Measuring Alexa Skill Privacy Practices across Three Years
Jide S. Edu, Xavier Ferrer Aran, Jose M. Such, Guillermo Suarez-Tangil
Abstract
Smart Voice Assistants are transforming the way users interact with technology. This transformation is mostly fostered by the proliferation of voice-driven applications (called skills) ofered by third-party developers through an online market. We see how the number of skills has rocked in recent years, with the Amazon Alexa skill ecosystem growing from just 135 skills in early 2016 to about 125k skills in early 2021. Along with the growth in skills, there is increasing concern over the risks that third-party skills pose to users' privacy. In this paper, we perform a systematic and longitudinal measurement study of the Alexa marketplace. We shed light on how this ecosystem evolves using data collected across three years between 2019 and 2021. We demystify developers' data disclosure practices and present an overview of the third-party ecosystem. We see how the research community continuously contribute to the market's sanitation, but the Amazon vetting process still requires signifcant improvement. We perform a responsible disclosure process reporting 675 skills with privacy issues to both Amazon and all afected developers, out of which 246 skills sufer from important issues (i.e., broken traceability). We see that 107 out of the 246 (43.5%) skills continue to display broken traceability almost one year after being reported. As a result, the overall state of afairs has improved in the ecosystem over the years. Yet, newly submitted skills and unresolved known issues pose an endemic risk. CCS CONCEPTS • Human-centered computing → Sound-based input / output; Natural language interfaces; • Security and privacy;
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ba4a16f4-4c18-46a4-8801-050a3ae4d089Cited by top-tier papers9
- Healthcare Voice AI Assistants: Factors Influencing Trust and Intention to UseXiao Zhan, Noura Abdi, William Seymour, Jose SuchCSCW 2024 · 39 citations
- Scrutinizing Privacy Policy Compliance of Virtual Personal Assistant AppsFuman Xie, Yanjun Zhang, Chuan Yan, Suwan Li et al.ASE 2022 · 31 citations
- Legal Obligation and Ethical Best Practice: Towards Meaningful Verbal Consent for Voice AssistantsWilliam Seymour, Mark Coté, Jose M. SuchCHI 2023 · 18 citations
- Voice App Developer Experiences with Alexa and Google Assistant: Juggling Risks, Liability, and SecurityWilliam Seymour, Noura Abdi, Kopo M. Ramokapane, Jide S. Edu et al.USENIX Security 2024 · 9 citations
- Understanding GDPR Non-Compliance in Privacy Policies of Alexa Skills in European MarketplacesSong Liao, Mohammed Aldeen, Jingwen Yan, Long Cheng et al.WWW 2024 · 9 citations
Builds on9
- FlowFence: Practical Data Protection for Emerging IoT Application FrameworksEarlence Fernandes, Justin Paupore, Amir Rahmati, Daniel Simionato et al.USENIX Security 2016 · 296 citations
- Skill Squatting Attacks on Amazon AlexaDeepak Kumar, Riccardo Paccagnella, Paul Murley, Eric Hennenfent et al.USENIX Security 2018 · 177 citations
- Dangerous Skills: Understanding and Mitigating Security Risks of Voice-Controlled Third-Party Functions on Virtual Personal Assistant SystemsNan Zhang, Xianghang Mi, Xuan Feng, XiaoFeng Wang et al.S&P 2019 · 160 citations
- Privacy Norms for Smart Home Personal AssistantsNoura Abdi, Xiao Zhan, Kopo M. Ramokapane, Jose M. SuchCHI 2021 · 107 citations
- An Analysis of Pre-installed Android SoftwareJulien Gamba, Mohammed Rashed, Abbas Razaghpanah, Juan Tapiador et al.S&P 2020 · 105 citations
Related papers
- Hey Alexa, is this Skill Safe?: Taking a Closer Look at the Alexa Skill EcosystemChristopher Lentzsch, Sheel Jayesh Shah, Benjamin Andow, Martin Degeling et al.NDSS 2021
- Hey Alexa, Who Am I Talking to?: Analyzing Users' Perception and Awareness Regarding Third-party Alexa SkillsAafaq Sabir, Evan Lafontaine, Anupam DasCHI 2022 · 14 citations
- Dangerous Skills Got Certified: Measuring the Trustworthiness of Skill Certification in Voice Personal Assistant PlatformsLong Cheng, Christin Wilson, Song Liao, Jeffrey Young et al.CCS 2020 · 58 citations
- SkillScanner: Detecting Policy-Violating Voice Applications Through Static Analysis at the Development PhaseSong Liao, Long Cheng, Haipeng Cai, Linke Guo et al.CCS 2023 · 7 citations
- SkillExplorer: Understanding the Behavior of Skills in Large ScaleZhixiu Guo, Zijin Lin, Pan Li, Kai ChenUSENIX Security 2020
