论文标题

不是您的普通应用:对Android浏览器的大规模隐私分析

Not Your Average App: A Large-scale Privacy Analysis of Android Browsers

论文作者

Pradeep, Amogh, Feal, Álvaro, Gamba, Julien, Rao, Ashwin, Lindorfer, Martina, Vallina-Rodriguez, Narseo, Choffnes, David

论文摘要

移动浏览器的透明度和隐私行为仍然被研究界广泛探索。实际上,与常规的Android应用相反,移动浏览器可能会呈现矛盾的隐私行为。一方面,他们可以访问(并可以暴露)敏感用户数据的唯一组合,从用户的浏览历史记录到受许可保护的个人身份信息(PII),例如唯一的标识符和地理位置。但是,另一方面,它们也处于独特的位置,可以通过实现与其他方面的数据共享来保护用户的隐私。在本文中,我们对数百个Android Web浏览器在浏览会话过程中如何保护或揭示用户数据的比较和经验分析。为此,我们从Google Play商店和四家中国应用商店收集了迄今为止最大的Android浏览器数据集。然后,我们开发了一种新颖的分析管道,该管道结合了静态和动态分析方法,以查找广泛的隐私增强(例如,广告障碍)和隐私伤害行为(例如,向第三方发送浏览历史记录,未验证TLS证书,不验证PII-不可享受PII-不可享受的识别者,包括brows-tos-toss-tos-tos-tos toshirties)。我们发现,在Google Play和中国商店上的各种流行应用程序都具有这些隐私性损害行为,包括声称在其描述中具有隐私性增强的应用程序。总体而言,我们的研究不仅提供了有关浏览器采用和透明度的重要考虑考虑因素的新见解,而且还提供了自动应用分析系统(例如沙盒)需要特定于上下文的分析来揭示这种隐私行为。

The transparency and privacy behavior of mobile browsers has remained widely unexplored by the research community. In fact, as opposed to regular Android apps, mobile browsers may present contradicting privacy behaviors. On the one end, they can have access to (and can expose) a unique combination of sensitive user data, from users' browsing history to permission-protected personally identifiable information (PII) such as unique identifiers and geolocation. However, on the other end, they also are in a unique position to protect users' privacy by limiting data sharing with other parties by implementing ad-blocking features. In this paper, we perform a comparative and empirical analysis on how hundreds of Android web browsers protect or expose user data during browsing sessions. To this end, we collect the largest dataset of Android browsers to date, from the Google Play Store and four Chinese app stores. Then, we developed a novel analysis pipeline that combines static and dynamic analysis methods to find a wide range of privacy-enhancing (e.g., ad-blocking) and privacy-harming behaviors (e.g., sending browsing histories to third parties, not validating TLS certificates, and exposing PII -- including non-resettable identifiers -- to third parties) across browsers. We find that various popular apps on both Google Play and Chinese stores have these privacy-harming behaviors, including apps that claim to be privacy-enhancing in their descriptions. Overall, our study not only provides new insights into important yet overlooked considerations for browsers' adoption and transparency, but also that automatic app analysis systems (e.g., sandboxes) need context-specific analysis to reveal such privacy behaviors.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源