Bug #3822
Restrict app permissions even more
Status: | Closed | Start date: | 09/28/2014 | |
---|---|---|---|---|
Priority: | High | Due date: | 06/15/2015 | |
Assignee: | - | % Done: | 0% | |
Category: | - | |||
Target version: | Orfox Beta 1 | |||
Component: |
Description
OrFox, as a privacy and security oriented browser, doesn't need any permissions except network access, permissions including "run a startup, sync, control vibration, modify system settings, NFC access, access profiles" are unnecessary and might pose a security and privacy risk for this kind of software.
Similar to OrWeb, OrFox should only have bare minimum required to function properly. (Please see screenshots attached)
Related issues
History
#1 Updated by n8fr8 about 3 years ago
- Target version set to Orfox Alpha
#2 Updated by n8fr8 over 2 years ago
- Due date set to 06/15/2015
#3 Updated by n8fr8 over 2 years ago
Perms to try and remove:
- take pictures and video
- precise location (or any location)
- add or remove accounts, create accounts, find accounts
- NFC
- read sync settings, any seync settings
- modify system settings
#4 Updated by amoghbl1 over 2 years ago
- Status changed from New to In Progress
Removing permissions might be a little harder than I expected, looking at this currently though.
#5 Updated by amoghbl1 over 2 years ago
- Status changed from In Progress to Resolved
#6 Updated by amoghbl1 over 2 years ago
- Read your web bookmarks and history
- Modify or delete the contents of your USB storage, read the contents of your USB storage
- *** Find Accounts on the device
- connect and disconnect from WiFi
- download files without notification
- view network connections
- view wifi connections
- run at startup
- control vibrations
- prevent phone from sleeping
- install shortcuts
- uninstall shortcuts
- follow up bug in place for this at #5395
#7 Updated by n8fr8 over 2 years ago
- Status changed from Resolved to Feedback
#8 Updated by n8fr8 over 2 years ago
- Target version changed from Orfox Alpha to Orfox Alpha 2
Moving this to beta b/c I think we need additional review of permissions to ensure we lock it down as much as possible
#9 Updated by n8fr8 over 2 years ago
- Target version changed from Orfox Alpha 2 to Orfox Beta 1
#10 Updated by n8fr8 over 2 years ago
- Status changed from Feedback to Resolved
We've removed the most objectionable permissions, specifically the "accounts": https://dev.guardianproject.info/issues/5395
We'll resolve this for now, and review the work. Then we can open new specific tickets in the future for any objectionable perms.
#11 Updated by n8fr8 over 2 years ago
- Status changed from Resolved to Closed