Linked by Thom Holwerda on Tue 10th Jun 2014 19:52 UTC

This system worked fairly well. If an app changed its permission needs, you’d be notified, and could choose whether to accept the update. With the most recent Play Store update, however, users are not told about certain permission changes if they don’t result in the addition of permissions to a new group. Given the sheer breadth of permissions a group now covers, this effectively leaves Android with only 13 permissions. An application can quietly update itself in future, to grant itself access to further permissions within a group, with the user left none the wiser.

Once an app is granted an individual permission within a group, that application has the ability to add any other permissions from the group in a future update, without users being notified of the change.

Oh Google.

Optimist view: Google I/O will bring changes to the permission system wherein the above makes sense. Pessimist view: Google is monumentally stupid.

I'm not an optimist.

Thread beginning with comment 590520
To read all comments associated with this story, please click here.
[roll eyes]
by Drunkula on Wed 11th Jun 2014 12:42 UTC
Member since:

Come on, Google. That is a very Facebook thing to do...

Reply Score: 2

RE: [roll eyes]
by Morgan on Wed 11th Jun 2014 13:53 in reply to "[roll eyes]"
Morgan Member since:

Ironically, Facebook has granted the user more fine-grained control over their privacy settings than ever. I noticed the other day that they now allow you to select exactly what kind of info you will allow other people's apps to get from your account. For example, if a friend of yours is using a photo-sharing app, and they wish to pull in your friend's list, location info, previous public posts, etc., you can choose whether to allow each of those data points.

Of course, I turn everything off for any app that has requested it in the past.

Reply Parent Score: 3