Privacy concerns have long been expressed around smart devices, and the concerns around Android apps have been studied by many past works. Over the past 10 years, we have crawled and scraped data for almost 1.9 million apps, and also stored the APKs for 135,536 of them. In this paper, we examine the trends in how Android apps have changed over time with respect to privacy and look at it from two perspectives: (1) how privacy behavior in apps have changed as they are updated over time, (2) how these changes can be accounted for when comparing third-party libraries and the app's own internals. To study this, we examine the adoption of HTTPS, whether apps scan the device for other installed apps, the use of permissions for privacy-sensitive data, and the use of unique identifiers. We find that privacy-related behavior has improved with time as apps continue to receive updates, and that the third-party libraries used by apps are responsible for more issues with privacy. However, we observe that in the current state of Android apps, there has not been enough of an improvement in terms of privacy and many issues still need to be addressed.
翻译:长期以来,人们一直对智能设备表示隐私关切,过去许多作品也研究过安道尔装置周围的隐私关切。 在过去10年中,我们爬了近190万个应用程序的数据并刮掉了这些数据,还储存了其中135 536个应用程序的APK数据。在本文中,我们审视了安托尔装置在隐私方面如何随时间变化的趋势,并从两个角度看问题:(1) 应用程序中的隐私行为随着时间的不断更新而变化,(2) 在比较第三方图书馆和应用程序内部时如何解释这些变化。为了研究这一点,我们研究了采用HTTPS的情况,是否对其他安装的应用程序进行扫描,是否对隐私敏感数据的许可使用,以及使用独特的识别器。我们发现,随着应用程序不断得到更新,与隐私有关的行为有了改善,应用程序使用的第三方图书馆对隐私问题的责任更大。然而,我们发现,在安托尔特应用程序的现状下,隐私方面的改进不够,许多问题仍有待解决。