Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I find it hilarious how Play Store is slowly banning permissions (some justified, some not) in regards to 'privacy', yet the internet permission is still classified as a low dangerous permission [0], which means that when you install an app, this permission is not even shown. (And you can't even turn it off!)

[0] https://developer.android.com/reference/android/Manifest.per...



The Internet permission was largely useless. If you knew what you were doing, it was trivial to bypass it to exfiltrate data. On top of that, almost every app requests it, which contributed to alarm fatigue in users.

Permissions are only useful if they can be enforced and users pay attention to them.


You can still, at least, allow users to revoke it, even if it's silently default.


just out of curiosity, how was it bypassed?


Apps can communicate via each other, so if any app has internet permission and public intent then other app can use that https://developer.android.com/training/basics/intents


so, "get your users to also install this other backdoored app with the internet permission".

I don't think that qualifies as "trivial", though it'll obviously work on some people.


The easiest way was to send an Intent to the browser with a specially constructed URL. Every phone has that installed.


For relatively small bits of info, probably only once before the app is uninstalled: yep, agreed, this works. There's no practical way to prevent it either, short of requiring interaction literally all the time, which just makes dialog-fatigue worse.

But ultimately this will do a single extremely visible GET request, which is limited by the browser's normal sandboxing. That's quite far from "bypassing the internet permission". And in some cases ineffective (e.g. I have multiple browsers and intentionally do not set a default), though that's rare enough that I don't think it's relevant.

---

An "app can send intents" permission would be sorta nice for things I truly want sandboxed, e.g. a password manager. XPrivacy allow(ed|s) blocking stuff like this, I would and did happily toggle it off for most apps since e.g. many games have no need of anything but their APK's data.


Run a local vpn like netguard! https://netguard.me/ I leave mine on deny by default.

That said, I completely agree. Google's approach to permissions on Android has been wildly user-hostile, and full of nonsense bundling like (relatively harmless) device-ID and (very much not) access to all call logs. Stuff like XPrivacy[1] demonstrates how they could have done this with far more user control and far less app interruption, but they haven't.

[1]: not the UI, the UI is terrible. but "send fake contacts" or "block outright" for every API is excellent, and doesn't require changing apps to support. the fact that the apps can query the state and I cannot lie about it is a problem, because they often require lots of bullshit that's not required.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: