PNC Bank app blocks access for “security reasons” if not allowed to scan files
storage.googleapis.com
storage.googleapis.com
The fact an app can essentially coerce you into accepting permissions "for your safety" is something that should be against Plays TOS and met with a swift banhammer.
It should also highlight how little control we have over these black boxes, when you grant permission, even for 5 minutes, you have no idea what directories it has accessed, if it's scanning for materials or hashes, sending data to a server etc. People moaned about Apple yet here the same thing could happen just by pressing "accept", the fact it's a banking app means you're more likely to accept. No idea how this is allowed to be honest.
This could also be a big problem if you have sensitive material on device and just allow any app to access files.
https://developer.android.com/about/versions/11/privacy/stor...
Asking for access to root directory is not allowed. Asking for access to "Downloads" or app-specific external directories is not allowed either.
There is an escape hatch:
https://www.xda-developers.com/google-file-manager-devs-subm...
but it is intended for dedicated file manager apps and requires an application to be manually reviewed by Google. Which hopefully means, that banks and other shady organizations won't qualify.
If I agree to location, I should be allowed to select where abouts I want that to be
If I agree to files, I want to select a directory and what data it can access about those files (for example, it can't access exif from my photos, nor the file created date)
If it wants my phone log, is it okay it can take every record ever made? Even ones from years ago?
Apps can take your entire contacts list once given permission, just a simple for each loop and upload to a server. I imagine once you've granted access, even if only for 30 seconds that's enough time to parse and upload the information elsewhere.
It's incredibly worrying how giving permission you're not aware of just how much data you're essentially allowing access to, if apps were required to select more precisely what they want, for how long and why and how it will be used, more people would hopefully be encouraged to think again.
Now with cookie popups across the web everyone just clicks "accept! Take all my data please!!". And often time that data you share is about others, so even if you are careful with whom you share information with, all it takes is one person to agree to share all their records on device and your carefully controlled fortress comes crumbling down...
Sigh.
For location, you can pick one time only, or access while you’re using the app (which some apps I think from there try to access it in the background, but iOS will notify you and ask you if you’re sure that’s okay every couple days or so I think. I’ve also been on dev betas and only really remember it complaining about the Weather widget using this all the time).
Definitely seems better than the all or nothing approach I remember from Android. But also I haven’t used android since android 9 was hot, so maybe things have evened out since.