Can Systems Explain Permissions Better? Understanding Users' Misperceptions under Smartphone Runtime Permission Model
Bingyu Shen, Lili Wei, Chengcheng Xiang, Yudong Wu, Mingyao Shen, Yuanyuan Zhou, Xinxin Jin
摘要
Current smartphone operating systems enable users to manage permissions according to their personal preferences with a runtime permission model. Nonetheless, the systems provide very limited information when requesting permissions, making it difficult for users to understand permissions' capabilities and potentially induced risks. In this paper, we first investigated to what extent current system-provided information can help users understand the scope of permissions and their potential risks. We took a mixed-methods approach by collecting real permission settings from 4,636 Android users, an interview study of 20 participants, and large-scale Internet surveys of 1559 users. Our study identified several common misunderstandings on the runtime permission model among users. We found that only a very small percentage (6.1%) of users can infer the scope of permission groups accurately from the system-provided information. This indicates that the information provided by current systems is far from sufficient. We thereby explored what extra information that systems can provide to help users make more informed permission decisions. By surveying users' common concerns on apps' permission requests, we identified five types of information (i.e., decision factors) that are helpful for users' decisions. We further studied the impact and helpfulness of the factors to users' permission decisions with both positive and negative messages. Our study shows that the background access factor helps most while the grant rate helps the least. Based on the findings, we provide suggestions for system designers to enhance future systems with more permission information.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper16
- Stuck in the Permissions With You: Developer & End-User Perspectives on App Permissions & Their Privacy RamificationsMohammad Tahaei, Ruba Abu-Salma, Awais RashidCHI 2023 · 被引用 36 次
- How WEIRD is Usable Privacy and Security Research?Ayako Akiyama Hasegawa, Daisuke Inoue, Mitsuaki AkiyamaUSENIX Security 2024 · 被引用 26 次
- Les Dissonances: Cross-Tool Harvesting and Polluting in Pool-of-Tools Empowered LLM AgentsZichuan Li, Jian Cui, Xiaojing Liao, Luyi XingNDSS 2026 · 被引用 24 次
- What You Experience is What We Collect: User Experience Based Fine-Grained Permissions for Everyday Augmented RealityMelvin Abraham, Mark McGill, Mohamed KhamisCHI 2024 · 被引用 18 次
- Take Over the Whole Cluster: Attacking Kubernetes via Excessive Permissions of Third-party ApplicationsNanzi Yang, Wenbo Shen, Jinku Li, Xunqi Liu 等CCS 2023 · 被引用 15 次
它引用的顶会 Paper2
- The Feasibility of Dynamically Granted Permissions: Aligning Mobile Privacy with User PreferencesPrimal Wijesekera, Arjun Baokar, Lynn Tsai, Joel Reardon 等S&P 2017 · 被引用 156 次
- Asking for a Friend: Evaluating Response Biases in Security User StudiesElissa M. Redmiles, Ziyun Zhu, Sean Kross, Dhruv Kuchhal 等CCS 2018 · 被引用 65 次
相关 Paper
- A Large Scale Study of User Behavior, Expectations and Engagement with Android PermissionsWeicheng Cao, Chunqiu Xia, Sai Teja Peddinti, David Lie 等USENIX Security 2021 · 被引用 42 次
- Explanation Beats Context: The Effect of Timing & Rationales on Users' Runtime Permission DecisionsYusra Elbitar, Michael Schilling, Trung Tin Nguyen, Michael Backes 等USENIX Security 2021 · 被引用 25 次
- See No Evil: Phishing for Permissions with False TransparencyGüliz Seray Tuncay, Jingyu Qian, Carl A. GunterUSENIX Security 2020
- Permission vs. App Limiters: Profiling Smartphone Users to Understand Differing Strategies for Mobile Privacy ManagementAshwaq Alsoubai, Reza Ghaiumy Anaraky, Yao Li, Xinru Page 等CHI 2022 · 被引用 24 次
- SmarPer: Context-Aware and Automatic Runtime-Permissions for Mobile DevicesKatarzyna Olejnik, Italo Dacosta, Joana Soares Machado, Kévin Huguenin 等S&P 2017 · 被引用 102 次
