Android 11 is taking away the camera picker, forcing use of the built-in camera
androidpolice.com
androidpolice.com
I’m also not immediately seeing a non-privacy reason to make this change either...
This change does not improve privacy, and may even reduce privacy by preventing the user from switching to a free and open source camera app, assuming that the stock camera app is proprietary.
A Google search for "malicious camera apps" leads to this from January https://cybernews.com/security/popular-camera-apps-steal-dat...
Copy-paste of its summary of the top 30 "beauty camera" apps:
> More than half (16) of these apps are based in Hong Kong or China
> One app doesn’t ask for permission to use your camera, but turns the camera on anyways – without any permission
> Three seemingly separate developers seem to be run by the same group, and may be connected to apps previously found to contain a widely-dispersed Trojan
> The top-ranked app developer Meitu, with more than 300 million installs, had apps identified as malware, violating Google’s ad policies, or secretly collecting data
> One app developer was found to install malware through its software
> One app was accused of sending users pornographic content, redirecting them to phishing sites, or collecting their pictures
> These apps are requesting up to 7 dangerous permissions, 5 on average, most of which are unnecessary for the app to function
> Unnecessary permissions include recording audio, using GPS, and seeing users’ phone statuses
> While only a few permissions are required for the app function, one app includes a whopping 40 total permissions
* The default camera app always takes a photo from the front or back camera
* Custom apps might return a photo from a usb camera, a remote camera, a file or a webpage. Exif data could be faked too.
* The 'security issue' is therefore that apps that ask the user to take a photo to prove something (for example, taking a photo of your passport to prove who you are, taking a photo of a QR code in a shop, etc) cannot have the assurance they want that the photo was just taken.
Discuss!
"The documentation advises explicitly checking for installed camera apps by their package names — meaning developers would have to pick preferred apps up front — and sending users to those apps directly. Of course, there are other ways to get options without identifying all package names, like getting a list of all apps and then manually searching for intent filters, but this seems like an over-complication."
For example, banning Gab is egregious and unacceptable under my framework.