Is Your Phone You? How Privacy Policies of Mobile Apps Allow the Use of Your Personally Identifiable Information

被引:4
|
作者
Chang, Kai Chih [1 ]
Zaeem, Razieh Nokhbeh [1 ]
Barber, K. Suzanne [1 ]
机构
[1] Univ Texas Austin, Elect & Comp Engn, Austin, TX 78712 USA
关键词
HEALTH;
D O I
10.1109/TPS-ISA50397.2020.00041
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
People continue to store their sensitive information in their smart-phone applications. Users seldom read an app's privacy policy to see how their information is being collected, used, and shared. In this paper, using a reference list of over 600 Personally Identifiable Information (PII) attributes, we investigate the privacy policies of 100 popular health and fitness mobile applications in both Android and iOS app markets to find the set of personal information these apps collect, use and share. The reference list of PII was independently built from a longitudinal study at The University of Texas investigating thousands of identity theft and fraud cases where PII attributes and associated value and risks were empirically quantified. This research leverages the reference PII list to identify and analyze the value of personal information collected by the mobile apps and the risk of disclosing this information. We found that the set of PII collected by these mobile apps covers 35% of the entire reference set of PII and, due to dependencies between PII attributes, these mobile apps have a likelihood of indirectly impacting 70% of the reference PII if breached. For a specific app, we discovered the monetary loss could reach $1M if the set of sensitive data it collects is breached. We finally utilize Bayesian inference to measure risks of a set of PII gathered by apps: the probability that fraudsters can discover, impersonate and cause harm to the user by misusing only the PII the mobile apps collected.
引用
收藏
页码:256 / 262
页数:7
相关论文
共 50 条
  • [1] How to use your mobile phone in emergency situations?
    Surinyach, Anna
    [J]. REVISTA ESPANOLA DE COMUNICACION EN SALUD, 2019, : 132 - 132
  • [2] How realistic are your mobile phone tests?
    Lecklider, T
    [J]. EE-EVALUATION ENGINEERING, 1999, 38 (02): : 26 - +
  • [3] Are You Altruistic? Your Mobile Phone Could Tell
    Bati, Ghassan F.
    Singh, Vivek K.
    [J]. 2017 IEEE SMARTWORLD, UBIQUITOUS INTELLIGENCE & COMPUTING, ADVANCED & TRUSTED COMPUTED, SCALABLE COMPUTING & COMMUNICATIONS, CLOUD & BIG DATA COMPUTING, INTERNET OF PEOPLE AND SMART CITY INNOVATION (SMARTWORLD/SCALCOM/UIC/ATC/CBDCOM/IOP/SCI), 2017,
  • [4] Your WiFi is leaking: What do your mobile apps gossip about you?
    Atkinson, John S.
    Mitchell, John E.
    Rio, Miguel
    Matich, George
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 80 : 546 - 557
  • [5] How to make money from your information and keep your privacy
    Rao, Divya
    Ng, Wee Keong
    [J]. PROCEEDINGS 2015 IEEE INTERNATIONAL CONFERENCE ON BIG DATA, 2015, : 2859 - 2861
  • [6] Devils in Your Apps: Vulnerabilities and User Privacy Exposure in Mobile Notification Systems
    Lou, Jiadong
    Zhang, Xiaohan
    Zhang, Yihe
    Li, Xinghua
    Yuan, Xu
    Zhang, Ning
    [J]. 2023 53RD ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, DSN, 2023, : 28 - 41
  • [7] Mobile apps and data privacy: when the service is free, the product is your data
    Polykalas, Spyros E.
    Prezerakos, George N.
    Chrysidou, Froso D.
    Pylarinou, Eleni D.
    [J]. 2017 8TH INTERNATIONAL CONFERENCE ON INFORMATION, INTELLIGENCE, SYSTEMS & APPLICATIONS (IISA), 2017, : 444 - 448
  • [8] YOUR MOBILE PHONE IS A TRAITOR! - RAISING AWARENESS ON UBIQUITOUS PRIVACY ISSUES WITH SASQUATCH
    Bonne, Bram
    Quax, Peter
    Lamotte, Wim
    [J]. INTERNATIONAL JOURNAL ON INFORMATION TECHNOLOGIES AND SECURITY, 2014, 6 (03): : 39 - 53
  • [9] You got a hole in your belly and a phone in your hand: How US government phone subsidies shape the search for employment
    Gershon, Ilana
    Gonzales, Amy
    [J]. NEW MEDIA & SOCIETY, 2021, 23 (04) : 853 - 871
  • [10] How are your Apps Doing? QoE Inference and Analysis in Mobile Devices
    Wehner, Nikolas
    Seufert, Michael
    Schueler, Joshua
    Casas, Pedro
    Hossfeld, Tobias
    [J]. PROCEEDINGS OF THE 2021 17TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM 2021): SMART MANAGEMENT FOR FUTURE NETWORKS AND SERVICES, 2021, : 49 - 55