this post was submitted on 17 Jan 2025
138 points (99.3% liked)
Cybersecurity
6056 readers
194 users here now
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
- Be respectful. Everyone should feel welcome here.
- No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
- No Ads / Spamming.
- No pornography.
Community Rules
- Idk, keep it semi-professional?
- Nothing illegal. We're all ethical here.
- Rules will be added/redefined as necessary.
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]
Notable mention to [email protected]
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Really? But my flashlight app says it needs location permissions to work...
My biggest gripe with Android perhaps is that somehow the nearby devices/location permissions is tied into WiFi and Bluetooth rather than just having a separate 'communications' permission to say who can use the network links.
I dont really understand what you mean by the second. If an app has WiFi and Bluetooth access, then it has location access. Not including WiFi and Bluetooth under location permissions would be very bad, because the average person doesnt understand that those things can be used to locate you.
It could go both ways. Simple example might be an offline GPS app, allow it location but not network other than when downloading maps. Network based location is a crude thing at the IP level, but can get pretty accurate if based on BT/WiFi access point.
It's a bit better with the 'only when in use' option on modern versions, but 'in use' could be a bit subjective if an app keeps a running service in the background. I seem to recall that Graphine has them split out as two distinct things.
Oh i see. CalyxOS has a built in firewall app to restrict that, which is handy.
Why should it be allowed to see the wifi SSID etc.?
The device will try and feed this info to Google for location when GPS can be reached. It's possible to turn off, but the fact that it can be used is troubling. Anything that can be turned off at a toggle can get flipped back on with an update.