A privacy and security analysis of early-deployed COVID-19 contact tracing Android apps

被引:30
|
作者
Hatamian, Majid [1 ]
Wairimu, Samuel [2 ]
Momen, Nurul [2 ,3 ]
Fritsch, Lothar [2 ]
机构
[1] Northumbria Univ, Dept Comp & Informat Sci, Newcastle Upon Tyne, Tyne & Wear, England
[2] Karlstad Univ, Dept Math & Comp Sci, Karlstad, Sweden
[3] Blekinge Inst Technol, Karlskrona, Sweden
关键词
COVID-19; Contact tracing app; Privacy; Security; Vulnerability; GDPR; Pandemic;
D O I
10.1007/s10664-020-09934-4
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
As this article is being drafted, the SARS-CoV-2/COVID-19 pandemic is causing harm and disruption across the world. Many countries aimed at supporting their contact tracers with the use of digital contact tracing apps in order to manage and control the spread of the virus. Their idea is the automatic registration of meetings between smartphone owners for the quicker processing of infection chains. To date, there are many contact tracing apps that have already been launched and used in 2020. There has been a lot of speculations about the privacy and security aspects of these apps and their potential violation of data protection principles. Therefore, the developers of these apps are constantly criticized because of undermining users' privacy, neglecting essential privacy and security requirements, and developing apps under time pressure without considering privacy- and security-by-design. In this study, we analyze the privacy and security performance of 28 contact tracing apps available on Android platform from various perspectives, including their code's privileges, promises made in their privacy policies, and static and dynamic performances. Our methodology is based on the collection of various types of data concerning these 28 apps, namely permission requests, privacy policy texts, run-time resource accesses, and existing security vulnerabilities. Based on the analysis of these data, we quantify and assess the impact of these apps on users' privacy. We aimed at providing a quick and systematic inspection of the earliest contact tracing apps that have been deployed on multiple continents. Our findings have revealed that the developers of these apps need to take more cautionary steps to ensure code quality and to address security and privacy vulnerabilities. They should more consciously follow legal requirements with respect to apps' permission declarations, privacy principles, and privacy policy contents.
引用
收藏
页数:51
相关论文
共 50 条
  • [31] Mind the GAP: Security & Privacy Risks of Contact Tracing Apps
    Baumgaertner, Lars
    Dmitrienko, Alexandra
    Freisleben, Bernd
    Gruler, Alexander
    Hoechst, Jonas
    Kuehlberg, Joshua
    Mezini, Mira
    Mitev, Richard
    Miettinen, Markus
    Muhamedagic, Anel
    Thien Duc Nguyen
    Penning, Alvar
    Pustelnik, Dermot
    Roos, Filipp
    Sadeghi, Ahmad-Reza
    Schwarz, Michael
    Uhl, Christian
    2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 458 - 467
  • [32] Privacy and Data Protection in COVID-19 Contact Tracing Apps: An Analysis from a Socio-Technical System Design Perspective
    Roesler, Michael
    Liston, Paul
    HCI INTERNATIONAL 2022 - LATE BREAKING PAPERS: INTERACTION IN NEW MEDIA, LEARNING AND GAMES, 2022, 13517 : 126 - 141
  • [33] Proximity tracing applications for COVID-19: data privacy and security
    Betarte, Gustavo
    Campo, Juan Diego
    Delgado, Andrea
    Ezzatti, Pablo
    Gonzalez, Laura
    Martin, Alvaro
    Martinez, Rodrigo
    Muracciole, Barbara
    2021 XLVII LATIN AMERICAN COMPUTING CONFERENCE (CLEI 2021), 2021,
  • [34] COVID-19 and contact tracing apps: The importance of theory and conceptual models
    Jannati, Nazanin
    INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 2023, 170
  • [35] COVID-19 contact tracing apps in Europe, technological feat or failure?
    Santos, A.
    Rachadell, J.
    Vareda, R.
    EUROPEAN JOURNAL OF PUBLIC HEALTH, 2022, 32
  • [36] Technological and analytical review of contact tracing apps for COVID-19 management
    Gupta, Rajan
    Pandey, Gaurav
    Chaudhary, Poonam
    Pal, Saibal K.
    JOURNAL OF LOCATION BASED SERVICES, 2021, 15 (03) : 198 - 237
  • [37] Privacy-preserving COVID-19 Contact Tracing Blockchain
    Tahir, Shahzaib
    Tahir, Hasan
    Sajjad, Ali
    Rajarajan, Muttukrishnan
    Khan, Fawad
    JOURNAL OF COMMUNICATIONS AND NETWORKS, 2021, 23 (05) : 360 - 373
  • [38] GoCoronaGo: Privacy Respecting Contact Tracing for COVID-19 Management
    Simmhan, Yogesh
    Rambha, Tarun
    Khochare, Aakash
    Ramesh, Shriram
    Baranawal, Animesh
    George, John Varghese
    Bhope, Rahul Atul
    Namtirtha, Amrita
    Sundararajan, Amritha
    Bhargav, Sharath Suresh
    Thakkar, Nihar
    Kiran, Raj
    JOURNAL OF THE INDIAN INSTITUTE OF SCIENCE, 2020, 100 (04) : 623 - 646
  • [39] COVID-19 Fight Enlists Digital Technology: Contact Tracing Apps
    Leslie, Mitch
    ENGINEERING, 2020, 6 (10) : 1064 - 1066
  • [40] GoCoronaGo: Privacy Respecting Contact Tracing for COVID-19 Management
    Yogesh Simmhan
    Tarun Rambha
    Aakash Khochare
    Shriram Ramesh
    Animesh Baranawal
    John Varghese George
    Rahul Atul Bhope
    Amrita Namtirtha
    Amritha Sundararajan
    Sharath Suresh Bhargav
    Nihar Thakkar
    Raj Kiran
    Journal of the Indian Institute of Science, 2020, 100 : 623 - 646