| ▲ | ajross 4 hours ago |
| What you want is basically how it works. On both phone platforms and PWAs, all permissions are visible to the user explicitly. All of them can be revoked at any time. Apps are disallowed from requesting an already-denied permission. Obviously apps can tell if they haven't been granted a permission (even if you tried to fake this, they aren't dummies and will know if it's not working), and obviously third party software isn't under any obligation to work without them. But the platforms have done what the platforms can do, at the architecture side, really. The next stage is human-audited enforcement of malware, which this AliExpress nonsense might hopefully run afoul of. |
|
| ▲ | xnx 4 hours ago | parent | next [-] |
| > Obviously apps can tell if they haven't been granted a permission (even if you tried to fake this, they aren't dummies and will know if it's not working), How can they tell? For the permissions I can think of: location, filesystem, etc. it should be easy to lie/spoof. |
|
| ▲ | drdexebtjl 4 hours ago | parent | prev [-] |
| >Obviously apps can tell if they haven't been granted a permission By design. This doesn’t need to be the case. It should be impossible to tell you have denied a permission. In TFA’s case, the browser could just keep processing audio but never hook it up to a real audio sink. |
| |
| ▲ | victorbjorklund 3 hours ago | parent | next [-] | | Soundd like a nightmare to build legitimate apps if you for example are building an app that uses the camera but you can’t in anyway tell that using the camera fails (because user had denied the permission 6 months ago and has no memory of it) and instead of being able to give a helpful error you are just ending up with I am guessing fake images (maybe just a black screen). | | |
| ▲ | wotb 26 minutes ago | parent | next [-] | | Just because it's hard doesn't mean you shouldn't try. What about a popup saying "xyz has tried to access the camera a lot lately, continue blocking?"? Or apps can apply for set of 'core permissions' that can't be denied but are much more tightly controlled? Apple and Google are some of the biggest companies in the world, they don't deserve as much leeway as you're offering. | |
| ▲ | voakbasda 3 hours ago | parent | prev [-] | | The image could contain a message that it is disabled. | | |
| ▲ | StingyJelly an hour ago | parent [-] | | Then it is detectable. Those permissions should have a third option alongside allow and block - spoof. |
|
| |
| ▲ | ajross 4 hours ago | parent | prev [-] | | That does nothing but start an arms race. Fine, audio "works" but do you get noise? Can you read back the sounds you play? No, right? It doesn't work, QED. Now the platform needs to fake the noise. Likewise for any other hardware access you want, and most of them are harder. How do you fake local storage without storing anything? How do you fake Bluetooth access without virtualizing an entire device? Do you fake the screen dimensions to look like something else? Input latency? Where does it stop? No, "does this work" is among the easiest questions to answer in technology. We aren't going to win this war. | | |
| ▲ | emctech 3 hours ago | parent [-] | | The best you can do on the modern web is reduce your fingerprint footprint, though it comes at a cost of websites breaking from JS disabling, or local time zone anonymisation. |
|
|