scholarly journals Evaluating the Data Privacy of Mobile Applications Through Crowdsourcing

Author(s):  
Ioannis Chrysakis ◽  
Giorgos Flouris ◽  
George Ioannidis ◽  
Maria Makridaki ◽  
Theodore Patkos ◽  
...  

Consumers are largely unaware regarding the use being made to the data that they generate through smart devices, or their GDPR-compliance, since such information is typically hidden behind vague privacy policy documents, which are often lengthy, difficult to read (containing legal terms and definitions) and frequently changing. This paper describes the activities of the CAP-A project, whose aim is to apply crowdsourcing techniques to evaluate the privacy friendliness of apps, and to allow users to better understand the content of Privacy Policy documents and, consequently, the privacy implications of using any given mobile app. To achieve this, we developed a set of tools that aim at assisting users to express their own privacy concerns and expectations and assess the mobile apps’ privacy properties through collective intelligence.

Author(s):  
Ioannis Chrysakis ◽  
Giorgos Flouris ◽  
George Ioannidis ◽  
Maria Makridaki ◽  
Theodore Patkos ◽  
...  

The utilisation of personal data by mobile apps is often hidden behind vague Privacy Policy documents, which are typically lengthy, difficult to read (containing legal terms and definitions) and frequently changing. This paper discusses a suite of tools developed in the context of the CAP-A project, aiming to harness the collective power of users to improve their privacy awareness and to promote privacy-friendly behaviour by mobile apps. Through crowdsourcing techniques, users can evaluate the privacy friendliness of apps, annotate and understand Privacy Policy documents, and help other users become aware of privacy-related aspects of mobile apps and their implications, whereas developers and policy makers can identify trends and the general stance of the public in privacy-related matters. The tools are available for public use in: https://cap-a.eu/tools/.


Hypertension ◽  
2020 ◽  
Vol 76 (Suppl_1) ◽  
Author(s):  
Khaled Abdelrahman ◽  
Josh Bilello ◽  
Megna Panchbhavi ◽  
Mohammed S Abdullah

Introduction: Diabetes mobile applications (apps) that help patients monitor disease have led to privacy concerns. We aimed to assess privacy policies for diabetes mobile applications with a focus on data transmission to outside parties. Methods: The App Store was used to gather apps pertaining to diabetes by searching “diabetes” and “blood sugar”. Two readers evaluated privacy policies (PP) including data sharing and storing techniques for mention of 27 predetermined criteria. All network traffic generated while loading and using the app was intercepted by a man-in-the-middle attack to listen to data delivered between the sender and receiver of data transmissions. A packet analyzer determined contents of transmission, where data was sent, and if transmission contained user data. Results: Of 35 apps evaluated, 29 (83%) had PP. The most frequent transmission destinations were Google (n=130 transmissions), Kamai Technologies (n=53), Facebook (n=38) and Amazon (n=33). 35 of 35 apps (100%) were transmitting data to a third party. 2 of 2 (100%) of those who had a privacy policy without mention of a third party transmitted data to a third party. 8 of 8 (100%) apps who mentioned they would not transmit to a third party were found to do so. 19 of 19 (100%) apps who mentioned they would transmit data to a third party were found to do so. All apps (n=6) without a privacy policy were found to be transmitting data to a third party. Conclusion: Most diabetes apps on the App store have accessible PP. All apps evaluated transmitted data to a third party, even when the policy stated this would not occur. As mobile applications are increasingly utilized by patients, it is important to warn of privacy implications.


Author(s):  
Sandeep Goyal ◽  
Anandan Pillai ◽  
Sumedha Chauhan

Healthcare initiatives backed by electronic-governance (e-governance) principles have contributed well to the extant literature and practice. Governments and healthcare systems across the world were taken aback by the swamping impact of the COVID-19 pandemic. However, they reacted quickly by developing contact-tracing mobile applications (apps) for creating awareness, providing information about various healthcare initiatives, and helping citizens to use the required information in case of emergency. The major challenge was to develop such e-governance interventions in a short time and ensure their quick adoption among the masses. Hence, it is worthwhile to investigate the factors leading to the adoption of such e-governance initiatives, especially in the context of a widespread pandemic situation. The present study is an attempt to analyze the factors driving the intention to use contact tracing mobile apps launched by governments globally during the COVID-19 pandemic. We have conducted the study in the context of India, where the government launched a community-driven contact tracing mobile app for its citizens during the COVID-19 pandemic in April 2020. The study adopted an empirical approach to test how epistemic value, convenience value, conditional value, functional value, and privacy concerns influenced the intention to use this approach. The study found that intention to use such an app was positively influenced by functional value, which in turn was positively influenced by convenience and conditional values. It suggests that the convenience of using the app, perceived seriousness of the pandemic (i.e., conditional value), and utilitarian benefits (i.e., functional value) of the contact-tracing mobile app enhanced its acceptance. However, its novelty (i.e., epistemic value) and privacy concerns are not significant predictors of intention to use. The study recommends that the government should place more emphasis on improving the functional value which is driven by convenience and context-specific features to push the use of an e-governance initiative during the crisis.


2020 ◽  
Author(s):  
Reham AlTamime ◽  
Vincent Marmion ◽  
Wendy Hall

BACKGROUND Mobile apps and IoT-enabled smartphones technologies facilitate collecting, sharing, and inferring from a vast amount of data about individuals’ location, health conditions, mobility status, and other factors. The use of such technology highlights the importance of understanding individuals’ privacy concerns to design applications that integrate their privacy expectations and requirements. OBJECTIVE This paper explores, assesses, and predicts individuals’ privacy concerns in relation to collecting and disclosing data on mobile health apps. METHODS We designed a questionnaire to identify participants’ privacy concerns pertaining to a set of 432 mobile apps’ data collection and sharing scenarios. Participants were presented with 27 scenarios that varied across three categorical factors: (1) type of data collected (e.g. health, demographic, behavioral, and location); (2) data sharing (e.g., whether it is shared, and for what purpose); and, (3) retention rate (e.g., forever, until the purpose is satisfied, unspecified, week, or year). RESULTS Our findings show that type of data, data sharing, and retention rate are all factors that affect individuals’ privacy concerns. However, specific factors such as collecting and disclosing health data to a third-party tracker play a larger role than other factors in triggering privacy concerns. CONCLUSIONS Our findings suggest that it is possible to predict privacy concerns based on these three factors. We propose design approaches that can improve users’ awareness and control of their data on mobile applications


2021 ◽  
Author(s):  
◽  
Jessica Aitken

<p>The practice of contemporary heritage interpretation has seen increased investment in digital technologies and more recently in mobile applications. However, few empirical studies assess how effective mobile apps are to the visitor experience of heritage sites. What kind of visitor experience do mobile apps provide? How do mobile apps deliver on the aims of interpretation for heritage sites? What types of apps work best? What are the challenges for developers and heritage professionals?  A qualitative research approach is used to examine two case studies; High Street Stories: the life and times of Christchurch’s High Street Precinct and IPENZ Engineering Tours: Wellington Heritage Walking Tour. These case studies ask what kind of experience mobile apps offer as an interpretation tool at these heritage sites. To investigate the topic, email interviews were carried out with heritage professionals and digital developers; together with qualitative interviews with visitors recruited to visit the case study sites using the mobile applications.   This study explores two current examples of mobile app technology in the heritage sector in a New Zealand context. The results of this study aim to augment current literature on the topic of digital interpretation. This study seeks to offer heritage managers and interpreters some key factors to consider when making decisions regarding the methods used to present and interpret heritage sites to visitors and in developing new interpretation and digital strategies that include mobile applications. Although each scenario presents its particular set of considerations and all heritage sites are different, it is hoped these recommendations can be applied and offer working models and strategies.</p>


Author(s):  
Brenda Mak ◽  
Leigh Jin

Mobile apps have been transforming how individuals and organizations share information and conduct business. This research studies the relationships among user readiness factors, privacy concerns, and user acceptance of mobile app stores. A survey was conducted among college smart phone users. Results indicate that the privacy concerns construct has a direct negative effect on purchase intention of mobile apps in the app store. In addition, user readiness has a direct positive effect on attitudes to the app store, and a net positive effect on purchase intention of apps in the app store. Implications of our findings were discussed.


Author(s):  
Zerin Mahzabin Khan ◽  
Rukhsana Ahmed ◽  
Devjani Sen

No previous research on cancer mobile applications (apps) has investigated issues associated with the data privacy of its consumers. The current chapter addressed this gap in the literature by assessing the content of online privacy policies of selected cancer mobile apps through applying a checklist and performing an in-depth critical analysis to determine how the apps communicated their privacy practices to end users. The results revealed that the privacy policies were mostly ambiguous, with content often presented in a complex manner and inadequate information on the ownership, use, disclosure, retention, and collection of end users' personal data. These results highlight the importance of improving the transparency of privacy practices in health and fitness cancer mobile apps to clearly and effectively communicate how end users' personal data are collected, stored, and shared. The chapter concludes with recommendations and discussion on practical implications for stakeholders like cancer app users, developers, policymakers, and clinicians.


2018 ◽  
Vol 2018 ◽  
pp. 1-13 ◽  
Author(s):  
Efthimios Alepis ◽  
Constantinos Patsakis

The extensive adoption of mobile devices in our everyday lives, apart from facilitating us through their various enhanced capabilities, has also raised serious privacy concerns. While mobile devices are equipped with numerous sensors which offer context-awareness to their installed apps, they can also be exploited to reveal sensitive information when correlated with other data or sources. Companies have introduced a plethora of privacy invasive methods to harvest users’ personal data for profiling and monetizing purposes. Nonetheless, up till now, these methods were constrained by the environment they operate, e.g., browser versus mobile app, and since only a handful of businesses have actual access to both of these environments, the conceivable risks could be calculated and the involved enterprises could be somehow monitored and regulated. This work introduces some novel user deanonymization approaches for device and user fingerprinting in Android. Having Android AOSP as our baseline, we prove that web pages, by using several inherent mechanisms, can cooperate with installed mobile apps to identify which sessions operate in specific devices and consequently further expose users’ privacy.


2019 ◽  
Author(s):  
José Javier Flors-Sidro ◽  
Mowafa Househ ◽  
Alaa Abd-Alrazaq ◽  
Josep Vidal-Alaball ◽  
Luis Fernandez-Luque ◽  
...  

BACKGROUND Mobile health has become a major channel for the support of people living with diabetes. Accordingly, the availability of diabetes mobile apps has been steadily increasing. Most of the previous reviews of diabetes apps have focused on the apps’ features and their alignment with clinical guidelines. However, there is a lack of knowledge on the actual compliance of diabetes apps with privacy and data security aspects. OBJECTIVE The aim of this study was to assess the level of privacy of diabetes mobile applications to contribute to raising the awareness of final users, developers and data-protection governmental regulators towards privacy issues. METHODS A web scraper capable of retrieving Android apps’ privacy-related information, particularly the dangerous permissions required by the apps, was developed with the aim of analyzing privacy aspects related to diabetes apps. Following the research selection criteria, the original 882 apps were narrowed down to 497 apps, which were finally included in the analysis. RESULTS 60% of diabetes apps may request dangerous permissions, which poses a significant risk for the users’ data privacy. In addition, 30% of the apps do not return their privacy policy website. Moreover, it was found that 40% of apps contain advertising, and that some apps that declared not to contain it actually had ads. 95.4% of the apps were free of cost, and those belonging to the Medical and Health and Fitness categories were the most popular. However, final users do not always realize that the free-apps’ business model is largely based on advertising, and consequently, on sharing or selling their private data, either directly or indirectly, to unknown third-parties. CONCLUSIONS The aforementioned findings unquestionably confirm the necessity to educate users and raise their awareness regarding diabetes apps privacy aspects. For this purpose, this research recommends properly and comprehensively training users, ensuring that governments and regulatory bodies enforce strict data protection laws, devising much tougher security policies and protocols in Android and in the Google Play Store, and the implication and supervision of all stakeholders in the apps’ development process.


Data ◽  
2021 ◽  
Vol 6 (10) ◽  
pp. 106
Author(s):  
Chrisa Tsinaraki ◽  
Irena Mitton ◽  
Marco Minghini ◽  
Marina Micheli ◽  
Alexander Kotsev ◽  
...  

The COVID-19 pandemic led to a multi-faceted global crisis, which triggered the diverse and quickly emerging use of old and new digital tools. We have developed a multi-channel approach for the monitoring and analysis of a subset of such tools, the COVID-19 related mobile applications (apps). Our approach builds on the information available in the two most prominent app stores (i.e., Google Play for Android-powered devices and Apple’s App Store for iOS-powered devices), as well as on relevant tweets and digital media outlets. The dataset presented here is one of the outcomes of this approach, uses the content of the app stores and enriches it, providing aggregated information about 837 mobile apps published across the world to fight the COVID-19 crisis. This information includes: (a) information available in the mobile app stores between 20 April 2020 and 2 August 2020; (b) complementary information obtained from manual analysis performed until mid-September 2020; and (c) status information about app availability on 28 February 2021, when we last collected data from the mobile app stores. We highlight our findings with a series of descriptives, which depict both the activities in the app stores and the qualitative information that was revealed by the manual analysis.


Sign in / Sign up

Export Citation Format

Share Document