logoalt Hacker News

yAaktoday at 4:15 PM2 repliesview on HN

The gotcha is “I gave it permission, then revoked permission in the UI, but it still has permission.”


Replies

swiftcodertoday at 4:27 PM

That's not quite it either. It's more along the lines of "I revoked access via one mechanism, then granted it via a different mechanism, and the setting UI for the first mechanism doesn't reflect the second action".

There's no privilege escalation here, but there is a misleading privacy settings UI, which offers no obvious way to audit/revoke permissions in the second case

show 1 reply
wtallistoday at 4:30 PM

Not quite. The steps are revoking permission in the UI (which works as expected), then implicitly granting permission in a way that the UI does not reflect but quietly persists.