Login | Register

Silver Surfers on The Tech Wave: Privacy Analysis of Android Apps for The Elderly

Title:

Silver Surfers on The Tech Wave: Privacy Analysis of Android Apps for The Elderly

Kapoor, Pranay (2022) Silver Surfers on The Tech Wave: Privacy Analysis of Android Apps for The Elderly. Masters thesis, Concordia University.

[thumbnail of Kapoor_MASc_F2022.pdf]
Preview
Text (application/pdf)
Kapoor_MASc_F2022.pdf - Accepted Version
Available under License Spectrum Terms of Access.
570kB

Abstract

Like other segments of the population, elderly people are also rapidly adopting the use of various mobile apps, and numerous apps are also being developed exclusively focusing on their specific needs. Mobile apps help the elderly to improve their daily lives and connectivity, their caregivers and family members to monitor their loved ones' well-being and health-related activities. While very useful, these apps also deal with a lot of sensitive private data such as healthcare reports, live location, and Personally Identifiable Information (PII) of the elderly and caregivers. While the privacy and security issues in mobile applications for the general population have been widely analyzed, there is limited work that focuses on elderly apps. We shed light on the privacy and security issues in mobile apps intended for elderly users, using a combination of dynamic and static analysis on 146 popular Android apps from the Google Play Store. To better understand some of these apps, we also test their corresponding IoT devices. Our analysis uncovers numerous security and privacy issues, leading to the leakage of private information and allowing adversaries to access user data. We find that 95/146 apps fail to adequately preserve the security and privacy of their users in one or more ways; specifically, 15 apps allow full account takeover, and 9 apps have an improper input validation check, where some of them allow an attacker to dump the database containing elderly and caregivers' sensitive information. We hope our study will raise awareness about the security and privacy risks introduced by these apps, and direct the attention of developers to strengthen their defensive measures.

Divisions:Concordia University > Gina Cody School of Engineering and Computer Science > Concordia Institute for Information Systems Engineering
Item Type:Thesis (Masters)
Authors:Kapoor, Pranay
Institution:Concordia University
Degree Name:M.A. Sc.
Program:Information Systems Security
Date:4 August 2022
Thesis Supervisor(s):Mohammad, Mannan and Youssef, Amr
ID Code:991057
Deposited By: Pranay Kapoor
Deposited On:27 Oct 2022 14:34
Last Modified:27 Oct 2022 14:34
All items in Spectrum are protected by copyright, with all rights reserved. The use of items is governed by Spectrum's terms of access.

Repository Staff Only: item control page

Downloads per month over past year

Research related to the current document (at the CORE website)
- Research related to the current document (at the CORE website)
Back to top Back to top