Lalaine: Measuring and Characterizing Non-Compliance of Apple Privacy Labels at Scale

06/13/2022
by   Yue Xiao, et al.
0

As a key supplement to privacy policies that are known to be lengthy and difficult to read, Apple has launched the app privacy labels, which purportedly help users more easily understand an app's privacy practices. However, false and misleading privacy labels can dupe privacy-conscious consumers into downloading data-intensive apps, ultimately eroding the credibility and integrity of the labels. Although Apple releases requirements and guidelines for app developers to create privacy labels, little is known about whether and to what extent the privacy labels in the wild are correct and compliant, reflecting the actual data practices of iOS apps. This paper presents the first systematic study, based on our new methodology named Lalaine, to evaluate data-flow to privacy-label (flow-to-label) consistency. Lalaine analyzed the privacy labels and binaries of 5,102 iOS apps, shedding light on the prevalence and seriousness of privacy-label non-compliance. We provide detailed case studies and analyze root causes for privacy label non-compliance that complements prior understandings. This has led to new insights for improving privacy-label design and compliance requirements, so app developers, platform stakeholders, and policy-makers can better achieve their privacy and accountability goals. Lalaine is thoroughly evaluated for its high effectiveness and efficiency. We are responsibly reporting the results to stakeholders.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/14/2023

The Overview of Privacy Labels and their Compatibility with Privacy Policies

Privacy nutrition labels provide a way to understand an app's key data p...
research
06/06/2022

Longitudinal Analysis of Privacy Labels in the Apple App Store

In December of 2020, Apple started to require app developers to annotate...
research
02/27/2023

Do as You Say: Consistency Detection of Data Practice in Program Code and Privacy Policy in Mini-App

Mini-app is an emerging form of mobile application that combines web tec...
research
06/29/2023

Honesty is the Best Policy: On the Accuracy of Apple Privacy Labels Compared to Apps' Privacy Policies

Apple introduced privacy labels in Dec. 2020 as a way for developers to ...
research
06/13/2023

Unpacking Privacy Labels: A Measurement and Developer Perspective on Google's Data Safety Section

Google has mandated developers to use Data Safety Sections (DSS) to incr...
research
06/19/2023

Toward the Cure of Privacy Policy Reading Phobia: Automated Generation of Privacy Nutrition Labels From Privacy Policies

Software applications have become an omnipresent part of modern society....
research
09/28/2021

Fighting the Fog: Evaluating the Clarity of Privacy Disclosures in the Age of CCPA

Vagueness and ambiguity in privacy policies threaten the ability of cons...

Please sign up or login with your details

Forgot password? Click here to reset