版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
2022/9/5新建文本文档.html
Mobileappsneeddatatofunction.That'swhyappdevelopers
askforvaryinglevelsofaccesstotheinformationonyourmobiledevice.Usually,it'stoimprovefunctionality,butoccasionallyitlacksproperjustification.
Appdevelopersmayrequestexcessiveaccesstopersonalinformationforavarietyofreasons,
including:sloppycodedevelopment,tailoringyourexperiencewhetherin-apporacrossapps,
monetizingyou,providinglegitimatefunctionalityorfornefariouspurposes(e.g.tostealdataand
resellwithoutyourknowledge).
AppleandGoogle-whomaintaintheworld'slargestmobileappecosystemsforiOSandAndroid
-havebeencrackingdownonexcessdatacollection.Thesetwomajorplatformsenforcestandards
thatappdevelopersmustmeettogainaplaceontheirrespectiveappstores,andtheycontinueto
raisethebarwhenitcomestoapppermissiontransparency.Appleevenmadeuserprivacythethemeofarecentadcampaign.
Buttheonusonproperdatahandlingcan'tfallentirelyonAppleandGoogle.Developersneedto
evaluatetheirdatacollectionpracticestominimizethepotentialprivacyimpactwhilemaintaining
functionalityintheirapps.Ontheotherhand,consumersneedtobeawareoftheprivacythatthey
aregivingupusingtheinformationavailabletothemontheirdevicesandthecontrolstheyprovidetomanagedatacollection.
file:///F:/桌面/报告审核新建文本文档.html
1/7
2022/9/5新建文本文档.html
OuranalysisofiOsapppermissions
Tobetterunderstandtheuseofapppermissionsandtheinformationthatappdevelopersaretrying
tocollect,welookedatthemetadatawithinasampleofalmost100,000popularappsacrossthe
AppStorecatalogue.Thissamplewasdeterminedbylookingattheappsthatareinstalledwithin
Wandera'scustomerbase,whichhas2.5milliondevicesundermanagementWedidnotinclude
themillionsofappsontheAppStorethathavenotachievedwidespreadadoption.Thisanalysis
wascarriedoutinQ2of2021.Themetadataanalyzedinthisresearchcomesfromaggregatedlogs
thatdonotcontainpersonalororganization-identifyinginformation.
Forouranalysistobemoreactionable,wegroupedappsbytheirAppStorecategories,allowing
readerstolookathowlogicalgroupsofappsaredesignedamongsttheirpeergroup.
file:///F:/桌面/报告审核新建文本文档.html
2/7
Camera
Whilecameraisaverycommonpermission,it'saveryriskyone.Withaccesstothecamera,abadactor
canspyonusers.Thisisthereasonwhytop-secretorganizationsdonotallowphoneswithcamerasintheirfacilitiesandwhysomevendorsdisablecameraaccessorremoveitfromthehardwaretosellto
theseorganizations.
Ina2020lawsuit,Instagramwasaccusedofmisusingthecamerapermissiontospyonusers
whentheyhadtheappopenbutweren'tinteractingwiththecamerafeature.Instagramclaimsitwasabug,andthatnocontentwasrecorded.
2022/9/5
新建文本文档.html
Topfourpermissions
Ouranalysisshowsthe
mostrequesteddatatypeisphotos,withatleasthalftheappsacrosseverycategoryrequestingaccesstophotos.
Thetopcategoriesofappsrequestingphotolibraryaccessare:
1.Photo&Video(96%).ThiscategoryincludesappssuchasYouTube,
FaceAppandSplice.
2.Shopping(87%).ThiscategoryincludesappssuchasAmazon,ShopandeBay.
3.SocialNetworking(84%).ThiscategoryincludesappssuchasFacebook,
InstagramandTwitter.
Photos
Historically,photolibraryaccesswasallornothing.
Forexample,ifauserwantedtouploadascreenshot
toTwitter,they'dhavetogiveTwitteraccessto
decadesofphotosintheirlibrary.Thereisnothing
nefariousaboutasocialmediaappneedingphoto
libraryaccess,butthislevelofaccessisexcessive
andcouldputusersatriskifpairedwithapoorly-built
app.WithiOS14,Appleintroducedmoreconsumer
controltophotopermissions.Now,whenanapp
needsthephotolibrary,itmustoffertheuserthe
choiceofallowingaccesstoselectedphotosorthe
entirelibrary.
Thecameraisthesecondmostpopularpermissionrequested.
Thetopcategoriesofappsrequesting
accesstothecameraare:
1.Photo&Video(90%)
2.ShoppingequalsecondwithSocial
Networking(83%)
3.Business(75%).ThiscategoryincludesappssuchasZoom,SlackandWebEx.
file:///F:/桌面/报告审核新建文本文档.html
3/7
Location
In2019,bothAppleandGoogleintroducedanextralayerofconsumerchoicetolocationpermissions.
PriortoiOs13,thereweretwolocationpermissions:WhenInUse(foreground)andAlways(background).Withios13,AllowOncewasintroduced,whichisconsideredatemporaryauthorization.
Similarly,priortoAndroid10,userswerepresentedwithtwooptions:allowordeny.Theformermeantlocationwasaccessedatalltimes(foregroundandbackground)andtherewasnoin-between,but
withAndroid10,tristatelocationpermissionwasintroducedsouserscouldthenselect'allowonlywhenappisinuse.’
Learnmoreaboutlocationdatamisuseinthis
investigationbyTheNewYorkTimes.
Microphone
Justlikethecamera,microphoneappaccessinthewronghandscanhaveseriousconsequences.Withtheabilitytoactivatethemicrophone,appscan
recordandtransmitprivateconversationsorlistenforwhat'sgoingonaroundyouinordertosellthisinformationtoadvertisingorganizations.Andifthepermissionwasabused,appscoulddothiswithouttheusers'knowledge.
However,iniOs14,Appleintroducedtheorange
dotthatindicateswhenyourmicrophoneisinuse
byanapp—makingiteasierforconsumerstoseeifsomethingfishyisgoingon.
2022/9/5
新建文本文档.html
Thirdonthelistofmost
popularpermissions
requestedislocation.
Thetopcategoriesofappsrequesting
locationinformationare:
1.Shopping,equalfirstwithFood&
Drink(81%).TheFood&DrinkcategoryincludesappssuchasDoorDash,
UberEatsandYelp.
2.SocialNetworking(72%)
3.Photo&Video(68%).
Thefourthmostpopularapprequestismicrophone.
Thetopcategoriesofappsrequestingaccesstothemicrophoneare:
1.SocialNetworking(69%)
2.Photo&Video(64%)
3.Business,equalthirdwithProductivity(41%).TheProductivitycategory
includesappssuchasAsana,GoogleCalendarandTimeTree.
file:///F:/桌面/报告审核新建文本文档.html
4/7
2022/9/5新建文本文档.html
Cross-appdatasharing
Thereisagreatdealofinformation-sharingthatgoesonoutsideoftheexplicitpermissionsabove.Theappsandboxisintendedtoprevent
appsfromsharingdatabetweenthem,butvarioustrackingapproaches
circumventthat.Eventhoughtheappsaren'tcommunicatingdirectlywitheachother,byconnectingvariousbackendservicesandwebinteractions,an
advertisercanpiecetogetheranaccuratepictureofauserbasedontheironline
behavior.Herearesomeexamplesofcross-appinformationsharingthatfalloutsideofthepermissionsoutlinedabove:
Informationexchangeshands(orapps)viaadvertisingidentifiersthattrackand
shareinformationaboutuserbehaviorforadtargetingpurposes,whichtheaverage
userprobablyneverrealizes.Thiscross-appinformationexchangeforadvertising
iswhyafteryousearchedfor'sourdough'onGoogle,yourInstagramfeedsuddenlystartedincludingadsforbread-bakingequipment.Recently,AppledeviceusersweregivenmorecontrolovertheirprivacywhenApplereleaseditsnewAppTracking
TransparencyfeaturewithiOS14.5.Nowappdevelopersneedtoaskwhethertheycantrackyouractivityacrossothercompanies'appsandwebsites.Note:ourpermissionsanalysisdoesnotyetincludethispermissionduetoitsnewness.
Thenextexampleconcernsthephotolibrary.AppsaccessingthephotolibrarymightalsobeaccessingGPSdataembeddedinthephotos,makingitpossibleforunwanted
partiestodecipherwhereapersonhasbeenandwhen—evenwheretheyliveand
work.LocationdatawillonlyattachtophotosifGPSisenabledforthecamera.But
ifyoudisableGPSdataforthecamera,youwilllosesomeofthebenefitsitprovides
withinthephotolibrary.Here'ssomeinformationonhowtoavoidsharingthe
locationdataofphotoswhenyousendthem.
Acaseofdatamishandlingcametolightin2020whenLinkedInandTikTokwere
accusedofcopyingtheclipboardcontentsofiOSusers.TheissuewasdiscoveredinthebetaversionofiOS14whenAppleaddedanewprivacyfeaturethatshowedaquickpop-upthatletusersknowwhenanapphasreadcontentfromtheirclipboard.Atfirstthismaynotseemconsequential,butit'snotuncommonforpeopletouseapasswordmanagerandcopy-pastecredentialsfromthepasswordmanagerintoawebsiteorapp.
file:///F:/桌面/报告审核新建文本文档.html
5/7
2022/9/5新建文本文档.html
Keytakeaways
DespiteimprovementsbybothAppleandGoogleinpromotingpersonalprivacy,
consumersneedtotakestepsoftheirowntosecuretheirdata.Thepurposeofthis
researchistoencourageuserstoconsiderthedatatheyaresharingbeforeaccepting
anyrequestthatappearsontheirdevices.Therearesomedatapointsinthisanalysis
thataren'tsurprising,andsomethatare.
Forexample,themajority(62%)ofnavigationappsrequestaccesstoyourlocation.
Itmakessenseforplacingyouonamap,butwhydoalmosthalfofthem(48%)also
requestaccesstoyourcamera?Samestoryforthe83%ofshoppingappsrequesting
accesstoyourcamera.ItmakessenseforscanningQRcodes,butwhydosomany
(87%)alsorequestaccesstoyourphotolibrary?Itpaystothinkaboutwhatanapp
actuallyneedstofunctionbeforehittingaccept.
Therearecategoriesofappsaskingformoreaccessthanothers.Accordingtoour
analysis,thesearePhoto&Video,ShoppingandSocialNetworking.Ifyouhave
ahighnumberofappsinthesecategories,considerdeletinganyyoudon'tuse
regularlytominimizetheriskofdataexposure.
Somepermissionsaremoresensitivethanothers,andthiswillvarypersontoperson.
Maybeyouworkinanindustrywhereyouhavesensitivefilesstoredinyourphoto
library,ormaybehigh-profilecontactsinyourcontactlibrary.Ifthisisthecase,
considerreviewingeachsensitivepermissionwithinyoursettingstoaudittheapps
thathaveaccesstoitsoyoucanremoveanythatmightposearisk.
file:///F:/桌面/报告审核新建文本文档.html
6/7
2022/9/5新建文本文档.html
Recommendations
Tominimizetheriskofhavingyoursensitiveinformationexposedtounwantedparties,
werecommendthefollowingadditionalprecautions:
·Readpermissionscarefullywhentheypopup.Askyourself:doesthisappneed
accesstotheprivatedatatofunction?Forexample,ifaweatherappisaskingfor
accesstoyourcameraorcontactlibrary,thinktwicebeforeaccepting,anddon't
hesitatetodenyaccesstorequeststhatyoudon'tunderstandordon'tagreewith.
·Regularlyaudityourapppermissionsettingstoseewhichappsareaccessingwhat
onyourdevice.Thingstolookfor:(1)appsyounolongeruse(considerdeleting
thembutifyoucannot,removethepermissiontosensitivedata);(2)appsthatarein
thenews(hastherebeenaburstofprivacyactivity?).
·Whenitcomestolocationdata,alwaysgrantpermission'onlywhileinuse'—which
isavailableonbothiOSandAndroid.
·Deleteappsyounolongerusetominimizetheriskofbugsappearinginoldor
abandonedapps.TherearefeaturesavailableonbothiOSandAndroidtooffload/
deleteunusedapps.
Ifyouoverseeappsforothersinabusinesscontext,considerthefollowing:
·Adoptasecuritysolutionthatoffersappvetting.Anappvettingtoolc
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 中建总公司《项目管理手册》版印刷版
- 影视制作项目执行流程及案例
- 物理八年级课程标准及目录解析
- 高校班级管理信息化系统设计
- 城市道路标志标线设置维护方案
- 创意手工坊创业方案及盈亏预算分析
- 建筑工程造价控制与案例分析
- 市政公用工程二建考前复习资料
- 中国饰品行业市场分析与竞争策略分析
- 企业增资协议
- 施工电梯基础施工方案-北京大学第一医院城南院区工程 V1
- 人教版三年级上册竖式计算练习300题及答案
- 心脏血管检查课件
- 运用PDCA循环管理提高手卫生依从性课件
- 二手房定金合同(2023版)正规范本(通用版)1
- 点因素法岗位评估体系详解
- 初中毕业英语学业考试命题指导
- DB63T 1933-2021无人机航空磁测技术规范
- 绘本这就是二十四节气春
- 开车前安全环保检查表(PSSR )
- 浑河浑南拦河坝海漫改造工程项目环评报告
评论
0/150
提交评论