Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Similarly, the default clock that came with my Xiaomi phone wanted permission to access my contacts before it would let me set an alarm. It did not get any such permission, I run an alternate clock/alarm app instead, and this will be the last Xiaomi phone I buy.


TBH that just sounds like bad design. The manufacturer could easily have granted that permission out of the box and you'd be none the wiser. A lot of built-in apps have permissions that can't be viewed by the user


The design worked for me! It highlighted a problem that I might want to be aware of when picking my next phone.

No, I don't want Google or whoever else to have their alarm app scanning my contacts for no good reason¹ either, and perhaps I can't stop it whoever is doing it, but given how many apps are locked onto that phone, how often it finds a reason to start one of them up, what perms they want, etc., I'm pretty sure I trust Xiaomi less. They probably have all my current data already anyway (I'm sure this phone is using more data than the previous one, though I've not dug into why yet, perhaps sending my info home is why), but hey ho…

My last phone was from Xiaomi too, but that was relatively stock Android (on the Android One program) so didn't have so much extra junk forced into it.

--

[1] they might have reason, I doubt I'd consider it good!


Google Apps generally have all permissions. GrapheneOS actually offers a sandboxed version of them that works like normal apps, and you can see how many permissions it is requesting.


"TBH that just sounds like bad design"... It's not bad design, it's deliberate design.

https://www.scss.tcd.ie/Doug.Leith/Android_privacy_report.pd...


Link doesn't explain why a built-in app would ask for permission to do anything. Eg as the sibling comment mentioned, Google apps often have full permissions by default and don't need to ask


I couldn't possibly link to the copious evidence online, anecdotal on this forum, high stakes data breaches, that personal data is being harvested by default en masse. It is true about the link, it was meant as nod to some at least scientific endeavour to investigate sharing.


> doesn't explain why a built-in app would ask for permission to do anything

> that personal data is being harvested by default en masse

You seem to be agreeing, at least to the point that a built-in app is usually granted permissions without requesting from the user. I think it would be more correct to say "bad implementation" instead of "bad design" but the point seems to make sense.

But ultimately it seems that you and OP both agree that this "bad implementation" (ask the user for permission instead of being granted by the OS) is the intended design (require unrelated permission for basic functionality).


You mean like bad bad design


> the default clock that came with my Xiaomi phone wanted permission to access my contacts

Unfortunately not surprising at all for Xiaomi, or any Chinese smartphone maker for that matter. Not that Korean or American Android phone makers like Samsung, Motorola, Google Pixel etc are privacy friendly, but Chinese smartphones are way worse.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: