The self-described “privacy conscious” “Unexpected Keyboard” app positioned itself as an internet-free keyboard that could be safely used for Termux, password entry, etc. The version they just uploaded to F-Droid, v 2.0.4, seems to be the first new version they have released here in some time. It just added full network access to its list of permissions.
While this is their right, I think there needs to be a protocol for when an app changes this permission across releases. I was only notified because after the update it came on my device’s Karma Firewall radar, which otherwise ignores apps that don’t have network permissions. Many people don’t have this set up.
I propose a temporary Anti-Feature be added to any app which toggles this permission across releases. An app shouldn’t be able to position itself as privacy-conscious non-network-accessing, gain user base, then silently toggle the permission.
Additionally I propose that F-Droid issue a warning when it sees this permission toggle. “WARNING: The version you are upgrading to has added full network access permissions”
This is a safety concern, and I do not want to see F-Droid open source apps used as vectors for spy-ware or loggers by groups that obtain or leverage ownership of apps.