Mostrar el registro sencillo del ítem
Sweat, Sync, and Exposure: A Privacy Analysis of Interoperable Health and Fitness Ecosystems in Android
| dc.contributor.author | Girish, Aniketh | |
| dc.contributor.author | Gunawan, Johanna T | |
| dc.contributor.author | Matic, Srdjan | |
| dc.contributor.author | Reardon, Joel | |
| dc.contributor.author | Tapiador, Juan | |
| dc.contributor.author | Vallina-Rodriguez, Narseo | |
| dc.date.accessioned | 2026-09-24T10:25:09Z | |
| dc.date.available | 2026-09-24T10:25:09Z | |
| dc.date.issued | 2027-07 | |
| dc.identifier.uri | https://hdl.handle.net/20.500.12761/2080 | |
| dc.description.abstract | Health and fitness services on mobile platforms operate within interconnected ecosystems that aggregate sensitive data across wearable devices, mobile apps, cloud services, and third-party SDKs. Through integrations with services such as Google Fit, Fitbit, Strava, and Garmin Connect via OAuth 2.0, hundreds of apps can gain access to health records provided by other apps and devices, from heart rate to sleep patterns. Two access control mechanisms regulate health data at different levels: Android runtime permissions govern data on the device, while OAuth scopes govern data exposed through integration platforms. However, neither mechanism con strains how data is subsequently shared with third parties. Once accessed, health data and user identifiers can flow to other apps and to dozens of embedded third-party SDKs. This paper presents the first large-scale empirical study of such health-data dissemination across Android health ecosystems. We study 1,548 health apps and 11 integration platforms using an analysis pipeline that combines static and dynamic analysis, BLE device simulation, sensor fuzzing, and network traffic instrumentation to capture cross-app data flows mediated by OAuth. Our analysis shows that 42.6% of analyzed apps integrate with at least one integration platform and that 57.2% transmit sensitive health data alongside persistent IDs to third parties, enabling cross-app profiling and re-identification for secondary purposes. Finally, we uncover structural privacy risks in OAuth-authorized integrations: 32% of integrating apps forward platform-sourced records to third party SDKs, with little or no user awareness. | es |
| dc.language.iso | eng | es |
| dc.title | Sweat, Sync, and Exposure: A Privacy Analysis of Interoperable Health and Fitness Ecosystems in Android | es |
| dc.type | conference object | es |
| dc.conference.date | 19-24 July 2027 | es |
| dc.conference.place | Delft, The Netherlands | es |
| dc.conference.title | Privacy Enhancing Technologies Symposium (was International Workshop of Privacy Enhancing Technologies) | * |
| dc.event.type | conference | es |
| dc.pres.type | paper | es |
| dc.rights.accessRights | open access | es |
| dc.acronym | PETS | * |
| dc.rank | A | * |
| dc.description.refereed | TRUE | es |
| dc.description.status | inpress | es |


