Tag: mobile

The effect of developer-specified explanations for permission requests on smartphone user behavior (CHI ’14)

Abstract In Apple’s iOS 6, when an app requires access to a protected resource (e.g., location or photos), the user is prompted with a permission request that she can allow or deny. These permission request dialogs include space for developers to optionally include strings of text to explain to the user why access to the […]

When it’s better to ask forgiveness than get permission: attribution mechanisms for smartphone resources (SOUPS ’13)

Abstract Smartphone applications pose interesting security problems because the same resources they use to enhance the user experience may also be used in ways that users might find objectionable. We performed a set of experiments to study whether attribution mechanisms could help users understand how smartphone applications access device resources. First, we performed an online […]

Android permissions: user attention, comprehension, and behavior (SOUPS ’12)

Abstract Android’s permission system is intended to inform users about the risks of installing applications. When a user installs an application, he or she has the opportunity to review the application’s permission requests and cancel the installation if the permissions are excessive or objectionable. We examine whether the Android permission system is effective at warning […]

Choice architecture and smartphone privacy: there’s a price for that (WEIS ’12)

Abstract Under certain circumstances, consumers are willing to pay a premium for privacy. We explore how choice architecture affects smartphone users’ stated willingness to install applications that request varying permissions. We performed two experiments to gauge smartphone users’ stated willingness to pay premiums to limit their personal information exposure when installing new applications. We found […]

How to ask for permission (HotSec ’12)

Abstract Application platforms provide applications with access to hardware (e.g., GPS and cameras) and personal data. Modern platforms use permission systems to protect access to these resources. The nature of these permission systems vary widely across platforms. Some platforms obtain user consent as part of installation, while others display runtime consent dialogs. We propose a […]

I’ve got 99 problems, but vibration ain’t one: a survey of smartphone users’ concerns (SPSM ’12)

Abstract Smartphone operating systems warn users when third-party applications try to access sensitive functions or data. However, all of the major smartphone platforms warn users about different application actions. To our knowledge, their selection of warnings was not grounded in user research; past research on mobile privacy has focused exclusively on the risks pertained to […]

Location privacy: user behavior in the field (SPSM ’12)

Abstract Current smartphone platforms provide ways for users to control access to information about their location. For instance, on the iPhone, when an application requests access to location information, the operating system asks the user whether to grant location access to this application. In this paper, we study how users are using these controls. Do […]