Lune

S&P2025顶会

Analyzing the iOS Local Network Permission from a Technical and User Perspective

David Schmidt, Alexander Ponticello, Magdalena Steinböck, Katharina Krombholz, Martina Lindorfer

2025年份
4顶会引用

摘要

In the past, malicious apps attacked routers or identified locations through local network communication. To mitigate security and privacy risks from local network access, Apple introduced a new permission with iOS 14. To be effective, the permission needs to protect against technical threats, and users must be able to make an informed permission decision. The latter is presumably hindered by the intrinsic technicality of the concept of the local network.

In this paper, we perform the first comprehensive analysis of the local network permission by studying four key aspects. We investigate the security of its implementation by systematically accessing the local network. We explore local network accesses via a large-scale dynamic analysis of 10,862 iOS and Android apps. We analyze the concepts that constitute the permission prompts, as this is all the information users get before making a decision. Based on the identified concepts, we conduct an online survey (N = 150) to comprehend users' understanding of the permission, their threat awareness, and common misconceptions.

Our work reveals two methods to bypass the permission from webviews, and that the protected local network addresses are insufficient. We show how and when apps access the local network, and how the situation differs between iOS and Android. Finally, we present the light and shadow of users' understanding of the permission. While nearly every participant is aware of at least one threat (83.11%), misconceptions are even more common (84.46%).

• We demonstrate two methods to bypass the permission and show that the protected local IP address range of the permission is insufficient.

• We analyze 10,862 cross-platform apps, out of which 152 iOS and 117 Android apps access the local network, and show differences between both platforms.

• We identify reoccurring concepts in permission prompts and present insights into the developer-specified purposes.

• We show that nearly every participant (83.11%) is aware of at least one threat but also that misconceptions are widespread, as 84.46% hold at least one.

For reproducibility and to enable future work, we publish our code to study the permission, analyze apps, extract and label permission messages, and evaluate the results at: https://github.com/SecPriv/local network.

TABLE 3: Our codebook to categorize the rationales. We assigned a code if we found one of the keywords in a rationale. The column # Apps shows the number of rationales with the code, related to the total 727 apps with rationales.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper4

问问它们各自怎么用它

它引用的顶会 Paper16

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖