• After 15+ years, we've made a big change: Android Forums is now Early Bird Club. Learn more here.

Android permissions explained, security tips, and avoiding malware

This is a great thread. I am hoping you can answer a question regarding new permission requirements by Google.

I just tried to install an app and it requested access to location, contacts, and storage.

I was OK with allowing the location so I could find the nearest location of the establishment. However it would not run if I did not allow access to contacts or storage. Another user complained to the developer. The developer stated that these are new blanket requirements that Google has and that all apps will need these permissions after Jan. 30, 2017.

I cannot find any details of this change/requirement. Is this legitimate? I cannot see why every app will need access to location, contacts and storage!

Thanks in advance if you can point me in the direction of the details of this requirement.

Kind Regards,
Chris
 
Having just purchased an HTC EVO, I am new to Android. I'm moderately familiar with Windows (hope this admission doesn't get me booted off the site) and have found that some of the security apps give you three options for a running application when it requests a service: allow, deny, or ask. Like many of the earlier posts, I thought this root post was very helpful and appreciate all of the subsequent comments that have helped contribute.
I suspect most applications' requests for services/access could be easily resolved into allow or deny. But it would seem very helpful for new or suspicious applications if the capability existed to request user approval for specific service requests when they are made. Then you could figure out whether what you are doing at the moment is likely to require access to that service or not. Just my $0.02 worth.
 
Blanket access to contacts and storage being required by Google regardless of whether the application needs them itself smells like something you find in fields occupied by male cattle. And if it were just boilerplate, why code the app so that it won't run if the permission is refused?

Now not knowing what the app is or does I can't comment on whether it needs those things or not. Just that the explanation sounds very dubious.
 
Back
Top Bottom