Social media applications leverage the amount of contextual data collected, correlating in real time digital and physical environment. This has many consequences, still little apprehended, that could affect the privacy of their users.
We explore the notion of "contextual integrity" when collecting data from ten hegemonic social media applications on the Android mobile platform. In other words, we measure the gap between users' expectations and effective access to their mobile resources and personal data.
This report presents three complementary studies:
1. a study of the announced collection practices (privacy policies, authorizations and permissions) to identify contextual integrity breaches;
2. a practical analysis for which we instrumented the mobile to collect the frequency and circumstances of access to location and text messaging resources, both regulated by authorizations;
3. and a proof of concept of a solution allowing the user to parameterize permissions such that they are granted to the applications according to the context of use.
We highlight contextual integrity breaches, both at the level of the announced collection practices study (unclear policies, inconsistencies, structural problems), and the practical study (capture of the location every second for some applications). The proposed solution mitigates these issues and has little impact on application functionality.
| Date | 30 Jul 2018 |
|---|
| Original language | French |
|---|
| Awarding Institution | - École de technologie supérieure
|
|---|
| Supervisor | Jean-Marc Robert (Supervisor) |
|---|
Bouganim, T. (Author),
Robert (Supervisor),
30 Jul 2018Student thesis: Master's thesis › Master in Engineering: Information Technology Engineering