See this or this.
Just a taste:
Just a taste:
Careful out there.This information might be obvious to some, but many users and application developers are not aware of the implications of default read access. In theory, this means that an application with only the INTERNET permission can upload the entire contents of the SD card to a server on the internet. While this does not constitute a direct breach of the Android security model, it should always be in the back of the user’s and developers’ minds. Also, should data be stored on the SD card, the sensitivity of this data should be considered.