grant access to contacts that you actually did get written permission from, or I don't know, of which you know for sure that they are using WhatsApp, too.
And yes, I do love the thought of hitting on someone in a bar and then pulling out this massive form sheet to ask for their written permission, just so you can ask for their number afterwards.
In your example, this sounds silly, but it's just not categorically different from examples where it doesn't, like say someone who stalks me asks you for my phone number, or a scam caller does.
Is some person a person I want to talk to?
Do you not know and are just hoping for the best without asking me?
Never installed the facebook app on any of my phones (In the odd event I REALLY need to check a cat picture on facebook, I use the browser version). Glad I went that route.
Now though I got a Samsung phone that has the facebook app preinstalled, but I never opened it (and all the other preinstalled apps DONT have the permissions on by default...so I hope it's true of the FB app too)
By pre-installed I mean impossible to uninstall without rooting and flashing a different ROM.
The only difference is the you don't get your space back since preinstalled apps occupy a different partition, but the app itself cannot run in any way.
AFAIK Android's current permission system is very similar to iOS's one with granular permissions granted at runtime for camera, contacts, etc.