[w3c/permissions] Preventing blackmail (#171)

Android permissions have evolved to allow a user allowing and denying specific requests made by an application. An application could just ask the user for location data, even though it was irrelevant for the functioning of the application. The application has to be able to deal with requests failing. This is useful because before the changes it was possible for an application to essentially blackmail a user into accepting permissions and refusing installation otherwise.

This problem is even worse on the web where absolutely no trust relationship to opened sites exist.

The question I am positing is: Does this proposal create similar problems?

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/permissions/issues/171

Received on Wednesday, 14 February 2018 15:04:05 UTC