Mobile App Privacy Compliance: Automated Technology to Help Regulators, App Stores and Developers
نویسندگان
چکیده
The copyright is held by the author/owner. Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee. Poster presented at the 13th Symposium on Usable Privacy and Security (SOUPS 2017). Abstract Mobile apps have to satisfy various privacy requirements. Notably, app publishers are often obligated to provide a privacy policy and notify users of their apps’ privacy practices. But how can a user tell whether an app behaves as its policy promises? In this study we are introducing a scalable system to analyze and predict Android apps’ compliance with privacy requirements. We report on our collaboration with three regulatory agencies. We present analysis results for 17,991 apps. We expect to soon be able to support app store-wide analysis (i.e., over a million apps) and to track changes in non-compliant behavior over time. Beyond its use by regulators and activists our technology is also intended to assist app developers and app store owners in their internal assessments of privacy requirement compliance.
منابع مشابه
Automated Analysis of Privacy Requirements for Mobile Apps
Mobile apps have to satisfy various privacy requirements. App publishers are often obligated to provide a privacy policy and notify users of their apps’ privacy practices. But how can we tell whether an app behaves as its policy promises? In this study we introduce a scalable system to help analyze and predict Android apps’ compliance with privacy requirements. Our system is not only intended f...
متن کاملToward a Framework for Detecting Privacy Policy Violation in Android Application Code
Mobile applications frequently access sensitive personal information to meet user or business requirements. Because this information is sensitive, regulators increasingly require mobile app developers to publish privacy policies that describe what information is collected, for what purpose is the information used and with whom it is shared. Furthermore, regulators have fined companies when thes...
متن کاملA Data Transparency Framework for Mobile Applications
— In today's mobile application marketplace, the ability of consumers to make informed choices regarding their privacy is extremely limited. Consumers largely rely on privacy policies and app permission mechanisms, but these do an inadequate job of conveying how information will be collected, used, stored, and shared. Mobile application developers go largely unrewarded for making apps more priv...
متن کاملAgile Development of a Custom-Made Vocabulary Mobile Application: A Critical Qualitative Approach
There have been some observed studies and developed applications (apps), with a concentration on Mobile Assisted Language Learning (MALL), and no consideration of communicative needs of the learners; besides, these studies focused on either the theoretical aspects or the utilization of the available apps in the market (Burston & Athanasiou, 2020). Hence, Vocabulary Guru (VG), a custom-made mobi...
متن کاملPrivacyInformer: An Automated Privacy Description Generator for the MIT App Inventor
With the advent of “smart” mobile phones and ubiquitous mobile applications, the pace at which people generate, access, and acquire data has accelerated significantly. In this thesis, we first examine how privacy issues in the mobile apps market compromise the well-being of both app consumers and developers, noting that one important problem is the lack of usable privacy policies. Subsequently,...
متن کامل