Conversation

> App security for other platforms generally involves code analysis to see what it does, rather than denying access to APIs. But Google made a decision to restrict APIs ... oh, you would simply statically analyze the javascript to know if it's bad. intriguing
3
55
You’re unable to view this Tweet because this account owner limits who can view their Tweets. Learn more
Replying to and
It means they can check the app manifest to determine whether those things are being requested from users and then they can enforce the policies. Similarly, they like adding those under-the-hood non-dangerous permissions when there isn't a complete privacy/security model.
1
3
Replying to and
For example, the low-level QUERY_ALL_PACKAGES allows listing and querying info about apps in the same user profile. An app without the permission can determine the apps installed in the profile by manually listing queries or using indirect ways of obtaining the information.
1
2
Show replies