Field Notes

source

Draft: blog post about android permissions

An F-Droid website merge request from July 2022 in which Michael Pöhn (uniqx) proposed a blog post responding to Google Play hiding app permissions, and the discussion turned into the most-documented direct clash between F-Droid’s maintainers and the GrapheneOS-adjacent critics. A saved copy is preserved here; the .raw.html companion is the provenance copy. An archive.today snapshot of the same page circulates in the dispute because several comments were later deleted from the live page.

What it shows

Two things, one technical and one social.

Technically, this is the origin of the “install-time permission display is misleading” complaint in PrivSec.dev on F-Droid security issues. Tommy Tran and Daniel Micay argued in the thread that surfacing low-level install-time permissions misleads users in both directions: dangerous permissions are not granted at install on modern Android, while workarounds such as manual query filters let apps obtain what an undisplayed permission (QUERY_ALL_PACKAGES) implies they cannot. Pöhn closed the MR calling their points “(over-exaggerated) but still good” and undertook to update the permission displays before reviving the blog post, so the complaint was substantively conceded by the person who opened the discussion.

Socially, the thread is the episode both sides later cited as the start of the feud. Hans-Christoph Steiner locked and unlocked the MR repeatedly, deleted posts as off-topic or as “threats and insults” against the code of conduct, and asked Micay to “keep your posts to your own forums.” Micay’s side describes the same episode as unprovoked attacks on him followed by a cover-up through deletion; the deleted comments are not visible on the live page or in this snapshot, so which deletions hid what cannot be settled from the artifact. What is visible is a substantive technical exchange, conceded in substance, moderated with deletions, and remembered by both communities as a grievance.

Limitations

The page is evidence about a 2022 discussion, not about the current state of F-Droid’s permission display, and the moderation record is incomplete by construction. Micay’s claim in the thread that the privileged-extension install path carried “multiple serious security vulnerabilities” is asserted there without detail and is not evaluated here.

Built on 2 sources (2 external).

Working out connections…