The finding that surprised me the most was the audacity of my little old flashlight app. I was using "Tiny Flashlight + LED", which is allowed to read your phone identity and have full Internet access. A flashlight app that needs Internet access is nonsensical to me. I switched to use OI Flashlight, which requires only the permissions of camera control and preventing the device from sleeping. I discovered during my research that most flashlight apps want Internet access. The top 4 flashlight apps that appear when searching for "flashlight" on Google Play are:
All four require Internet connectivity! However, the winner of the most inappropriate and egregious permissions contest is "Brightest Flashlight Free" by Goldenshores Technologies, LLC. This popular app (over 10 million downloads) requires the following permissions:
- full Internet access
- your location (both coarse and fine)
- modify your SD card contents
- read your phone identity