[liberationtech] ChatSecure (Gibberbot!) v12 for Android is out
Nathan of Guardian
nathan at guardianproject.info
Thu Oct 24 05:34:56 PDT 2013
Ben Laurie <ben at links.org> wrote:
>On 24 October 2013 08:01, Nathan of Guardian
><nathan at guardianproject.info> wrote:
>> -----BEGIN PGP SIGNED MESSAGE-----
>> Hash: SHA1
>>
>>
>> "The Guardian Project’s award-winning open-source app “Gibberbot” for
>> Android, has been rebranded to “ChatSecure” for its version 12
>release,
>> unifying the branding with the iPhone and iPad apps, while offering
>> major updates in security from the device through the network."
>
>Can you explain why it needs these permissions:
>
>use accounts on the device
>find accounts on the device
>view configured accounts
>add or remove accounts
ChatSecure can utilize your existing, pre-authorized Google Account on your device to sign into Google Talk / Hangouts chats without requiring you to enter in your password again. This makes using the app with accounts that have 2-step auth enabled quite easy, not requiring a cumbersome application password etc.
The user is prompted once to grant permission for the app to do so before any sensitive credentials are revealed. We really only need view/read account permission, but there are not fine grain enough permissions to do so in the Android API.
As a side note, we have begun exploring using the remove account permission as part of the Panic feature, allowing the user to both remove the app, and temporarily disable access to their Google account from their phone in two taps.
Thanks for taking a look!
More information about the liberationtech
mailing list