| ▲ | yAak 5 hours ago | ||||||||||||||||
The gotcha is “I gave it permission, then revoked permission in the UI, but it still has permission.” | |||||||||||||||||
| ▲ | swiftcoder 4 hours ago | parent | next [-] | ||||||||||||||||
That's not quite it either. It's more along the lines of "I revoked access via one mechanism, then granted it via a different mechanism, and the setting UI for the first mechanism doesn't reflect the second action". There's no privilege escalation here, but there is a misleading privacy settings UI, which offers no obvious way to audit/revoke permissions in the second case | |||||||||||||||||
| |||||||||||||||||
| ▲ | wtallis 4 hours ago | parent | prev [-] | ||||||||||||||||
Not quite. The steps are revoking permission in the UI (which works as expected), then implicitly granting permission in a way that the UI does not reflect but quietly persists. | |||||||||||||||||