Hidden “App Ops” Feature in Android 4.3 Lets You Disable Permissions From Apps
droid-life.com
droid-life.com
Well-behaved apps won't ask for permissions they don't need anyway, and badly-behaved apps will simply refuse to run without all the permissions they (and their ad services) request.
Without the ability to pretend to have the permission but not actually provide useful data, this really won't help much.
On the bright side, at least a subset of these do behave in the sensible way: various reports suggest that calendar and contact accesses will successfully return empty results rather than erroring out, for instance.
If this were true it would be an issue on iOS. Its not.
Which, in the end, has the same result - if the user does not grant the permission, the app will refuse to work.
I do not download crapware either, but I don't have much trust into bizdevs trying to monetize anything. This is the first solution that I would expect.
To prevent that from happening you've got to deny access to the addressbook altogether, which isn't desireable if you don't want to kill the market for Voip/Chat on mobile phones.
Apps like Whatsapp, or the Voip/Xmpp client I am working on for my company just need a way to determine who on your contactlist is available for chat/Voip via your app.
Also: how do you think that apps like Skype enable you to call some landline number for a cheaper rate? They do this by creating a local dialin number that routes the caller to the actual destination.
What could work is that the OS gives hashes instead of the real numbers to the apps, but that would suck for anyone that had a web service that needs those numbers. (for say creating a cheaper dialin number to call some of your contacts)
With any luck, those apps will (rightfully) die do to lack of user base. Of course, the cynic in me knows that the unwashed masses will never go to the trouble of dealing with all those permissions, even if they know about them.
BTW, what do you consider "badly-behaved"? I've seen so many "good" apps ask for so much it boggles my mind (as someone else mentioned, WTF does a music player need access to your addressbook?).
Any app which requests a permission whose use isn't instantly obvious from the nature of the app. "Full network access" for a non-multiplayer game. "Location access" for anything that isn't a mapping app or point-of-interest finder (and even the latter ought to allow manual zipcode entry or similar). Contact access for any non-communications app. Phone state access for almost any app that isn't an dialer or call-control management app.
A music player that asks for access to your contacts would fall squarely under "badly behaved".
I would say that this is close to universally untrue -- apps generally ask for permissions that cover the superset of all possible edge conditions, even though only a subset of their users will ever actually need that.. If I'm someone who will never use the contacts feature, for instance, I would love to have the option -- on install -- of saying "Yeah, I understand you want that but no, you aren't getting it". This is a step in that direction.
I've been waiting for this feature since the day I got my first android phone.
I am of the opinion you should be offered a refund/uninstall if new permissions get added. Or have a way of disabling them like the posting is about.
http://www.androidpolice.com/2013/04/03/cyanogenmod-will-no-...
And, if he does change his mind, it's more likely to be to remove the opt-out feature.
People don't expect Free Software to phone home like common malware. It's shocking. That's why I mentioned it.
Oh, and it isn't opt-in. It's opt-out, until the developer changes his mind again:
http://www.androidpolice.com/2013/04/03/cyanogenmod-will-no-...
[1] https://code.google.com/p/android/issues/detail?id=58043
Fantastic.
More to the point: why would an app ask for permissions it didn't need in the first place? The most likely thing to happen is that the app would be useless.
No piece of documentation or sample code has ever encouraged a pattern of "checking if your app has permission X or Y" because it's a total waste of time. Likewise, none of the built-in Android apps or any of the open-source apps from Google developers I've seen do that. There is no point to doing so.
In fact, it's actually bad practice because you're adding a bunch of error checking code for an error condition that's never going to happen. If you're getting a SecurityException for an action that you've explicitly requested the permission for, you're running on a broken API and it's not your responsibility to handle that.
The framework does include methods for checking permissions, but they are generally meant for things like inter-process communication and library code. There's no need to use them for ordinary applications you are building yourself. And nobody does that, rightfully so.
Ultimately it is a matter of time before something like this does make its way into the core features of Android. It is worth thinking about how Android is both deficient and helpful with its design philosophy regarding that eventuality.
Ad networks. So wrap the calls to the ad network library in try/catch, and, in most cases, that takes care of the mostly gratuitous permissions.
Good. Let them die. If there's really demand for them, better alternatives will pop up.
Developers: You are now on notice to handle SecurityException and fail soft. in most cases, this should be easy to do, and when it isn't, you can, at least, post a dialog that says" "This app really needs SOME_PERMISSION in order to run."
But since it is hidden, you are not on the hook, yet, to support users that start making use of this feature.
http://commonsware.com/blog/2013/07/26/app-ops-developer-faq...
If you ask me, manufacturers should be prohibited from adding to /system/app but that's not how the Android licensing works. So, we get un-uninstallable apps (vote with your wallet - buy only Nexus experience!).
As others have mentioned I'm sure some app developers will resort to just erroring out if they can't access something they asked permission to access, but hopefully we'll be able to shame the bigger players away from that.
I wonder if Google is using requested permissions in Play rankings. The apps which require _all_ permissions should definitely be ranked lower.
Google is probably reluctant to do things that "harm" competing ad networks for fear of getting sued.
It's called app goggles or something.
I block internet access to lots of apps thatdo not need,it. And most of them crash when they try to use it.
Eg. Swype tries to connect every time i reboot my phone. Not sure if they are just checking for updates or uploading my personal dict, but since it doesn't try to upload anything while I'm actually writing, i just watch it die every reboot and that is it.
Almost all games i tried i removed access to see running apps and contact list. Very few crashed, meaning they probably expose those api to ads, and they are not using them yet.