A privacy and security analysis of early-deployed COVID-19 contact tracing Android apps

被引:30
|
作者
Hatamian, Majid [1 ]
Wairimu, Samuel [2 ]
Momen, Nurul [2 ,3 ]
Fritsch, Lothar [2 ]
机构
[1] Northumbria Univ, Dept Comp & Informat Sci, Newcastle Upon Tyne, Tyne & Wear, England
[2] Karlstad Univ, Dept Math & Comp Sci, Karlstad, Sweden
[3] Blekinge Inst Technol, Karlskrona, Sweden
关键词
COVID-19; Contact tracing app; Privacy; Security; Vulnerability; GDPR; Pandemic;
D O I
10.1007/s10664-020-09934-4
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
As this article is being drafted, the SARS-CoV-2/COVID-19 pandemic is causing harm and disruption across the world. Many countries aimed at supporting their contact tracers with the use of digital contact tracing apps in order to manage and control the spread of the virus. Their idea is the automatic registration of meetings between smartphone owners for the quicker processing of infection chains. To date, there are many contact tracing apps that have already been launched and used in 2020. There has been a lot of speculations about the privacy and security aspects of these apps and their potential violation of data protection principles. Therefore, the developers of these apps are constantly criticized because of undermining users' privacy, neglecting essential privacy and security requirements, and developing apps under time pressure without considering privacy- and security-by-design. In this study, we analyze the privacy and security performance of 28 contact tracing apps available on Android platform from various perspectives, including their code's privileges, promises made in their privacy policies, and static and dynamic performances. Our methodology is based on the collection of various types of data concerning these 28 apps, namely permission requests, privacy policy texts, run-time resource accesses, and existing security vulnerabilities. Based on the analysis of these data, we quantify and assess the impact of these apps on users' privacy. We aimed at providing a quick and systematic inspection of the earliest contact tracing apps that have been deployed on multiple continents. Our findings have revealed that the developers of these apps need to take more cautionary steps to ensure code quality and to address security and privacy vulnerabilities. They should more consciously follow legal requirements with respect to apps' permission declarations, privacy principles, and privacy policy contents.
引用
收藏
页数:51
相关论文
共 50 条
  • [21] Privacy Preservation of COVID-19 Contact Tracing Data
    Olawoyin, Anifat M.
    Leung, Carson K.
    Wen, Qi
    20TH INT CONF ON UBIQUITOUS COMP AND COMMUNICAT (IUCC) / 20TH INT CONF ON COMP AND INFORMATION TECHNOLOGY (CIT) / 4TH INT CONF ON DATA SCIENCE AND COMPUTATIONAL INTELLIGENCE (DSCI) / 11TH INT CONF ON SMART COMPUTING, NETWORKING, AND SERV (SMARTCNS), 2021, : 288 - 295
  • [22] Contact-tracing apps and alienation in the age of COVID-19
    Rowe, Frantz
    Ngwenyama, Ojelanki
    Richet, Jean-Loup
    EUROPEAN JOURNAL OF INFORMATION SYSTEMS, 2020, 29 (05) : 545 - 562
  • [23] Covid-19 contact-tracing apps and the public/private co-production of security
    Markussen, Havard Rustad
    SECURITY DIALOGUE, 2023, 54 (05) : 436 - 454
  • [24] Time to evaluate COVID-19 contact-tracing apps
    Colizza, Vittoria
    Grill, Eva
    Mikolajczyk, Rafael
    Cattuto, Ciro
    Kucharski, Adam
    Riley, Steven
    Kendall, Michelle
    Lythgoe, Katrina
    Bonsall, David
    Wymant, Chris
    Abeler-Dorner, Lucie
    Ferretti, Luca
    Fraser, Christophe
    NATURE MEDICINE, 2021, 27 (03) : 361 - 362
  • [25] Coping with COVID-19 using contact tracing mobile apps
    Li, Chenglong
    Li, Hongxiu
    Fu, Shaoxiong
    INDUSTRIAL MANAGEMENT & DATA SYSTEMS, 2023, 123 (05) : 1440 - 1464
  • [26] Time to evaluate COVID-19 contact-tracing apps
    Vittoria Colizza
    Eva Grill
    Rafael Mikolajczyk
    Ciro Cattuto
    Adam Kucharski
    Steven Riley
    Michelle Kendall
    Katrina Lythgoe
    David Bonsall
    Chris Wymant
    Lucie Abeler-Dörner
    Luca Ferretti
    Christophe Fraser
    Nature Medicine, 2021, 27 : 361 - 362
  • [27] Towards a seamful ethics of Covid-19 contact tracing apps?
    Andrew S. Hoffman
    Bart Jacobs
    Bernard van Gastel
    Hanna Schraffenberger
    Tamar Sharon
    Berber Pas
    Ethics and Information Technology, 2021, 23 : 105 - 115
  • [28] Towards a seamful ethics of Covid-19 contact tracing apps?
    Hoffman, Andrew S.
    Jacobs, Bart
    van Gastel, Bernard
    Schraffenberger, Hanna
    Sharon, Tamar
    Pas, Berber
    ETHICS AND INFORMATION TECHNOLOGY, 2021, 23 (SUPPL 1) : 105 - 115
  • [29] COVID-19 contact tracing apps: UK public perceptions
    Samuel, G.
    Roberts, S. L.
    Fiske, A.
    Lucivero, F.
    McLennan, S.
    Phillips, A.
    Hayes, S.
    Johnson, S. B.
    CRITICAL PUBLIC HEALTH, 2022, 32 (01) : 31 - 43
  • [30] What Users Think of COVID-19 Contact-Tracing Apps: An Analysis of Eight European Apps
    Garousi, Vahid
    Cutting, David
    Felderer, Michael
    IEEE SOFTWARE, 2022, 39 (03) : 22 - 30