Apps, Trackers, Privacy, and Regulators: A Global Study of the Mobile Tracking Ecosystem
Abbas Razaghpanah, Rishab Nithyanand, Narseo Vallina-Rodriguez, Srikanth Sundaresan, Mark Allman, Christian Kreibich, Phillipa Gill
Abstract
Third-party services form an integral part of the mobile ecosystem: they ease application development and enable features such as analytics, social network integration, and app monetization through ads. However, aided by the general opacity of mobile systems, such services are also largely invisible to users. This has negative consequences for user privacy as third-party services can potentially track users without their consent, even across multiple applications. Using real-world mobile traffic data gathered by the Lumen Privacy Monitor (Lumen), a privacyenhancing app with the ability to analyze network traffic on mobile devices in user space, we present insights into the mobile advertising and tracking ecosystem and its stakeholders. In this study, we develop automated methods to detect third-party advertising and tracking services at the traffic level. Using this technique we identify 2,121 such services, of which 233 were previously unknown to other popular advertising and tracking blacklists. We then uncover the business relationships between the providers of these services and characterize them by their prevalence in the mobile and Web ecosystem. Our analysis of the privacy policies of the largest advertising and tracking service providers shows that sharing harvested data with subsidiaries and third-party affiliates is the norm. Finally, we seek to identify the services likely to be most impacted by privacy regulations such as the European General Data Protection Regulation (GDPR) and ePrivacy directives. of the device itself and with real user-stimuli while operating entirely in user-space and without requiring root access. Lumen is available for free on Google Play, and provides us with anonymized, yet rich app traffic data from its users.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cb23db78-3528-4e5a-ad98-7c7ce2c77632Cited by top-tier papers32
- 50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions SystemJoel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On et al.USENIX Security 2019 · 196 citations
- IoT Inspector: Crowdsourcing Labeled Network Traffic from Smart Home Devices at ScaleDanny Yuxing Huang, Noah J. Apthorpe, Frank Li, Gunes Acar et al.UbiComp 2020 · 171 citations
- Share First, Ask Later (or Never?) Studying Violations of GDPR's Explicit Consent in Android AppsTrung Tin Nguyen, Michael Backes, Ninja Marnau, Ben StockUSENIX Security 2021 · 70 citations
- Understanding Malicious Cross-library Data Harvesting on AndroidJice Wang, Yue Xiao, Xueqiang Wang, Yuhong Nan et al.USENIX Security 2021 · 41 citations
- Quantity vs. Quality: Evaluating User Interest Profiles Using Ad Preference ManagersMuhammad Ahmad Bashir, Umar Farooq, Maryam Shahid, Muhammad Fareed Zaffar et al.NDSS 2019 · 41 citations
Builds on4
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 798 citations
- Reliable Third-Party Library Detection in Android and its Security ApplicationsMichael Backes, Sven Bugiel, Erik DerrCCS 2016 · 345 citations
- Obfuscation-Resilient Privacy Leak Detection for Mobile Apps Through Differential AnalysisAndrea Continella, Yanick Fratantonio, Martina Lindorfer, Alessandro Puccetti et al.NDSS 2017 · 131 citations
- A Privacy Analysis of Cross-device TrackingSebastian Zimmeck, Jie S. Li, Hyungtae Kim, Steven M. Bellovin et al.USENIX Security 2017 · 72 citations
Related papers
- Freely Given Consent?: Studying Consent Notice of Third-Party Tracking and Its Violations of GDPR in Android AppsTrung Tin Nguyen, Michael Backes, Ben StockCCS 2022 · 32 citations
- Fingerprinting SDKs for Mobile Apps and Where to Find Them: Understanding the Market for Device FingerprintingMichael A. Specter, Mihai Christodorescu, Abbie Farr, Bo Ma et al.CCS 2025
- “You Are Deceived in the Pocket”: An Exploratory Study of Intrusive Advertisements in Mobile ApplicationsMiaoying Cai, Dongsun Kim, Lingling Fan, Xiangyu Zhang et al.ISSTA 2026
- Are We Getting Well-informed? An In-depth Study of Runtime Privacy Notice Practice in Mobile AppsShuai Li, Zhemin Yang, Yuhong Nan, Shutian Yu et al.CCS 2024 · 1 citation
- Where You Go Matters: A Study on the Privacy Implications of Continuous Location TrackingBenjamin Baron, Mirco MusolesiUbiComp 2021 · 21 citations
