Re: Suggestion for another rejection criteria
"the OS"? which is that?
I use both. Neither do what I want, putting them together would be better.
iOS has what you say, but only on few access rights. Location, contacts, calendars, reminders, photos, bluetooth & mic. However, they do allow you to disable those access. Does it mean the apps have no possibilty of access to other items (sms, to take an example)? Does it mean that that access is un-reported, so as not to worry us?
I dunno, but the list the of access rights has increased, slowly. That list used to be even shorter before. Again, does it mean that that possibility of app access did not exist? Or was just unreported?
Take an example - security boffins have reported some success in guessing lock passwords from reading accelerometers. & accelerometers are accessible from the iOS apis. Does my barcode scanner need 3D access? I wouldn't know if it asked for it.
Android has lots more detail, but doesn't allow you to muzzle access. Yes, I can see "full network access" for my barcode scanner, but I can't turn it off, unlike iOS. Android's Plenty of Fish has a looong list of things it likes to look at: device & app history, identity, location, photos, camera, wifi connection info, phone info, full network access, vibration control, prevent phone sleep.... That's a fair bit, no? And, way more detailed than iOS's limited list.
So, no, neither iOS 7 nor KitKat is happy land for me. I'd like any app chatting outside of its own processing and files, or its own servers on the net, to report its intent. Whether it is to access another app, the network, sms, etc... And I'd like the OS to reject undeclared interactions outright.
Then again, I am the kind of paranoid fool who won't use banking apps on a mobile ;-)