2
1 Comment

Why app permissions matter more than passwords on smartphones

Most people focus on strong passwords for mobile security, but I’ve realized permissions play a much bigger role.

Once an app gets access to the camera, mic, location, or storage, it can keep collecting data in the background—even if your password is strong. Passwords protect login access, but permissions control ongoing data access.

While reviewing apps on my phone, I noticed many apps still had permissions enabled that weren’t really needed anymore. Limiting access to “only while using” and removing unused permissions made a noticeable difference in background activity.

Curious how others here think about mobile privacy—do you regularly review app permissions, or mostly rely on passwords and locks?

on December 30, 2025
  1. 1

    This is such an underappreciated point. Passwords are a one-time gate, but permissions are an ongoing lease on your data.

    I've started thinking of it like real estate - giving an app camera access is like handing over keys to your house. Doesn't matter how strong your front door lock is if they're already inside.

    The "only while using" option was a game-changer. Also worth checking which apps have "Nearby Devices" or "Background App Refresh" enabled - those are the sneaky ones.

    For founders building mobile apps: being transparent about why you need each permission (and requesting them contextually, not all at once on first launch) builds way more trust than collecting everything upfront.