Do not really understand how Android sandboxing works for system apps.

  • FarLine99OP
    link
    fedilink
    English
    41 year ago

    I wouldn’t be so sure about the possibility of a bypass. I’ve heard that system applications have more privileges, but sandboxing is still active and permissions work for them.

    • @[email protected]
      link
      fedilink
      161 year ago

      Wasn’t there news a couple years ago that google tracked your location even if you had location turned off?

      • FarLine99OP
        link
        fedilink
        English
        21 year ago

        You can’t disable location permission for google services, so that’s obvious. But microphone/camera permissions can be disabled, that’s why I’m wondering.

        • @[email protected]
          link
          fedilink
          9
          edit-2
          1 year ago

          You can even turn off sensors in Androids developer options, but your dialer app for example will still be able to use your microphone

          As long as the hardware isn’t physically disconnected, you kinda have to assume it can be used and abused.

    • 𝒍𝒆𝒎𝒂𝒏𝒏
      link
      fedilink
      41 year ago

      I’m rooted with GSF, revoking some permissions forcibly from Play Services (most notably location access) causes the device to reboot, and the permission gets restored forcibly.

      This never used to happen previously (the permission used to get revoked successfully, and things like Google Timeline would act as if your device had disappeared despite location being enabled). I assume a background update implemented this permission recovery mechanism - i’ve since disabled play store on my device and slowly been culling off my usage of other Google apps

    • The Hobbyist
      link
      fedilink
      3
      edit-2
      1 year ago

      There really should be no doubt that a system application can have unlimited and unrestricted access to everything, bypassing all security and sand boxing. That is the extent of the meaning of system app. It’s like having root privileges, admin access.

      Whether Google makes use of it or not is something else, but it could be exploiting that privilege and with Google’s history and the fact that the distributed version of android which contains the google services pre installed is a custom version of android of which you’ll never see the source code, you really have to ask yourself.

      That’s why GrapheneOS is so important: you are the user and you get to control how Android works: the way it actually should, where if you install google services (which is up to you!) it gets installed under your terms and with your permissions.

      Edit: correcting a misinformed message and the irrelevant followup. More clarification on system apps here: https://developer.android.com/guide/platform/

    • @[email protected]
      link
      fedilink
      11 year ago

      It absolutely can. It took a screenshot of what I was doing without my permission. Only reason why I found out was cause it for a survey they were doing. So I wouldn’t be surprised if they’re doing it all the time without me knowing.