Uncovering Relationships Between Android Developers, User Privacy, and Developer Willingness to Reduce Fingerprinting Risks
Authors
Paper Title
Uncovering Relationships Between Android Developers, User Privacy, and Developer Willingness to Reduce Fingerprinting Risks
Publication Info
- Topic area: Developer perceptions and platform interventions for improving user privacy in mobile ecosystems.
- Keywords: Android, fingerprinting, user privacy, developer perceptions, API Usage Purposes, platform interventions, privacy trade-offs, enforcement, mobile apps.
Background and Problem
- Problem / challenge: Despite platform changes to restrict user tracking, mobile apps continue to covertly track users via device fingerprinting, which lacks user notice and opt-out mechanisms. Developers play a critical role in either improving or degrading user privacy, yet their dynamics and willingness to adopt privacy-enhancing policies remain underexplored.
- Significance: Fingerprinting circumvents user control and poses significant privacy risks. Understanding developer behavior and willingness to adopt privacy-enhancing changes is crucial for platforms to effectively address these risks.
- Motivation and related work: Prior research has demonstrated the prevalence of fingerprinting in mobile apps and websites, its circumvention of user consent mechanisms, and its demographic-specific risks. While automatic detection and prevention methods treat developers as adversaries, this study explores opportunities for collaboration between platforms and developers to improve privacy.
Solution
- Proposed approach: A hypothetical platform change called "API Usage Purposes," requiring Android developers to declare purposes for APIs that could be abused for fingerprinting in their app's manifest file.
- Novelty:
- Quantitative measurement of developers' effort-privacy trade-offs.
- Analysis of developer preferences for optional versus required privacy-enhancing changes.
- Insights into developers' concerns, including compliance, enforcement, and user experience.
- Comparison of developer perceptions of Android versus iOS privacy protections.
- Procedure and key techniques:
- A survey of 246 Android developers introduced the "API Usage Purposes" concept.
- Developers were asked about their familiarity with fingerprinting, their app/SDK's use of fingerprinting, and their perceptions of the proposed change's impact on privacy and developer effort.
- Logistic regression analysis was used to study factors influencing support for the change, including developer effort, privacy impact, and fingerprinting use.
Results
- Concrete findings:
- 89% of developers supported the "API Usage Purposes" change (41.5% required, 48% optional).
- Developers who use fingerprinting were six times more likely to support the change (OR = 6.480; p < 0.05).
- Perceived effort negatively impacted support (OR = 0.46; p < 0.01), while perceived privacy benefits positively impacted support (OR = 3.651; p < 0.001).
- Advantage over baselines: Contrary to expectations, developers most impacted by the change (those using fingerprinting) were more likely to support it, suggesting potential for collaboration rather than adversarial approaches.
- Experiments / evaluation:
- Survey design included Likert scales, open-ended questions, and comparisons of optional versus required implementation models.
- Regression analyses tested hypotheses about effort-privacy trade-offs and developer support.
- Participants were recruited from professional Android developer panels, ensuring a knowledgeable sample.
- Limitations and future work:
- Limited to Android developers; future studies should include iOS developers and real-world validation of findings.
- Potential biases in self-reported data and hypothetical scenarios.
- Further research needed to understand why developers use fingerprinting despite privacy concerns.
Summary
This study surveyed 246 Android developers to evaluate their willingness to adopt a privacy-enhancing platform change ("API Usage Purposes") aimed at reducing fingerprinting risks. Developers overwhelmingly supported the change, even when significant effort was anticipated, with surprising support from those using fingerprinting. The findings highlight an opportunity for platforms to collaborate with developers to improve user privacy, addressing concerns around enforcement, documentation, and user experience. Future work should explore generalizability to iOS developers and real-world implementation scenarios.
Research Questions / Practical Problems
Question signals indexed for this paper.
- 75%
PrivacyAkinator: Articulating Key Privacy Design Decisions by Answering LLM-Generated Multiple-choice Questions
CHI '26· Explainable AI (XAI) +3
- 71%
Understanding Challenges for Developers to Create Accurate Privacy Nutrition Labels
CHI '22· Privacy by Design & User Control +1
- 71%
A Scoping Review and Guidelines on Privacy Policy's Visualization from an HCI Perspective
CHI '26· Privacy Perception & Decision-Making +2
- 71%
The Privacy Paradox of LLMs: User Perceptions and the Reality of PII Leakage
CHI '26· Explainable AI (XAI) +2
- 71%
Understanding User Needs Underlying the Expected Roles of LLM-Based Chatbots in Privacy Decision-Making
CHI '26· Explainable AI (XAI) +2
- 71%
Robust Methods for Developer Screening in Rapidly Evolving AI Contexts
CHI '26· Explainable AI (XAI) +2
- 71%
The AI Memory Gap: Users Misremember What They Created With AI or Without
CHI '26· Human-LLM Collaboration +2
- 71%
The Impact of AI Trustworthiness Labels on the Perception of AI Products
CHI '26· Explainable AI (XAI) +2
- 71%
Helping Johnny Make Sense of Privacy Policies with LLMs
CHI '26· Privacy by Design & User Control +2
- 71%
How Much Trust is Enough? Towards Calibrating Trust in Technology
CHI '26· Explainable AI (XAI) +2
Based on Jaccard similarity of research subtopics & professions (≥60%)