IDPFilter: Mitigating interdependent privacy issues in third-party apps

被引:0
|
作者
Liu, Shuaishuai [1 ]
Biczok, Gergely [1 ,2 ,3 ]
机构
[1] Budapest Univ Technol & Econ, Dept Networked Syst & Serv, CrySyS Lab, Budapest, Hungary
[2] HUN REN BME Informat Syst Res Grp, Bugapest, Hungary
[3] Univ Michigan, Dept EECS, Ann Arbor, MI USA
关键词
Interdependent privacy; Third-party apps; Permissions; Information filtering; Application programming interface;
D O I
10.1016/j.cose.2025.104321
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Third-party applications have become an essential part of today's online ecosystem, enhancing the functionality of popular platforms. However, the intensive data exchange underlying their proliferation has raised concerns about interdependent privacy (IDP). This paper investigates the IDP issues of third-party apps that were previously not studied comprehensively. Specifically, first, we analyze the permission structure of multiple app platforms, identifying permissions that have the potential to cause interdependent privacy issues by enabling a user to share someone else's personal data with an app. Second, we collect datasets and characterize the extent to which existing apps request these permissions, revealing the relationship between characteristics such as the respective app platform, the app's type, and the number of interdependent privacy-related permissions it requests. Third, we analyze why IDP is neglected by both data protection regulations and app platforms and then devise the principles that should be followed when designing a mitigation solution. Finally, based on these principles and satisfying clearly defined objectives, we propose IDPFilter, a platform-agnostic API that enables application providers to minimize collateral information collection by filtering out data collected from their users, but implicating others as data subjects. We implement a proof-of-concept prototype, IDPTextFilter, that implements the filtering logic on textual data, and provide its initial performance evaluation concerning privacy, accuracy, and efficiency.
引用
收藏
页数:17
相关论文
共 50 条
  • [31] Automated Detection and Classification of Third-Party Libraries in Large Scale Android Apps
    Wang H.-Y.
    Guo Y.
    Ma Z.-A.
    Chen X.-Q.
    Guo, Yao (yaoguo@pku.edu.cn), 1600, Chinese Academy of Sciences (28): : 1373 - 1388
  • [32] Updating apps for graphics and .NET - Third-party tools save money and time
    Purdum, Jack J.
    DR DOBBS JOURNAL, 2007, 32 (04): : 85 - +
  • [33] On the Road with Third-party Apps: Security Analysis of an In-vehicle App Platform
    Eriksson, Benjamin
    Groth, Jonas
    Sabelfeld, Andrei
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON VEHICLE TECHNOLOGY AND INTELLIGENT TRANSPORT SYSTEMS (VEHITS 2019), 2019, : 64 - 75
  • [34] Issues in third-party intervention research and the role of destruction in conflict
    Potter, Joel
    Scott, John L.
    ECONOMICS OF PEACE AND SECURITY JOURNAL, 2010, 5 (01): : 26 - +
  • [35] TrackAdvisor: Taking Back Browsing Privacy from Third-Party Trackers
    Li, Tai-Ching
    Hang, Huy
    Faloutsos, Michalis
    Efstathopoulos, Petros
    PASSIVE AND ACTIVE MEASUREMENT (PAM 2015), 2015, 8995 : 277 - 289
  • [36] THIRD-PARTY EVALUATION
    ETRIS, SF
    MATERIALS RESEARCH AND STANDARDS, 1972, 12 (11): : 7 - +
  • [37] Information Sharing and User Privacy in the Third-Party Identity Management Landscape
    Vapen, Anna
    Carlsson, Niklas
    Mahanti, Anirban
    Shahmehri, Nahid
    ICT SYSTEMS SECURITY AND PRIVACY PROTECTION, 2015, 455 : 174 - 188
  • [38] TTPCookie: Flexible Third-Party Cookie Management for Increasing Online Privacy
    Javed, Ashar
    Merz, Christian
    Schwenk, Joerg
    2014 IEEE 13TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM), 2014, : 37 - 44
  • [39] Security and Privacy Perceptions of Third-Party Application Access for Google Accounts
    Balash, David G.
    Wu, Xiaoyuan
    Grant, Miles
    Reyes, Irwin
    Aviv, Adam J.
    PROCEEDINGS OF THE 31ST USENIX SECURITY SYMPOSIUM, 2022, : 3397 - 3414
  • [40] Third-party payers
    不详
    JOURNAL OF THE AMERICAN DENTAL ASSOCIATION, 2005, 136 (10): : 1378 - 1378