Goodbye Tracking? Impact of iOS App Tracking Transparency and Privacy Labels

04/07/2022
by   Konrad Kollnig, et al.
0

Tracking is a highly privacy-invasive data collection practice that has been ubiquitous in mobile apps for many years due to its role in supporting advertising-based revenue models. In response, Apple introduced two significant changes with iOS 14: App Tracking Transparency (ATT), a mandatory opt-in system for enabling tracking on iOS, and Privacy Nutrition Labels, which disclose what kinds of data each app processes. So far, the impact of these changes on individual privacy and control has not been well understood. This paper addresses this gap by analysing two versions of 1,759 iOS apps from the UK App Store: one version from before iOS 14 and one that has been updated to comply with the new rules. We find that Apple's new policies, as promised, prevent the collection of the Identifier for Advertisers (IDFA), an identifier for cross-app tracking. Smaller data brokers that engage in invasive data practices will now face higher challenges in tracking users - a positive development for privacy. However, the number of tracking libraries has roughly stayed the same in the studied apps. Many apps still collect device information that can be used to track users at a group level (cohort tracking) or identify individuals probabilistically (fingerprinting). We find real-world evidence of apps computing and agreeing on a fingerprinting-derived identifier through the use of server-side code, thereby violating Apple's policies. We find that Apple itself engages in some forms of tracking and exempts invasive data practices like first-party tracking and credit scoring. We also find that the new Privacy Nutrition Labels are sometimes inaccurate and misleading. Overall, our findings suggest that, while tracking individual users is more difficult now, the changes reinforce existing market power of gatekeeper companies with access to large troves of first-party data and motivate a countermovement.

READ FULL TEXT
research
03/14/2023

The Overview of Privacy Labels and their Compatibility with Privacy Policies

Privacy nutrition labels provide a way to understand an app's key data p...
research
02/27/2023

Before and after China's new Data Laws: Privacy in Apps

Privacy in apps is a topic of widespread interest because many apps coll...
research
01/20/2021

Bolder is Better: Raising User Awareness through Salient and Concise Privacy Notices

This paper addresses the question whether the recently proposed approach...
research
04/13/2021

The AppChk Crowd-Sourcing Platform: Which third parties are iOS apps talking to?

In this paper we present a platform which is usable by novice users with...
research
11/14/2022

Buying Privacy: User Perceptions of Privacy Threats from Mobile Apps

As technology and technology companies have grown in power, ubiquity, an...
research
06/09/2021

Auditing Network Traffic and Privacy Policies in Oculus VR

Virtual reality (VR) is an emerging technology that enables new applicat...
research
02/07/2018

Measuring third party tracker power across web and mobile

Third-party networks collect vast amounts of data about users via web si...

Please sign up or login with your details

Forgot password? Click here to reset