Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For this specific issue, I believe https://developer.android.com/preview/privacy/scoped-storage is the solution.

Too bad many Android developers are opposing this feature (e.g. previous discussion: https://news.ycombinator.com/item?id=19521211).



Scoped storage does not prevent applications from sharing PII with each other. There are already advertising networks, using BroadcastReceivers and ContentProviders to share analytics data — it is simple and does not require individual apps to have external storage access.


Loos like that system also fixes the "steal user location data from pictures metadata" bypass: https://developer.android.com/preview/privacy/scoped-storage...


Yeah, that seems like the right answer.

However, I think you still have to hold developers responsible for clever tricks that violate the intent of the Android permissions system. There are always going to be loopholes. (This likewise means that there has to be room for developers to make honest mistakes.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: