Mobile security

Android permissions you should review today

A quick guide to auditing which apps have more access than they need.

An Android permission is a question whose answer lasts for years. You grant it in two seconds, usually in a hurry, and from then on the app can use it every time it opens without ever asking again. Reviewing the list once a year takes ten minutes and usually turns up a surprise.

The four permissions most worth checking

They are not all equally heavy. These open the widest door:

  • Microphone. It can record while the app is in the foreground. That makes sense in a calling or voice-notes app; it makes none in a flashlight, a game or a keyboard.
  • Location. Android separates precise from approximate, and while in use from always. Very few apps need precise and always together; a weather app works just as well on approximate.
  • Storage and photos. Modern Android lets you grant access only to the images you pick. If an app wants your whole gallery to change one avatar, it is asking for more than it needs.
  • Accessibility. The most sensitive of them all: it can read what is on screen and act on your behalf. It exists for screen readers and automation. If an ordinary app requests it, that deserves a very good explanation.

What to look at before installing

The store listing says more than it seems if you read it in this order:

  • Who publishes the app. A real name, a website that exists, a track record. A developer with a single app and no history is not suspicious on its own, but it asks for more reading.
  • The data safety section: what is collected, what is shared with third parties, whether deletion can be requested. It is self-declared, so it counts most when it admits something inconvenient.
  • The declared permissions against what the app claims to do. The gap between those two lists is the single most useful signal there is.
  • Recent negative reviews, not the average score. That is where the screen-filling ads and the features that stopped being free show up.

After installing

Under Settings, Privacy, Permission manager, Android groups apps by permission rather than by app. It reads far better that way: instead of opening forty listings, you see at a glance who holds the microphone. Revoke anything that does not fit; if something was genuinely needed, the app will ask again when the moment comes.

Two more settings that pay off: strip permissions from apps you have not opened in months, and turn on automatic permission removal for unused apps. And deleting an app you have not opened in half a year is the most effective privacy measure that exists.

What appears on no list at all

Network access is not requested as a permission: it is simply declared. An app with no eye-catching permissions can still send out whatever it knows about you. So the underlying question is not only which permissions it asks for, but what it needs in order to work.

Silentium Supernova apps request the minimum their function requires and do their work on the device: no accounts, no analytics, no cloud. The proof is available to anyone: put them in airplane mode and check that they still do the same thing.