In 2008, Android’s security model was a single dialog box: “This app wants access to: [list of everything]. Install?” If you tapped Install, the app got everything. If you tapped Cancel, you couldn’t use the app. There was no granularity, no runtime control, no encryption by default, no verified boot, no SELinux, no sandboxing beyond basic Linux UID separation.