
Research Article
Silver Surfers on the Tech Wave: Privacy Analysis of Android Apps for the Elderly
@INPROCEEDINGS{10.1007/978-3-031-25538-0_35, author={Pranay Kapoor and Rohan Pagey and Mohammad Mannan and Amr Youssef}, title={Silver Surfers on the Tech Wave: Privacy Analysis of Android Apps for the Elderly}, proceedings={Security and Privacy in Communication Networks. 18th EAI International Conference, SecureComm 2022, Virtual Event, October 2022, Proceedings}, proceedings_a={SECURECOMM}, year={2023}, month={2}, keywords={Elderly privacy Android apps privacy and security}, doi={10.1007/978-3-031-25538-0_35} }
- Pranay Kapoor
Rohan Pagey
Mohammad Mannan
Amr Youssef
Year: 2023
Silver Surfers on the Tech Wave: Privacy Analysis of Android Apps for the Elderly
SECURECOMM
Springer
DOI: 10.1007/978-3-031-25538-0_35
Abstract
Like other segments of the population, elderly people are also rapidly adopting the use of various mobile apps, and numerous apps are also being developed exclusively focusing on their specific needs. Mobile apps help the elderly to improve their daily lives and connectivity, and their caregivers or family members to monitor the loved ones’ well-being and health-related activities. While very useful, these apps also deal with a lot of sensitive private data such as healthcare reports, live location, and Personally Identifiable Information (PII) of the elderly and caregivers. While the privacy and security issues in mobile applications for the general population have been widely analyzed, there is limited work that focuses on elderly apps. We shed light on the privacy and security issues in mobile apps intended for elderly users, using a combination of dynamic and static analysis on 146 popular Android apps from Google Play Store. To better understand some of these apps, we also test their corresponding IoT devices. Our analysis uncovers numerous security and privacy issues, leading to the leakage of private information and allowing adversaries to access user data. We find that 95/146 apps fail to adequately preserve the security and privacy of their users in one or more ways; specifically, 15 apps allow full account takeover, and 9 apps have an improper input validation check, where some of them allow an attacker to dump the database containing elderly and caregivers’ sensitive information. We hope our study will raise awareness about the security and privacy risks introduced by these apps, and direct the attention of developers to strengthen their defensive measures.