Login | Register

Privacy Analysis of Technological Solutions Designed for Victims of Intimate Partner Abuse

Title:

Privacy Analysis of Technological Solutions Designed for Victims of Intimate Partner Abuse

Yu, Xiufen (2023) Privacy Analysis of Technological Solutions Designed for Victims of Intimate Partner Abuse. Masters thesis, Concordia University.

[thumbnail of Yu_MASc_S2024.pdf]
Preview
Text (application/pdf)
Yu_MASc_S2024.pdf - Accepted Version
Available under License Spectrum Terms of Access.
522kB

Abstract

Stalkerware is malicious software that monitors and tracks a victim’s online and offline activity. This harmful technology has become a growing concern, jeopardizing the security and privacy of millions of victims and fostering stalkerware and Intimate Partner Violence (IPV). In response, various solutions have emerged, including anti-stalkerware apps that aim to prevent and detect the use of monitoring apps on a user’s device. Organizations dedicated to assisting IPV victims have also enhanced their online presence, offering improved support and easy access to resources and materials. Considering how these tools and support websites handle sensitive personal information of users, it is crucial to assess the privacy risks associated with them. In this thesis, we conduct a privacy analysis on 25 anti-stalkerware apps, 323 websites, 52 hidden device detection apps to identify issues such as PII leaks, authentication problems and 3rd-party tracking. Our tests reveal that 14/25 apps, 210/323 websites, 41/52 hidden device detection apps share user information with 3rd-party services through trackers, cookies or session replay. Based on our analysis of anti-stalkerware websites, we identified 44 domains to which sensitive data is sent, along with 3 services collecting information submitted in forms through session replay. During the dynamic analysis of hidden device detection apps, 25 third-party hosts were observed gathering device or apps information. Furthermore, we conducted a readability assessment of privacy policies obtained from anti-stalkerware apps/websites and hidden device detection apps. Our findings indicate that these privacy policies are highly complex and challenging to comprehend.

Divisions:Concordia University > Gina Cody School of Engineering and Computer Science > Concordia Institute for Information Systems Engineering
Item Type:Thesis (Masters)
Authors:Yu, Xiufen
Institution:Concordia University
Degree Name:M.A. Sc.
Program:Information Systems Security
Date:12 September 2023
Thesis Supervisor(s):Mannan, Mohammad and Youssef, Amr
ID Code:992940
Deposited By: Xiufen Yu
Deposited On:05 Jun 2024 16:19
Last Modified:05 Jun 2024 16:19
All items in Spectrum are protected by copyright, with all rights reserved. The use of items is governed by Spectrum's terms of access.

Repository Staff Only: item control page

Downloads per month over past year

Research related to the current document (at the CORE website)
- Research related to the current document (at the CORE website)
Back to top Back to top