Show simple item record

dc.contributor.authorGirish, Aniketh 
dc.contributor.authorGunawan, Johanna T
dc.contributor.authorMatic, Srdjan 
dc.contributor.authorReardon, Joel
dc.contributor.authorTapiador, Juan
dc.contributor.authorVallina-Rodriguez, Narseo 
dc.date.accessioned2026-09-24T10:25:09Z
dc.date.available2026-09-24T10:25:09Z
dc.date.issued2027-07
dc.identifier.urihttps://hdl.handle.net/20.500.12761/2080
dc.description.abstractHealth and fitness services on mobile platforms operate within interconnected ecosystems that aggregate sensitive data across wearable devices, mobile apps, cloud services, and third-party SDKs. Through integrations with services such as Google Fit, Fitbit, Strava, and Garmin Connect via OAuth 2.0, hundreds of apps can gain access to health records provided by other apps and devices, from heart rate to sleep patterns. Two access control mechanisms regulate health data at different levels: Android runtime permissions govern data on the device, while OAuth scopes govern data exposed through integration platforms. However, neither mechanism con strains how data is subsequently shared with third parties. Once accessed, health data and user identifiers can flow to other apps and to dozens of embedded third-party SDKs. This paper presents the first large-scale empirical study of such health-data dissemination across Android health ecosystems. We study 1,548 health apps and 11 integration platforms using an analysis pipeline that combines static and dynamic analysis, BLE device simulation, sensor fuzzing, and network traffic instrumentation to capture cross-app data flows mediated by OAuth. Our analysis shows that 42.6% of analyzed apps integrate with at least one integration platform and that 57.2% transmit sensitive health data alongside persistent IDs to third parties, enabling cross-app profiling and re-identification for secondary purposes. Finally, we uncover structural privacy risks in OAuth-authorized integrations: 32% of integrating apps forward platform-sourced records to third party SDKs, with little or no user awareness.es
dc.language.isoenges
dc.titleSweat, Sync, and Exposure: A Privacy Analysis of Interoperable Health and Fitness Ecosystems in Androides
dc.typeconference objectes
dc.conference.date19-24 July 2027es
dc.conference.placeDelft, The Netherlandses
dc.conference.titlePrivacy Enhancing Technologies Symposium (was International Workshop of Privacy Enhancing Technologies) *
dc.event.typeconferencees
dc.pres.typepaperes
dc.rights.accessRightsopen accesses
dc.acronymPETS*
dc.rankA*
dc.description.refereedTRUEes
dc.description.statusinpresses


Files in this item

This item appears in the following Collection(s)

Show simple item record