Comparing Privacy Labels of Applications in Android and iOS

被引:2
|
作者
Khandelwal, Rishabh [1 ]
Nayak, Asmit [1 ]
Chung, Paul [1 ]
Fawaz, Kassem [1 ]
机构
[1] Univ Wisconsin Madison, Madison, WI 53705 USA
关键词
privacy nutrition labels; google data safety section; apple privacy label; consistency; cross-platform analysis;
D O I
10.1145/3603216.3624967
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The increasing concern for privacy protection in mobile apps has prompted the development of tools such as privacy labels to assist users in understanding the privacy practices of applications. Both Google and Apple have mandated developers to use privacy labels to increase transparency in data collection and sharing practices. These privacy labels provide detailed information about apps' data practices, including the types of data collected and the purposes associated with each data type. This offers a unique opportunity to understand apps' data practices at scale. In this study, we conduct a large-scale measurement study of privacy labels using apps from the Android Play Store (n=2.4M) and the Apple App Store (n=1.38M). We establish a common mapping between iOS and Android labels, enabling a direct comparison of disclosed practices and data types between the two platforms. By studying over 100K apps, we identify discrepancies and inconsistencies in self-reported privacy practices across platforms. Our findings reveal that at least 60% of all apps have different practices on the two platforms. Additionally, we explore factors contributing to these discrepancies and provide valuable insights for developers, users, and policymakers. Our analysis suggests that while privacy labels have the potential to provide useful information concisely, in their current state, it is not clear whether the information provided is accurate. Without robust consistency checks by the distribution platforms, privacy labels may not be as effective and can even create a false sense of security for users. Our study highlights the need for further research and improved mechanisms to ensure the accuracy and consistency of privacy labels.
引用
收藏
页码:61 / 73
页数:13
相关论文
共 50 条
  • [1] Analysis of Security Permissions on Android and iOS from a Privacy Perspective
    Luna, Carlos
    Galuppo, Raul Ignacio
    2024 L LATIN AMERICAN COMPUTER CONFERENCE, CLEI 2024, 2024,
  • [2] A Comparative Study of Android and iOS Mobile Applications' Data Handling Practices Versus Compliance to Privacy Policy
    Kununka, Sophia
    Mehandjiev, Nikolay
    Sampaio, Pedro
    PRIVACY AND IDENTITY MANAGEMENT: THE SMART REVOLUTION, 2018, 526 : 301 - 313
  • [3] An empirical study of privacy labels on the Apple iOS mobile app store
    Scoccia, Gian Luca
    Autili, Marco
    Stilo, Giovanni
    Inverardi, Paola
    9TH IEEE/ACM INTERNATIONAL CONFERENCE ON MOBILE SOFTWARE ENGINEERING AND SYSTEMS, MOBILESOFT 2022, 2022, : 114 - 124
  • [4] Cross-Platform Mobile Applications for Android and iOS
    Hui, Ng Moon
    Chieng, Liu Ban
    Ting, Wen Yin
    Mohamed, Hasimah Hj
    Arshad, Muhammad Rafie Hj Mohd
    2013 6TH JOINT IFIP WIRELESS AND MOBILE NETWORKING CONFERENCE (WMNC 2013), 2013,
  • [5] Forensic Analysis of Dating Applications on Android and iOS Devices
    Hutchinson, Shinelle
    Shantaram, Neesha
    Karabiyik, Umit
    2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 837 - 848
  • [6] A Comparative Study of Misapplied Crypto in Android and iOS Applications
    Feichtner, Johannes
    PROCEEDINGS OF THE 16TH INTERNATIONAL JOINT CONFERENCE ON E-BUSINESS AND TELECOMMUNICATIONS, VOL 2: SECRYPT, 2019, : 96 - 108
  • [7] Mobile Handset Privacy: Measuring the Data iOS and Android Send to Apple and Google
    Leith, Douglas J.
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2021, PT II, 2021, 399 : 231 - 251
  • [8] Platform privacies: Governance, collaboration, and the different meanings of "privacy" in iOS and Android development
    Greene, Daniel
    Shilton, Katie
    NEW MEDIA & SOCIETY, 2018, 20 (04) : 1640 - 1657
  • [9] A privacy enforcing framework for Android applications
    Neisse, Ricardo
    Steri, Gary
    Geneiatakis, Dimitris
    Fovino, Igor Nai
    COMPUTERS & SECURITY, 2016, 62 : 257 - 277
  • [10] Privacy Consistency Analyzer for Android Applications
    Maitra, Sayan
    Suh, Bohyun
    Ghanavati, Sepideh
    2018 IEEE 5TH INTERNATIONAL WORKSHOP ON EVOLVING SECURITY & PRIVACY REQUIREMENTS ENGINEERING (ESPRE 2018), 2018, : 28 - 33