Google Play is reinstating the app permissions section
twitter.com
twitter.com
https://www.businessinsider.com/what-are-apple-privacy-nutri...
When I saw this post I assumed Google was rolling back their privacy nutrition label like things they added. I didn’t realize it was about the granular list.
Here's a full list of entitlements from Apple. You'll find that a lot of them wouldn't make sense to display on a store page:
https://developer.apple.com/documentation/bundleresources/en...
Isn't the next version of Android the first time users will be allowed to deny an app permission to send notifications? That's been in iOS from the start and has always provided a way to silence apps that spam notifications.
https://developer.android.com/about/versions/13/changes/noti...
iOS only added permissions at all in iOS 6, before that apps had access to photos, calendars, contacts and reminders automatically.
https://www.xda-developers.com/android-13-beta-3-review-noti...
Android has recently been refining their notifications model, increasing the granularity of the notifications by splitting them into "types" and user-assigned "priority" levels. It seems default-off is the newest step in that, apparently.
For example, every app gets INTERNET by default, meaning that lots of privacy-violating things don't have to be declared at all! Other permissions like ACCESS_FINE_LOCATION being required until recently for accessing Bluetooth devices meant that users would think that every BLE app was spying on them. People don't understand the implications of what a permission means for their data / privacy
A developer-written description of exactly what an app is doing with user data and why is much better (with of course the issue that developers can simply lie)
And not something that should be hand waved away in the quest to say that written descriptions are better. They are not, but having both in other can help to a great extent. A practice I've rarely seen is the description containing each permission name, and what it's needed for, in other words, explaining that mapping that's missing.
This was a dumb hack by Google. "BLE can be used to spy on your location" => "you must grant all location data to said app".
This is something that is better dealt with a clear privacy warning next to the actually relevant permission rather than conflating it with GPS.
I'd rather they just put all the information out there on full display and maybe create an API that lets apps compete over explaining it clearly/warning users.
A lot of security settings (especially on the privacy level) are often too over-complex or total placebo in nature. A big problem is that these settings often get wiped and unstick themselves every time an app or OS update occurs, which totally defeats the purpose of having to configure apps independently. Many apps like TikTok and Instagram barely even function unless you grant them invasive camera and microphone access regularly (not even selectively).
Regulators need to pursue device makers instead of trying to address each individual app maker... Samsung and Apple grant access to accelerometers, cameras, contacts, etc. to begin with to apps (even when it's nowhere necessary), rather than just restricting access at the device and OS level... This allows device makers to grant certain apps backdoors for a fee.
Modern phones make me miss Blackberries so much, it's a damn shame they're barely compatible with modern networks now or I'd light my old one up and forget about these overpriced touch screen snitch/spy devices.
^ are these vetted in any way? are they enforced? I'm okay with this being 'vendor says this', but if app stores are reporting it next to permissions (which are programmatic constraints), feels like it's at best aspirational, potentially deceptive. Are there real penalties? Or is this just a system for wrist slapping in the rare case someone is caught in a lie.
> When Google becomes aware of a discrepancy between your app behavior and your declaration, we may take appropriate action, including enforcement action.
(https://support.google.com/googleplay/android-developer/answ...)
(could also do dataflow analysis on code in a trusted third party CI system)
they did this with the huq sdk https://www.vice.com/en/article/y3vp35/google-tells-apps-dis...