On The Ridiculousness of Notice and Consent: Contradictions in App Privacy Policies

On The Ridiculousness of Notice and Consent: Contradictions in App Privacy Policies
复制标题

DOI:
--
复制
发表时间:
2019-05
期刊:
--
影响因子:
--
通讯作者:
Ehimare Okoyomon;N. Samarin;Primal Wijesekera;Amit Elazari Bar On;Narseo Vallina-Rodriguez;Irwin Reyes;Álvaro Feal;Serge Egelman
Ehimare Okoyomon;N. Samarin;Primal Wijesekera;Amit Elazari Bar On;Narseo Vallina-Rodriguez;Irwin Reyes;Álvaro Feal;Serge Egelman
中科院分区:
其他
文献类型:
--
作者:
Ehimare Okoyomon;N. Samarin;Primal Wijesekera;Amit Elazari Bar On;Narseo Vallina-Rodriguez;Irwin Reyes;Álvaro Feal;Serge Egelman

文献摘要

相似文献

信息时代占主导地位的隐私框架依赖于“通知和同意”的概念。也就是说,服务提供商通常会通过隐私政策披露他们的数据收集做法,然后用户可以同意他们的条款。然而,大多数用户不太可能理解这些披露,这在很大程度上是由于含糊、欺骗性和误导性的声明。通过将实际的收集和共享做法与隐私政策中的披露进行比较,我们展示了问题的范围。通过分析来自Google Play商店的68,051个应用程序、它们相应的隐私政策以及观察到的数据传输,我们调查了针对家庭设计(DFF)计划中应用程序的潜在虚假陈述、关于第三方数据共享的披露不一致以及关于安全数据传输的相互矛盾的披露。我们发现,在8030个DFF应用程序(即针对儿童的应用程序)中,9.1%的人声称他们的应用程序不是针对儿童的,30.6%的人声称不知道收到的数据来自儿童。此外,我们观察到,在68,051个应用程序中,10.5%的应用程序与第三方服务提供商共享个人身份标识,但没有在其隐私政策中声明任何个人身份标识,只有22.2%的应用程序明确指定了第三方。这最终使用户不仅很难,而且在大多数情况下不可能确定他们的个人数据在哪里被处理。此外,我们发现,9424个应用程序在传输个人识别码时没有使用TLS,但其中28.4%的应用程序声称采取了安全数据传输的措施。归根结底,这些披露与实际应用行为之间的差异说明了通知与同意框架的荒谬。
The dominant privacy framework of the information age relies on notions of “notice and consent.” That is, service providers will disclose, often through privacy policies, their data collection practices, and users can then consent to their terms. However, it is unlikely that most users comprehend these disclosures, which is due in no small part to ambiguous, deceptive, and misleading statements. By comparing actual collection and sharing practices to disclosures in privacy policies, we demonstrate the scope of the problem. Through analysis of 68,051 apps from the Google Play Store, their corresponding privacy policies, and observed data transmissions, we investigated the potential misrepresentations of apps in the Designed For Families (DFF) program, inconsistencies in disclosures regarding third-party data sharing, as well as contradictory disclosures about secure data transmissions. We find that of the 8,030 DFF apps (i.e., apps directed at children), 9.1% claim that their apps are not directed at children, while 30.6% claim to have no knowledge that the received data comes from children. In addition, we observe that 10.5% of 68,051 apps share personal identifiers with third-party service providers, yet do not declare any in their privacy policies, and only 22.2% of the apps explicitly name third parties. This ultimately makes it not only difficult, but in most cases impossible, for users to establish where their personal data is being processed. Furthermore, we find that 9,424 apps do not use TLS when transmitting personal identifiers, yet 28.4% of these apps claim to take measures to secure data transfer. Ultimately, these divergences between disclosures and actual app behaviors illustrate the ridiculousness of the notice and consent framework.