I never give apps I distrust permission to my photos, I instead select the photos in my gallery app and share them with the app. And as a side note, many users have cloud backups enabled, whether intentionally or accidentally (having clicked “accept” once, instead of “ask me later”); so big-tech likely stores a copy of the actual pictures, and depending on how lackluster the defaults are regarding privacy, have full access to it.
The API for apps is also flawed. I’m not sure about Android but on iOS apps are told whether the user has given them full or partial access, and some apps needlessly ask for full permissions when they don’t need it. Apple themselves set a bad example with this, iMovie for iOS won’t even launch without full photos access
On devices I use personally I haven’t encountered such examples for years, because the first thing I do is substitute first-party apps with FOSS alternatives. My mom does however, and her Samsung’s camera app for example, won’t function unless you give it permission to scan for nearby devices; among others, which I can’t fully remember. So the stock Android experience seems similar to what you’re describing for iOS.
Graphene’s scope feature basically lets you share a set of pictures/videos/directory whether it’s empty or not and tells the app that it has full access. For snoopy apps just create an empty directory somewhere and set the scope to that and allow access if the app is persistent. More info: https://grapheneos.org/usage#storage-scopes.
And with the current state of machine photo classification, they can sort out at least some subset of the interesting ones, so it won’t just be a ton of noise they need to sift through if say they are looking for nudes or post-its with passwords written on them.
I never give apps I distrust permission to my photos, I instead select the photos in my gallery app and share them with the app. And as a side note, many users have cloud backups enabled, whether intentionally or accidentally (having clicked “accept” once, instead of “ask me later”); so big-tech likely stores a copy of the actual pictures, and depending on how lackluster the defaults are regarding privacy, have full access to it.
I love the GrapheneOS approach with scopes.
The API for apps is also flawed. I’m not sure about Android but on iOS apps are told whether the user has given them full or partial access, and some apps needlessly ask for full permissions when they don’t need it. Apple themselves set a bad example with this, iMovie for iOS won’t even launch without full photos access
On devices I use personally I haven’t encountered such examples for years, because the first thing I do is substitute first-party apps with FOSS alternatives. My mom does however, and her Samsung’s camera app for example, won’t function unless you give it permission to scan for nearby devices; among others, which I can’t fully remember. So the stock Android experience seems similar to what you’re describing for iOS.
Graphene’s scope feature basically lets you share a set of pictures/videos/directory whether it’s empty or not and tells the app that it has full access. For snoopy apps just create an empty directory somewhere and set the scope to that and allow access if the app is persistent. More info: https://grapheneos.org/usage#storage-scopes.
And with the current state of machine photo classification, they can sort out at least some subset of the interesting ones, so it won’t just be a ton of noise they need to sift through if say they are looking for nudes or post-its with passwords written on them.