(Don't want to start a flame war and I am not really an Android fan)
(Don't want to start a flame war and I am not really an Android fan)
In theory, it is good, but in practice, it's broken.
The iOS way installs the app, but denies access to the resource.
How do you expect this to work otherwise?
You are representing it as though Apple asks for user's permission for every sensitive resource.
But since you're asking: I expect the permissions to be more granular.
And I would like to be able to revoke some of them if the developer allows it.
I think the android permission system is sane and reasonably functional. It's the users responsibility to read the requested permissions at install time and make a call.
There could be improvements here of course. I'd like to see a two tiered approach where developers could mark which permissions are optional and users could decide which to grant the on the first or each time these permissions are used in addition to the current method. I'd also like to see a requirement for devs to provide an explination of what each requested permission is needed for that could display on the market.
Hopefully these types of controls will continue to evolve on all platforms.
This would be SO useful!
I have an app that I want to be able to collect crash reports for. This means I need the "READ_LOG" permission. Thing is, the log CAN have other potentially private information in it, so there's a scary warning for that permission.
If I could ask for READ_LOG permission at run-time, and Android would pop up a box saying "This app is requesting access to the log to: 'create a complete crash report and send it to the developer'" or some such, then only the very few people who are actually sending me a crash report would ever have to "reveal" their log data to my app.
Another situation I've got is I'd like to use the the permission to act as your Google account to optionally grab some user detail from <some Google service>, but I don't want to scare off users with this permission.
The other feature on my permission wish list is some permission specific options like internet access to [urlmask1,urlmask2,...] or log read access to logs from my app only, errors and warnings.
Oddly; even when you (the dev) ask for this; Google prompts you (the user) at access-time to approve/deny account access permissions (similar to Google's OAuth prompts on the web). Seems that would remove the need to ask for the permission at install time as well.
The SMS permission in Android seems the most egregious to me. For example, an Android app you install requires SMS permission. However, in Android as it stands right now, the app does not need to notify a user when it sends an SMS - there's no requirement (nay, not even a widget to pop open and require the user to "Send" the way you see on other platforms like iOS--you've got to build this into your client yourself) to do this. So, you install a third party SMS client thinking you'll use it to send SMSes, but the app can send SMSes on its own, without you even seeing them. See also: http://www.cs.ncsu.edu/faculty/jiang/RogueSPPush/
Personally, while not perfect, I like Blackberry's model here (Cyanogenmod has implemented something similar) - the user can block out certain functions, knowing full well that the app will break - but can then decide to re-enable them if needed or once their trust level is raised.
I guess what I'm advocating here is a combined approach
- up front permission notification of android, but more fine grained
- activity alert approve/deny from ios
- selective permission blocks from bb except the developer can specify which permissions are optional so the apps don't crash when you disable random permissions, they just refuse to start with a clear message.
- parameters for some permissions to further narrow the scope like URL masks that you'll access over the internet instead of asking for full net access, etc.
iOS seems to only care about your location when it comes to permissions which worries me a little.
It’s granular from the developer point of view, but it’s not for the user: when you install an app you either grant it all the permissions it requires (before you have a chance to actually run the app and see what it does) or you don’t install it at all.
With the iOS model (asking permissions when the app uses them) I can install an app, deny it permission to use my location and it will still work for everything else.
Also, how would that solve the problem if the Android developers forgot to add the ”read contacts” permission in the SDK? They would still have to update the software to add it.
It would be nice to allow or deny an app "optional" permissions (selected as optional BY the app) at run-time. It would NOT be nice for users to be able to do this willy-nilly. With the dozens of possible permissions, you'd have millions of potential combinations a particular user could enable or disable, and you'd need to be sure your app worked with any combination.
But worse than that is the fact that a lot of apps are monetized by ads, and disabling "INTERNET" permission would prevent ads from downloading. If I'm trying to make a living off of my app, I don't want to make it easy for people to get it for free. Some people will anyway, of course, but no need to make it easy.
I meant the Android OS developers (which is what happened with iOS here), not the 3rd party developers.
String READ_CONTACTS Allows an application to read the user's contacts data.
String WRITE_CONTACTS Allows an application to write (but not read) the user's contacts data.
So yes, if they HAD forgotten, then Android would have the same security hole. But it doesn't, because they took security seriously.[1] http://developer.android.com/reference/android/Manifest.perm...