A Survey of Smartphone Users’ Concerns

As security researchers, our goal is to protect end users. But what should we protect users from? What do users worry or care about? There’s not much consensus: Android, iOS, and Windows Phone all warn users about different risks of applications.

To help answer this question, I asked 3,115 smartphone how upset they would be if various negative events happened on their smartphones. I asked each user about 12 of 99 possible risks. For example: “How upset would you be if an application deleted all of the events on your calendar, without asking you first?”

I ranked the 99 risks by the amount of user concern. (Full ranking here, last page.) The highest-ranked risks pertain to financial or data loss, and the lowest-ranked risks pertain to phone settings (Bluetooth connections, sound, etc.). Notably, all four of the location-related risks ranked in the bottom half. This makes me question the huge amount of attention that researchers pay to location privacy. Users seem to care a lot more about their contacts, photos, and text messages than about their location.

This work is still ongoing; I’m planning to run some follow-up studies. If there’s a research question about user concerns that you’d like answered, let me know – I might be able to answer it with a follow-up study.

Comments: 1 Comment
Categories: Mobile security, Usability

Vulnerabilities in Chrome Extensions

In fall 2011, Nicholas Carlini and I reviewed 100 Chrome extensions, including the 50 most popular ones. We found that 40% of the extensions contained some type of vulnerability, and 27% of the extensions contained core extension vulnerabilities (i.e., the most severe class of vulnerability). In an earlier blog post, I wrote about some of the vulnerabilities.

I’m now releasing the full report, which contains our methodology, the full set of findings, and the list of vulnerable extensions. We e-mailed the developers of all of the extensions with contact information, but the following extensions still remain unpatched:

    Google Translate 1.2.3.1, RSS Subscription Extension (by Google) 2.1.3, Awesome Screenshot: Capture & Annotate 3.0.4, Speed Dial 2.1, SocialPlus! 2.5.4, Fast YouTube Search 1.2, SmileyCentral 1.0.0.3, Select To Get Maps 1.1.1, Forecastfox 2.0.10, The Huffington Post 1.0.5, X-notifier 0.8.2, Print Plus 1.0.5.0, 4chan 4chrome 9001.47, ScribeFire 1.7, Blank Canvas Script Handler 0.0.17, Happy Status 1.0.1, me2Mini 0.0.81, Noooo button 1, Nu.nl TV gids 1.1.3, Smart Photo Viewer on Facebook 1.3.0.1, Democracy Now! 1.1

If you use one of these extensions, I recommend contacting the developer and asking him or her to fix the extension. However, there is no need for you to be alarmed: we have no reason to believe that the vulnerabilities are being actively exploited by anyone.

Comments: 1 Comment
Categories: Web security

The Usability of Android Permissions

I recently ran two user studies to determine the effectiveness of Android permissions in practice. Our results are now available as a technical report: Android Permissions: Attention, Comprehension, Behavior. Android permissions are supposed to inform users of the risks of using applications. However, researchers have speculated that users ignore them. We decided to establish how well they actually work.

Here are our primary findings:

  • Attention. In both a self-reported Internet survey and observational laboratory study, 17% of participants paid attention during a given installation. 42% of laboratory study participants were completely unaware of permissions.
  • Comprehension. Only 3% of Internet survey respondents could correctly answer three multiple-choice comprehension questions. No lab study participants could correctly describe all of the permissions of familiar apps.
  • Behavior. A majority of Internet survey respondents and 20% of lab study participants say they have decided not to install an app in the past because of its permissions.

We categorized 20% of the lab study participants as “power users”: they sometimes look at permissions and scored reasonably well on our comprehension test. It’s possible that a small fraction of “power users” could write negative reviews when they encounter troubling permission requests, thereby protecting other users.

Our studies identified several factors that contribute to the low attention and comprehension rates. Here are two of them: Continue reading

Comments: 1 Comment
Categories: Mobile security, Usability

Give Me Your Best Guess

If you had to guess:

  1. What percentage of Android users know about permissions?
  2. What percentage of Android users look at permissions during installation?

This is a serious, non-rhetorical question. Please leave your guesses as comments.

Update: Interesting! I was curious about whether anyone actually had faith that the permission system works well. (It looks like the answer is no.)

Comments: 11 Comments
Categories: Mobile security, Usability

Research Methods: Pre-Testing A Survey With A Focus Group

Today, I tried out a new survey pre-test technique: a focus group. In the past, I’ve relied solely on individual feedback and pilot studies. It was a fantastic experience, and the feedback was much more detailed than what I have been able to get from one-on-one interviews and pilot studies.

Recruitment
I placed advertisements on Craigslist soliciting participants for the discussion. I offered $30 per person for an hour. About thirty people responded within a few hours, and I selected nine people who represented a diverse age range.

Format
After they signed consent forms, participants took the survey on their laptops. I gave each participant a notepad and asked them to take notes. Next, I kicked off the discussion with a round-robin ice breaker activity. The ice-breaker was effective at getting people comfortable. We then discussed each of the survey questions in order, with the survey projected at the front of the room. For each question, I asked: “Do you understand the terms used in the question?”, “Were you able to answer the question?”, “Are the options sufficient to express your opinion?”, “Was there anything else that you disliked about the question?” As necessary, I tailored each of these discussion points to the survey question that we were discussing.

Benefits of the focus group

  • The major benefit of a group discussion is that some people will bring up points that resonate with others, triggering additional comments that would not have come about in a one-on-one conversation. For example, one person said, “I don’t like X because of Y.” Another person replied, “It seemed strange to me, too, but I didn’t know why. You’re right. I really wish that it said Z instead.”
  • There were also several occasions where the participants disagreed. It was valuable for me to see both perspectives at once.
  • In one-on-one interviews, shy interviewees will answer questions monosyllabically or not at all. This is awkward in a one-on-one setting. In the focus group, it’s easy to ask, “Jane, I saw you shaking your head a little. What do you think of what Bob said?”

Continue reading

Comments: 2 Comments
Categories: Usability

Behavioral Advertising on TV

NBC takes on the topic of Internet privacy with this clip from Parks and Recreation.

“So it learns information about me? Seems like an invasion of privacy.”
“Dude, if you think that’s bad, go to Google Earth and type in your address.”

Comments: 1 Comment
Categories: Web security

When Apps Do Bad Things

Researchers have been working on tools (like AppFence) to help users control how their personal information is used by applications. Recently, some colleagues and I asked 25 Android users to tell us about their bad experiences with applications, to provide insight into whether there is real user demand for more control over how applications access and use their personal information.

We asked, “Have you ever uninstalled (or stopped using) an application because you didn’t like what it was doing with your personal information?” 6 of 25 people said yes:

  • Spam. Three people said that they’d uninstalled apps that sent them spam and/or used their accounts to send spam to others. For example, one person reported that an application had misused her Twitter account: “I logged on and it was posting crazy stuff like, ‘Oh! I just won $1000 while doing this or something’ … And I’m like, that definitely wasn’t me, it was the app.”
  • Social privacy. One person said that she didn’t like how an application shared information about her on Facebook. “I went on [app name] to buy tickets and if you went on Facebook you could see who bought tickets where and what their names are. So I chose not to buy tickets on [app name] because I didn’t want anyone to see where I sat if they went on to Facebook.”
  • Programming errors. Two people said that they had used applications with logic errors that affected their personal information. For example, “But what it did was, if I sent a text message to one person, it would send it to everyone in my list.”
  • General privacy. One person read a Wall Street Journal article that listed applications that share user data with other parties like advertising networks. “…I went through my phone and went through that list, and got rid of all of them except for one. … Shazam was the only one I kept, because the functionality. I know people are taking my stuff but functionality-wise I need that.”

Two other users said that they would uninstall applications if the applications misused their personal information, but they had no way of knowing how their data was being used.

Comments: 4 Comments
Categories: Mobile security, Usability

Advertising and Android Permissions

Recently, I had the opportunity to sit down and chat with a few Android users who aren’t computer scientists. One of the things that we talked about was advertising.  If a person mentioned using an app with ads, I asked, “Do you think the advertiser can use the app’s permissions?”  Twelve people answered this question:

  • Yes: 5
  • No: 2
  • I don’t know: 5

People were right to be confused by the question.  The correct answer is complex (check out the last paragraph of this blog post).  However, I wasn’t trying to test people.  Instead, I wanted to get a general sense of what people think the relationship is between ads, applications, and permissions.

Some people didn’t think the advertiser should get permissions:

  • “I gave these permissions to [app name]. No permissions to the ad.”
  • “They can have advertisements like TV has advertisements, a million people’s phones can have advertisements, but they shouldn’t have access to your phone just cause they have advertisements on them.  They shouldn’t get a permission at all.”
  • “I guess it’s possible, depending on their relationship with whoever made the app. But I couldn’t imagine why they would have permissions that would go through my phone state and identity. … I hope not.”

On the other hand, some people said that they think it’s reasonable for advertisers to get access to information about them via permissions:

  • “I’ve read that advertisers are sending people things on mobile devices based on, like– you might be near some store, so you might get something that pops up on your phone that says, ‘We’re giving a two for one deal today in the next two hours,’ or so.”
  • “They probably get at least location-based so they know where people are accessing it and where they’re downloading it from, how they’re getting to their ads most likely.”
  • “The advertisers could use what I look up on the Internet to better, I guess, suit the ads that they put in for my specific [ads]. When I’m searching for things if it has access to what I look for on the Internet, it could find and put ads that are similar to interests I’ve looked up on the Internet to my phone.”

These are just simple anecdotes, but I find them interesting.

It’s hard to gauge how people feel about advertising and permissions because they don’t understand Android permissions to begin with. For example, the person who mentioned Internet search history made that statement because he misunderstood an unrelated permission that does not give access to Internet search history.

Can an advertiser use an app’s permissions?
When you see an advertisement in an application, there are three parties.  First, there’s the application itself, which asks the user for permissions.  Second, there’s the advertising library, which is shoved into the application and therefore gains access to all of the app’s permissions.  Third, the advertising library displays the advertisement itself.  The advertisement can’t directly use any of the permissions, but the advertising library might share information with the company that is running the ad.  So if you see an REI ad while playing a game, you should know that the invisible ad library gets all of the game’s permissions, and it might share information like your location with REI.

P.S. Thanks to Elizabeth Ha, Serge Egelman, Ariel Haney, and Erika Chin, who interviewed users with me.

Comments: 2 Comments
Categories: Mobile security, Usability

Android vs iOS

Android malware has managed to sneak into the official Android Market for a few months at a time, but Apple’s review process has (thus far) prevented any iOS malware from entering the Apple App Store.

When I tell people this, I commonly get two questions:

  1. Does that mean iOS is better than Android?
  2. Should Google start reviewing all Android apps?

My answer is that security is only one part of the mobile application ecosystem. Apple’s reviewers filter out malware, but they also censor application developers for other reasons. If you are a security-conscious user who downloads lots of apps, then maybe iOS is “better” for you. If you want apps that let you tether your phone or view adult content, then maybe Android is “better” for you.

Regardless of one’s opinion about the tradeoff between security and freedom of development, I predict that problems with the app review process will arise in the next few years. App markets are growing rapidly, and the review process is slow and human-intensive. I don’t see how it can keep scaling up. For example: neither Apple nor Google could manually review the entire Internet. I think the security community needs to find better, automated ways to address the problem of mobile malware — but this will be hard to do until there is more mobile malware out there to study.

Comments: 1 Comment
Categories: Mobile security

Fortify Adds Android Permission Support

Erika Chin and I have been working with Fortify’s Security Research Group to integrate Android permission warnings into Fortify SCA. Specifically, Fortify SCA now warns Android developers when permissions are missing or unnecessary (i.e., when an application is over- or under-privileged). Here’s an excerpt from the Q4 release notes:

Google Android – Updated support now provides improved detection of underprivileged Android applications, including missing permissions for privileged API calls, as well as sending and receiving intents. In addition, Fortify now detects overprivileged Android applications that request unnecessary permissions. This update introduces three new categories related to privilege management.

Hopefully this will help developers avoid permission errors.

For those of you looking for a free alternative, Stowaway can tell you if your application has extra permissions. Stowaway has the advantage of working on binaries (i.e., libraries), but it doesn’t warn developers about missing permissions (which Fortify SCA does).

Comments: 2 Comments
Categories: Developer tips, Mobile security