• español
    • English
  • Login
  • español 
    • español
    • English
  • Tipos de Publicaciones
    • bookbook partconference objectdoctoral thesisjournal articlemagazinemaster thesispatenttechnical documentationtechnical report
Ver ítem 
  •   IMDEA Networks Principal
  • Ver ítem
  •   IMDEA Networks Principal
  • Ver ítem
JavaScript is disabled for your browser. Some features of this site may not work without it.

Sweat, Sync, and Exposure: A Privacy Analysis of Interoperable Health and Fitness Ecosystems in Android

Compartir
Ficheros
PoPETS27-WATS.pdf (2.475Mb)
Identificadores
URI: https://hdl.handle.net/20.500.12761/2080
Metadatos
Mostrar el registro completo del ítem
Autor(es)
Girish, Aniketh; Gunawan, Johanna T; Matic, Srdjan; Reardon, Joel; Tapiador, Juan; Vallina-Rodriguez, Narseo
Fecha
2027-07
Resumen
Health and fitness services on mobile platforms operate within interconnected ecosystems that aggregate sensitive data across wearable devices, mobile apps, cloud services, and third-party SDKs. Through integrations with services such as Google Fit, Fitbit, Strava, and Garmin Connect via OAuth 2.0, hundreds of apps can gain access to health records provided by other apps and devices, from heart rate to sleep patterns. Two access control mechanisms regulate health data at different levels: Android runtime permissions govern data on the device, while OAuth scopes govern data exposed through integration platforms. However, neither mechanism con strains how data is subsequently shared with third parties. Once accessed, health data and user identifiers can flow to other apps and to dozens of embedded third-party SDKs. This paper presents the first large-scale empirical study of such health-data dissemination across Android health ecosystems. We study 1,548 health apps and 11 integration platforms using an analysis pipeline that combines static and dynamic analysis, BLE device simulation, sensor fuzzing, and network traffic instrumentation to capture cross-app data flows mediated by OAuth. Our analysis shows that 42.6% of analyzed apps integrate with at least one integration platform and that 57.2% transmit sensitive health data alongside persistent IDs to third parties, enabling cross-app profiling and re-identification for secondary purposes. Finally, we uncover structural privacy risks in OAuth-authorized integrations: 32% of integrating apps forward platform-sourced records to third party SDKs, with little or no user awareness.
Compartir
Ficheros
PoPETS27-WATS.pdf (2.475Mb)
Identificadores
URI: https://hdl.handle.net/20.500.12761/2080
Metadatos
Mostrar el registro completo del ítem

Listar

Todo IMDEA NetworksPor fecha de publicaciónAutoresTítulosPalabras claveTipos de contenido

Mi cuenta

Acceder

Estadísticas

Ver Estadísticas de uso

Difusión

emailContacto person Directorio wifi Eduroam rss_feed Noticias
Iniciativa IMDEA Sobre IMDEA Networks Organización Memorias anuales Transparencia
Síguenos en:
Comunidad de Madrid

UNIÓN EUROPEA

Fondo Social Europeo

UNIÓN EUROPEA

Fondo Europeo de Desarrollo Regional

UNIÓN EUROPEA

Fondos Estructurales y de Inversión Europeos

© 2021 IMDEA Networks. | Declaración de accesibilidad | Política de Privacidad | Aviso legal | Política de Cookies - Valoramos su privacidad: ¡este sitio no utiliza cookies!