1
C y L a b U s a b l e P r i v a c y & S e c u r i t y L a b
- r
a t
- r
y H T T P : / / C U P S . C S . C M U . E D U
Privacy, Law, and Engineering & Smartphones Public Policy - - PowerPoint PPT Presentation
CyLab Privacy, Law, and Engineering & Smartphones Public Policy Rebecca Balebako y & c S a e v c i u r P r Advisor: Dr. Lorrie Cranor i t e y l b L a a s b U o b r a a t L o y r C y U H D T T E
1
C y L a b U s a b l e P r i v a c y & S e c u r i t y L a b
a t
y H T T P : / / C U P S . C S . C M U . E D U
2
3
4
5
6
Android 2012 iOS 2012
7
8
9
Hazim Almuhimedi, Florian Schaub, …
10
Googe Play Store, Oct 19, 2014 https://support.google.com/googleplay/answer/6014972?p=app_permissions&rd=1
11
– Location – Contacts – Calendar – Reminders – Photos – Camera – Microphone – Health Kit – Motion Activity – Social
12
13
14
15
16
17
18
19
Credits – Michael Heiss / FlickR
20
signatures and/or voice print.)
made or received.)
numbers, postal, email and text addresses.)
such as transaction data.)
measure health or wellness.)
photos, text, or video.)
21
purposes including offering products and services that may interest you.)
by law.)
companies that provide common tools and information for apps about app consumers.)
sharing.)
22
Is Your Inseam a Biometric? A Case Study on the Role of Usability Studies in Developing Public Policy Balebako, R., Shay, R., Cranor, L. In USEC 2014
23
24
25
26
27
28
29
30
31
100% 50% 50% 100%
Strongly disagree Disagree Neutral Agree Strongly agree I would want notifications like this when I download or use an app The privacy notice gave me information I care about It is important for me to remember what the notification says over time I was surprise by what I learned from the privacy notification This notification could be improved so I understand it better I expected the app to collect my browser history and share it with ad networks.
32
33
C y L a b U s a b l e P r i v a c y & S e c u r i t y L a b
a t
y H T T P : / / C U P S . C S . C M U . E D U
34
35
35
36
36
37
37
38
38
39
39
40
40
41
41
42
43
Behavior Collect or Store Parameters specific to my app 84% Which apps are installed 74% Location 72% Sensor information (not location-related) 63% Contacts 54% Password 36%
44
11 34 45 110 28
45
46