Short paper: enhancing mobile application permissions with runtime feedback and constraints

  • Authors:
  • Jaeyeon Jung;Seungyeop Han;David Wetherall

  • Affiliations:
  • Microsoft Research, Redmond, WA, USA;University of Washington, Seattle, WA, USA;University of Washington, Seattle, WA, USA

  • Venue:
  • Proceedings of the second ACM workshop on Security and privacy in smartphones and mobile devices
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

We report on a field study that uses a combination of OS measurements and qualitative interviews to highlight gaps between user expectations with respect to privacy and the result of using the existing permissions architecture to install mobile apps. Most of our participants expected advertising and analytics behavior, yet they were often surprised by applications' data collection in the background and the level of data sharing with third parties that actually occurred. Given participant feedback, we propose platform support to reduce this "expectation gap" with transparency of data usage and constrained permissions.