{"id":3256,"date":"2013-11-02T10:41:58","date_gmt":"2013-11-02T17:41:58","guid":{"rendered":"http:\/\/www.coolkarma.com\/dharma\/?p=3256"},"modified":"2013-11-02T10:45:39","modified_gmt":"2013-11-02T17:45:39","slug":"shame-on-google","status":"publish","type":"post","link":"https:\/\/www.karmabytes.net\/?p=3256","title":{"rendered":"Shame on Google"},"content":{"rendered":"<p><iframe loading=\"lazy\" id=\"mainframe\" name=\"mainframe\" src=\"http:\/\/coolkarma.com\/apppermissions.html\" height=\"480\" width=\"625\" frameborder=\"0\"><\/iframe><\/p>\n<p>Last night the redneck and I were sitting on the front porch enjoying the evening sky and we noticed a very bright light in the south western hemisphere just over the tops of the trees.\u00a0 It was moving slowly across the horizon and we wondered what it could be.\u00a0 Well don&#8217;t you know, there are ANDROID apps that you can download onto your phone that you can POINT up at he sky and it will SHOW you the constellation that you are looking at!\u00a0 How cool is that?\u00a0 So I started to research what apps were out there for pay and for free download.\u00a0 I read a few reviews, peeked at a couple forums and went to download the Google SKYMAP on my Galaxy 5.<\/p>\n<p><a href=\"http:\/\/www.coolkarma.com\/dharma\/wp-content\/uploads\/shameRed.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-thumbnail wp-image-3269\" alt=\"shameRed\" src=\"http:\/\/www.coolkarma.com\/dharma\/wp-content\/uploads\/shameRed-150x150.png\" width=\"150\" height=\"150\" \/><\/a>As I read the permissions that the app needed, I paused, wrinkled my brow and began my blog in my mind.\u00a0 Why does a camera app need to <i>test access to protected storage<\/i>?\u00a0 Dang, that doesn&#8217;t even sound good.\u00a0 Moreover why would it need to know anything about the phone calls that I make?\u00a0 Houston, we have a problem.<\/p>\n<p>Of course, its not just Google.\u00a0 And the particular app that I&#8217;m going to pick on is certainly not the most egregious out there.\u00a0 But its a good annotated example and you know I like flashy mouse over images so if for no other reason I am going to use Google SkyMaps as my <em>pick peeve of the moment<\/em>.<\/p>\n<p>Do you ever READ the permissions on your Android apps when you press the GREEN ACCEPT button?\u00a0 Do you ever wonder if the provider really NEEDS those permissions?\u00a0 Well as a former DIT in higher education, my brain is wired to wonder.\u00a0 Why would a flashlight app need access to my contact list?\u00a0 Why does a ringtone need to MAKE PHONE CALLS?!\u00a0 Why does this FREE racing game want to know MY GPS?<\/p>\n<p>So I did a bit more digging and actually found the following &#8220;explanation&#8221; on a <a href=\"https:\/\/groups.google.com\/forum\/#!msg\/google-sky-map\/KT21oJiD08Q\/0kehSXkTXwcJ\" target=\"_blank\">google-sky-map forum<\/a>, presumably by one of the google developers who worked on creating skymap.\u00a0 Who knows if its true, and I&#8217;m sure he&#8217;s now in the google witness protection program and this link will soon be self destruct.<\/p>\n<p>But when asked WHY does google sky need so many permissions the programmers response was:<\/p>\n<address style=\"padding-left: 30px;\">&#8220;It doesn&#8217;t really. I think the only one that is meaningful is &#8220;not allow the phone to go to sleep&#8221;, although that might not be the case any more.<\/address>\n<address style=\"padding-left: 30px;\">\u00a0<\/address>\n<address style=\"padding-left: 30px;\">Back when we first released Sky Map, the permissions model was pretty coarse. I think we just used the defaults. Over time, Android split things into multiple settings. It required some amount of effort, both technical and bureaucratic, to change them, and we figured that it wasn&#8217;t worth the effort.&#8221;<\/address>\n<address style=\"padding-left: 30px;\">\u00a0<\/address>\n<p>I was a technical bureaucrat for years, I&#8217;m not going to argue the point that its not true about the efforts of change management.\u00a0 But as long as there are other options out there, even if I have to pay a buck or two, I&#8217;m going to install an app that doesn&#8217;t require as many android permissions.<\/p>\n<p>And that&#8217;s basically my rule of thumb.\u00a0 I ask myself:<\/p>\n<p style=\"padding-left: 30px;\">Do I really need this app?<br \/>\nDo I trust the publisher?<br \/>\nHave I read the reviews?<br \/>\nDo I understand why its asking for these permissions?<br \/>\nIs there an alternative application that asks for LESS?<\/p>\n<h2 style=\"text-align: center;\">If you don&#8217;t know?\u00a0 Don&#8217;t download.<\/h2>\n<p>Its pretty much that simple.\u00a0 But how do you KNOW?\u00a0 What do some of the security and privacy settings even mean?\u00a0 Well, if you are curious there&#8217;s a wonderful thread on everything you ever wanted to know about androids that does a good job at digging in the dog pile of settings and permissions as well as letting you know which ones may pose a serious risk. <strong><a href=\"http:\/\/androidforums.com\/android-applications\/36936-android-permissions-explained-security-tips-avoiding-malware.html\" target=\"_blank\">Android permissions explained, security tips, and avoiding malware<\/a><br \/>\n<\/strong><br \/>\nToo technical?\u00a0 Lifehacker has a wonderful brief on the topic?\u00a0\u00a0 <a href=\"http:\/\/lifehacker.com\/5991099\/why-does-this-android-app-need-so-many-permissions\" target=\"_blank\">Why Does This Android App Need So Many Permissions?\u00a0 <\/a>Which actually includes some apps that you can download that will modify the permissions\u00a0 and either stop or alert you to <i>phishy<\/i> behavior.<\/p>\n<p>And if you want to go back and CHECK to see what permissions the apps you have already installed have on your android, its easy to do.<\/p>\n<ul>\n<li>Tap the Menu button<\/li>\n<li>Select Settings<\/li>\n<li>Look for the Application Manager (on my menu I had to select the MORE tab first)<\/li>\n<li>Then select the app that you want to check an scroll all the way down to see the PERMISSIONS list.<\/li>\n<\/ul>\n<p><a href=\"http:\/\/www.coolkarma.com\/dharma\/wp-content\/uploads\/venusapp.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-3268\" alt=\"venusapp\" src=\"http:\/\/www.coolkarma.com\/dharma\/wp-content\/uploads\/venusapp-168x300.png\" width=\"168\" height=\"300\" srcset=\"https:\/\/www.karmabytes.net\/wp-content\/uploads\/venusapp-168x300.png 168w, https:\/\/www.karmabytes.net\/wp-content\/uploads\/venusapp.png 450w\" sizes=\"auto, (max-width: 168px) 100vw, 168px\" \/><\/a>I went through and deleted a few apps that I either no longer needed, or I simply didn&#8217;t want them to have such deep hooks to my personal life.\u00a0 Oh and if you don&#8217;t CARE who sees your chit, you should probably REMOVE YOUR FRIENDS from your address books and social networks that DO.\u00a0 Because once you open yourself up to the world, we get exposed too.<\/p>\n<p>And in case you were wondering &#8230; that <i>light<\/i> in the sky, it was Venus.\u00a0 And the android app <a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.lavadip.skeye&amp;hl=en\" target=\"_blank\">SkEye Astronomy<\/a> only asked for my GPS permissions.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last night the redneck and I were sitting on the front porch enjoying the evening<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[12,69],"tags":[],"class_list":["post-3256","post","type-post","status-publish","format-standard","hentry","category-dharma","category-tech-tips"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.karmabytes.net\/index.php?rest_route=\/wp\/v2\/posts\/3256","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.karmabytes.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.karmabytes.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.karmabytes.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.karmabytes.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3256"}],"version-history":[{"count":26,"href":"https:\/\/www.karmabytes.net\/index.php?rest_route=\/wp\/v2\/posts\/3256\/revisions"}],"predecessor-version":[{"id":3284,"href":"https:\/\/www.karmabytes.net\/index.php?rest_route=\/wp\/v2\/posts\/3256\/revisions\/3284"}],"wp:attachment":[{"href":"https:\/\/www.karmabytes.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3256"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.karmabytes.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3256"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.karmabytes.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3256"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}