Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The point of removing the INTERNET permission as I see it is to prevent the app from sending out any information, allowing you to trust it with your sensitive information. However if the app can raise an intent that will cause another app to send out information of its choosing it has effectively broken that permission, even if it never created a socket. Sure, the app may have a hard time getting information back (although there are channels such as app updates at the very least) it isn't enough to trust an app with your passwords just because it doesn't have any permissions.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: