mollyim / mollyim-android

Enhanced and security-focused fork of Signal.
GNU Affero General Public License v3.0
1.58k stars 86 forks source link

Think about permissions that Molly uses #197

Closed ghost closed 1 year ago

ghost commented 1 year ago

Is there an existing request for this?

Feature description

Disclaimer: this is not a feature request, per se. I was looking at the permissions that Molly requires and i now I wonder whether all of them are really necessary or not. I think that a part of the hardening should consists also in evaluating these kind of things. Moreover, by removing some permissions and the relative code the attack surface will be reduced.

For more information: https://developer.android.com/training/permissions/evaluating

ghost commented 1 year ago

I’m going to close this issue as this topic, in my opinion, needs more thinking and better writing on my side. Cheers to your work!