Inferences on shared devices and shared screens disclose to third parties
Aliases: over-the-shoulder personalization · living-room account · shared-device disclosure
What it is
A living-room TV, a classroom projector, a shared tablet, handing a phone over so someone can read one message — the “guessed for you” on that screen is not a whisper to the account holder. Shared-screen inference leakage is personalised output, as a visible interface, exposing estimates about the owner to whoever is present, including people the owner did not mean to tell.
The channel is physical co-viewing, not a breached server.
Why it happens
Once an inference becomes a cover, a reason line, or a notification badge, it enters a space anyone who looks up can read. Shared devices often stay on one account; the system still ranks from the primary profile. A third party sees an unintroduced portrait: a health channel, a dating ad, a late-night genre. Even if the owner already knows those tags, the person beside them is being notified for the first time.
“Display is disclosure” here gains an audience: not the user, the person next to them. There is rarely time to review before showing — the gesture of handing over the screen is faster than opening settings. Default accounts on living-room devices are especially sharp, because co-viewing is normal use, not misuse.
Studying it
Use staged scenes or lab co-viewing: the owner browses in a way that will produce a sensitive inference, then watches home or notifications with family, colleagues, or a stranger. Dependent variables: which inferences a third party can restate, the owner’s embarrassment and grabbing for the device, later switch to guest. Independent variables: device (phone-hand-over / TV / projector), whether the UI shows reasons or identity tags, whether a one-tap guest exists.
Do not only measure how the owner feels seeing the tag. Third-party restatement is the evidence of leakage.
Where it stops holding
Audio recommendations in personal headphones leak much less, unless captions sit on a shared screen. One person, one device, never lent, almost never triggers this. On a work display showing an organisational role rather than a taste, what leaks is a job, not a private attribute. This entry is about third-party disclosure from co-viewing. It does not redefine sensitive classes, and it does not treat whether the misclassified have an appeal.
Applying it
- Living-room and classroom devices default to a configuration with no personal inference. Personalization requires an explicit switch into a personal profile, labelled on screen as “ranking as [name].”
- Provide one-tap guest or cast-sanitise: keep covers, strip reasons and identity tags, show notification counts not contents.
- Check: have a non-owner look at the home screen for ten seconds from three metres and write down what they think the owner likes or is going through. If they can write an unpublished fact, leakage holds. Then test whether one-tap guest suppresses those facts.
Related
- Same group: L6.06.1 Behavioural inference can reach information the user never disclosed · L6.06.2 Displaying an inference is itself a disclosure · L6.06.3 Inferences in sensitive categories need extra constraints · L6.06.4 Combinations of non-sensitive behaviours can yield sensitive attributes; item-wise compliance is not whole-system compliance · L6.06.6 Wrong inferences also harm, and the misclassified often have nowhere to appeal · L6.06.7 Tolerance for inference depends on the setting; the same inference is judged differently across products · L6.06.8 Opting out of inference and opting out of data collection are different controls
- Nearby: L6.12 Conflict Between Personalization and Predictability · L6.07 Presenting Recommendation Reasons · L6.05 Turning Personalization Off
- Search terms:
shared-screen inference leakage·over-the-shoulder personalization·living-room account
Cards in the same group
- L6.06.1Behavioural inference can reach information the user never disclosed
- L6.06.2Displaying an inference is itself a disclosure
- L6.06.3Inferences in sensitive categories need extra constraints
- L6.06.4Combinations of non-sensitive behaviours can yield sensitive attributes; item-wise compliance is not whole-system compliance
- L6.06.6Wrong inferences also harm, and the misclassified often have nowhere to appeal
- L6.06.7Tolerance for inference depends on the setting; the same inference is judged differently across products
- L6.06.8Opting out of inference and opting out of data collection are different controls