Show simple item record

dc.contributor.authorReyes, Irwin
dc.contributor.authorWijesekera, Primal
dc.contributor.authorReardon, Joel
dc.contributor.authorElazari Bar On, Amit
dc.contributor.authorRazaghpanah, Abbas
dc.contributor.authorVallina-Rodriguez, Narseo 
dc.contributor.authorEgelman, Serge
dc.date.accessioned2021-07-13T09:33:32Z
dc.date.available2021-07-13T09:33:32Z
dc.date.issued2018-07-24
dc.identifier.urihttp://hdl.handle.net/20.500.12761/551
dc.description.abstractWe present a scalable dynamic analysis frame- work that allows for the automatic evaluation of the privacy behaviors of Android apps. We use our system to analyze mobile apps’ compliance with the Children’s Online Privacy Protection Act (COPPA), one of the few stringent privacy laws in the U.S. Based on our auto- mated analysis of 5,855 of the most popular free children’s apps, we found that a majority are potentially in violation of COPPA, mainly due to their use of third- party SDKs. While many of these SDKs offer configuration options to respect COPPA by disabling tracking and behavioral advertising, our data suggest that a majority of apps either do not make use of these options or incorrectly propagate them across mediation SDKs. Worse, we observed that 19% of children’s apps collect identifiers or other personally identifiable information (PII) via SDKs whose terms of service outright prohibit their use in child-directed apps. Finally, we show that efforts by Google to limit tracking through the use of a resettable advertising ID have had little success: of the 3,454 apps that share the resettable ID with advertisers, 66% transmit other, non-resettable, persistent identifiers as well, negating any intended privacy-preserving properties of the advertising ID.
dc.language.isoeng
dc.title“Won’t Somebody Think of the Children?” Examining COPPA Compliance at Scaleen
dc.typeconference object
dc.conference.date24–27 July 2018
dc.conference.placeBarcelona, Spain
dc.conference.titleThe 18th Privacy Enhancing Technologies Symposium (PETS 2018)*
dc.event.typeconference
dc.pres.typepaper
dc.type.hasVersionVoR
dc.rights.accessRightsopen access
dc.subject.keywordWeb tracking
dc.subject.keywordmeasurement
dc.subject.keyworduser privacy
dc.subject.keywordJavaScript APIs
dc.subject.keywordHTTP cookies
dc.description.refereedTRUE
dc.description.statuspub
dc.eprint.idhttp://eprints.networks.imdea.org/id/eprint/1795


Files in this item

This item appears in the following Collection(s)

Show simple item record