Is there no way to restrict folder access by app ?! - Security Discussion

I'm currently using AFWall+ and Xprivacy to manage which app can access my data and which app can access the Internet.
I'm rooted and on CyanogenMod btw.
I basically just block Internet access for every apps and for those apps that really do require Internet access, I restrict what exactly these apps can access.
But there there are a couple of huge flaws in that system:
Let's say you install a hypothetical app to share your photos. That app needs Internet access and access to a folder containing your photos.
But there is no way to restrict access to just a single folder. You either grant access to your whole file system or you deny it completely.
So this app could easily spy on other things like your videos, music, confidential documents or whatever.
I know there are ways to secure folders with passwords, but when I put a password on my documents folder, my document reader won't be able to access that folder anymore.
Is there an app or Xposed module that I could use to simply specify which app can access which folders?

Hi,
I don't know if this Xposed module AppOpsXposed could be an answer for you.

AppOpsXposed just let's you change app permissions, as in "Storage access: Yes/No". The same can be done with Xprivacy more safely and it is not what I'm looking for at all. I basically want to be able to set permissions on a per-folder basis.

Related

[Q] How do I allow only one app to access data connection?

As the title says: How do I allow only one app which I select to access the data connection?
To clarify, I want all apps to have permission to access the data connection, just not at the same time. (I want only the app I'm using to access the internet at that time.)
Disable background data in settings and use Droidwall (search in market)
Press the THX BUTTON BELOW if I HELPED !!!
Contact me:
My website: Droidiser.in
Facebook
My Facebook Page
Add me to your circles
Twitter
I'm not rooted, so I can't use Droidwall. And, apps seem to access the internet even when background data is disabled
bumpbumpbumpbumpbumpbumpbumpbumpbump
These are the incentives I tired my phone for, Droidwall and other things
Sent from my Galaxy S Infinity on xda free
You have to root it if you wanna block anything. Then Droidwall or LBE.
Wrong section btw.
via XDApp

[Completed] Is there a way to block apps from accessing internet in Lollipop?

I did some research on internet and most of the articles related to this topic are either outdated or suggests using some kind of another app.
I want to block internet access to apps I've installed without installing any other app or firewall. I was wondering whether there are any inbuilt settings in Lollipop which has this feature?
Basically I am worried that apps like Clean Master, etc. would be snooping around my msgs, contacts lists, pics and sending them to their servers.
Hi,
Thanks for using XDA Assist.
No, there's no built-in feature in Lollipop to block Internet access. That's not a priority for Google
However I do recommend you to use AFWall+ (root required) or NetGuard.

How to block internet connections for specific apps?

Hi, I have a Samsung Galaxy S8+ which I purchased 3 or 4 months ago but I have never used it.
The device has been stored in a drawer because the first time I logged in I could not find a way to block Internet access for specific applications.
Now I would like to start using the device, but only if I can block Internet access (mobile data AND Wi-Fi) for specific applications.
I do not want to allow Internet access to applications like Contacts, Messages, Goople Play Store, Google Play Services, Gallery, etc., etc., etc.
So the question is:
How can I block Internet access (both mobile data and Wi-Fi) to all the applications I choose to? I am not talking about third party apps like firewalls... I want to block Internet access using the built-in (stock) apps/features/whatever... I mean by making use of the options that the device has by default.
Thanks in advance!
No there's no way to limit one app from getting to the Internet built into the phone. You could turn off the sync settings for some of them like Contacts, Gallery, etc.
I have to ask, why does it matter if those apps can get to the Internet? I mean how do you expect to install apps if you were able to block the Play Store?
Un-sync is the only thing you can do, https://play.google.com/store/apps/details?id=eu.faircode.netguard&hl=en is the other option.
What do you mean you can't? What about adhell2? As far as I know, it has internet permission for individual apps, and it doesn't need root...?
mjones73 said:
No there's no way to limit one app from getting to the Internet built into the phone. You could turn off the sync settings for some of them like Contacts, Gallery, etc.
I have to ask, why does it matter if those apps can get to the Internet? I mean how do you expect to install apps if you were able to block the Play Store?
Click to expand...
Click to collapse
Many of those apps have permissions like "storage", "phone ID", "contacts", "calendar", "camera", "microphone", etc...
Therefore, when those applications are given Internet access they will be able to send all our data via the Internet ...
That's why it's so important to block them having Internet access.
For example, if an application has access to your data, to your storage or your contacts, it stands to reason that it should not have Internet access...
Google or any other companies are not my tutor or my parents (I'm old enough to have grand children). They should not have, simultaneously, access to my storage data, contacts, calendar, and Internet access to send out all those data and info...
My son has a Huawei P10 and that device allows the user to block Internet access to specific apps.
So if this Samsung device does not have a way to limit specific apps from getting to the Internet, then the phone is a spyware device...
With the due respect, only a completly fool would use such a compromised device.
Note: my biggest problem is not Google Play Store because it's an app which I could use without allowing permissions like "storage", "contacts", and such. But I don't use Google Play Store. I use F-Droid and (if needed) Yalp Store.
Niccolò Paganini said:
Many of those apps have permissions like "storage", "phone ID", "contacts", "calendar", "camera", "microphone", etc...
Therefore, when those applications are given Internet access they will be able to send all our data via the Internet ...
That's why it's so important to block them having Internet access.
For example, if an application has access to your data, to your storage or your contacts, it stands to reason that it should not have Internet access...
Google or any other companies are not my tutor or my parents (I'm old enough to have grand children). They should not have, simultaneously, access to my storage data, contacts, calendar, and Internet access to send out all those data and info...
My son has a Huawei P10 and that device allows the user to block Internet access to specific apps.
So if this Samsung device does not have a way to limit specific apps from getting to the Internet, then the phone is a spyware device...
With the due respect, only a completly fool would use such a compromised device.
Note: my biggest problem is not Google Play Store because it's an app which I could use without allowing permissions like "storage", "contacts", and such. But I don't use Google Play Store. I use F-Droid and (if needed) Yalp Store.
Click to expand...
Click to collapse
I was gonna say maybe use tinfoil around your phone . If you decide you want to use internet on a specific app remove the foil. But IDK if it'll work though.
dalanik said:
What do you mean you can't? What about adhell2? As far as I know, it has internet permission for individual apps, and it doesn't need root...?
Click to expand...
Click to collapse
Hmm i'll have to look into that.
eddyo1993 said:
I was gonna say maybe use tinfoil around your phone . If you decide you want to use internet on a specific app remove the foil. But IDK if it'll work though.
Click to expand...
Click to collapse
Couldn't he just keep the phone in his tinfoil hat?
Mr. Orange 645 said:
Couldn't he just keep the phone in his tinfoil hat?
Click to expand...
Click to collapse
Yes he can. He can call it a phone accessory.
Take a look at "Datally: mobile data-saving & WiFi app by Google"
https://play.google.com/store/apps/details?id=com.google.android.apps.freighter
Sent from my SM-G955F using Tapatalk
gesbon said:
Take a look at "Datally: mobile data-saving & WiFi app by Google"
https://play.google.com/store/apps/details?id=com.google.android.apps.freighter
Sent from my SM-G955F using Tapatalk
Click to expand...
Click to collapse
If Datally allows control that'd be great. You can control an apps permissions, but none are directly internet.
Niccolò Paganini said:
Many of those apps have permissions like "storage", "phone ID", "contacts", "calendar", "camera", "microphone", etc...
Therefore, when those applications are given Internet access they will be able to send all our data via the Internet ...
That's why it's so important to block them having Internet access.
For example, if an application has access to your data, to your storage or your contacts, it stands to reason that it should not have Internet access...
Google or any other companies are not my tutor or my parents (I'm old enough to have grand children). They should not have, simultaneously, access to my storage data, contacts, calendar, and Internet access to send out all those data and info...
My son has a Huawei P10 and that device allows the user to block Internet access to specific apps.
So if this Samsung device does not have a way to limit specific apps from getting to the Internet, then the phone is a spyware device...
With the due respect, only a completly fool would use such a compromised device.
Note: my biggest problem is not Google Play Store because it's an app which I could use without allowing permissions like "storage", "contacts", and such. But I don't use Google Play Store. I use F-Droid and (if needed) Yalp Store.
Click to expand...
Click to collapse
I guess I'm a fool because I don't care if Google is syncing my data so I could also get to it from my account via my PC..
Maybe you should stick to a Huawei P10 or a flip phone I guess...
Funniest thing ever!! He is complaining that his son can block internet access on his Huawei device, and then complains that his Samsung cannot due the same and therefore is a spyware device. EVEN THOUGH HUAWEI HAS BEEN PROVEN TO BE SPYING ON US CITIZENS BY THE FBI!! Like if u actually cared about your privacy you would stick with Samsung and stay far far away from Huawei
If you have root, use any firewall app available on Playstore such as AFWall+ or Droid Firewall
Niccolò Paganini said:
Many of those apps have permissions like "storage", "phone ID", "contacts", "calendar", "camera", "microphone", etc...
Therefore, when those applications are given Internet access they will be able to send all our data via the Internet ...
That's why it's so important to block them having Internet access.
For example, if an application has access to your data, to your storage or your contacts, it stands to reason that it should not have Internet access...
Google or any other companies are not my tutor or my parents (I'm old enough to have grand children). They should not have, simultaneously, access to my storage data, contacts, calendar, and Internet access to send out all those data and info...
My son has a Huawei P10 and that device allows the user to block Internet access to specific apps.
So if this Samsung device does not have a way to limit specific apps from getting to the Internet, then the phone is a spyware device...
With the due respect, only a completly fool would use such a compromised device.
Note: my biggest problem is not Google Play Store because it's an app which I could use without allowing permissions like "storage", "contacts", and such. But I don't use Google Play Store. I use F-Droid and (if needed) Yalp Store.
Click to expand...
Click to collapse
Hello, i have same concerns with you. Have you find solution to this problem ?
Stock Samsung Apps like samsung music, calendar, camera etc. sending information to internet. I don't want this.
I used to use lineage os before, and this process was so simple. But now i have a s10e. I can't block internet access per apps.
Jail break your phone for true control (definitely worth it), everything you need to know is online. Tin foil ???
Found any solutions? I'd really be happy to find a way to do this without rooting my s10e.
And if you're only solution is still tin foil and think it doesn't make any sense, buy yourself a brain before answering please.
Kojackk said:
Found any solutions? I'd really be happy to find a way to do this without rooting my s10e.
Click to expand...
Click to collapse
Grab Activity Launcher on the Play Store (the one by Adam Szalkowski) and search for "Manage App Data. You can restrict access to mobile data and wifi on a per-app basis.

Mobile Device Management - MDM

well my company decided that company emails will work only under MDM. So today we tested this app on my mobile on BYOD mode as logical container.
https://www.manageengine.com/mobile-device-management/
And I am really not happy to what this app has access and I can't restrict it, because the access is enabled by admin of MDM. Please see attached screenshot.
the app has access to: camera, contacts, location, phone and storage and i can't block this access.
for contacts, phone and storage it looks like it has access only to folders in container (I hope, as i can't access my contact and documents from work profile). However accessing camera and location is not ok for me. Yes the admin of MDM app can see where i am in live and i can't block it. If I root the device the program will stop working, any other way how to prevent access to camera and location? Using oneplus 7T on Oxygen OS 10.0.15. Thinking about removing this app, but work email on the phone is almost must have for me.
wolfyy said:
well my company decided that company emails will work only under MDM. So today we tested this app on my mobile on BYOD mode as logical container.
https://www.manageengine.com/mobile-device-management/
And I am really not happy to what this app has access and I can't restrict it, because the access is enabled by admin of MDM. Please see attached screenshot.
the app has access to: camera, contacts, location, phone and storage and i can't block this access.
for contacts, phone and storage it looks like it has access only to folders in container (I hope, as i can't access my contact and documents from work profile). However accessing camera and location is not ok for me. Yes the admin of MDM app can see where i am in live and i can't block it. If I root the device the program will stop working, any other way how to prevent access to camera and location? Using oneplus 7T on Oxygen OS 10.0.15. Thinking about removing this app, but work email on the phone is almost must have for me.
Click to expand...
Click to collapse
Whenever a device is enrolled with MDM mobile device management solution, you do not have any control over it. Only an IT admin can make any changes to the device.
The IT admins configure the MDM agent on the device via the MDM server. This includes policy configuration, apps, and content push as well as security controls.

How clipboard should be implemented

On iPhone, the clipboard retains data only for about 20 minutes, and there is no concept of clipboard history.
On Android, different OEMs have different implementations. Samsung has a very neat clipboard history feature that allows one to copy something quickly and paste it elsewhere.
Here is the problem:
The clipboard retains the last copied item until the phone is rebooted. This allows any app that can access clipboard to see what is there, and may be keep a record of it too in its own data (although I don't think this is possible unless the user manually pastes it somewhere).
HOW CLIPBOARD SHOULD BE IMPLEMENTED​
1. Clipboard should be automatically erased by the OS every 20 minutes or so.
2. Clipboard Access should be a setting and users should be able to allow/ deny access per app (just like they can for other permissions like Camera, Microphone, etc.).
3. Clipboard History should be retained in a secure encrypted storage, so user can access it whenever he wants. No app should have access to the history. User must manually copy it each time it is required.
Use ColorNote to retain copies and hyperlinks. Auto backup to SD card or cloud.
I use it to store bookmarks as well.
blackhawk said:
Use ColorNote to retain copies and hyperlinks. Auto backup to SD card or cloud.
I use it to store bookmarks as well.
Click to expand...
Click to collapse
That requires me to create a note each time, which is not convenient. Hope you're aware of the restrictions with clipboard starting with Android Q. I welcome this move to block clipboard monitoring by 3rd party apps.
If the OS allows to keep clipboard history, it should ensure no apps have access to it without user intervention.
TheMystic said:
That requires me to create a note each time, which is not convenient. Hope you're aware of the restrictions with clipboard starting with Android Q. I welcome this move to block clipboard monitoring by 3rd party apps.
If the OS allows to keep clipboard history, it should ensure no apps have access to it without user intervention.
Click to expand...
Click to collapse
Clipboard works ok on Q... scoped storage sucks. For those who think they can install anything they want rather than being careful what they install. No saving dumb bunnies... they always end up dead.

Categories

Resources