Stuck in the Permissions With You: Developer & End-User Perspectives on App Permissions & Their Privacy Ramifications

Privacy by Design & User ControlPrivacy Perception & Decision-MakingSoftware Engineers & DevelopersUI/UX DesignersHCI Researchers

Literature Title

Stuck in the Permissions With You: Developer & End-User Perspectives on App Permissions & Their Privacy Ramifications

Literature Information

  • Subject Area: User Privacy and Permission Management
  • Keywords: Smartphone permissions, privacy, developers, app users, usable privacy, usable security, programming, empirical software engineering, mixed research methods

Research Background and Issues

  • Problems and Challenges:

    • Smartphone permission systems are critical mechanisms for protecting user data and resources, but issues such as over-permissioning and unused permissions persist in permission management.
    • While there is a substantial body of literature on end-user perspectives regarding permissions, there is a significant lack of empirical research on developers' perspectives, their decision-making processes, and their understanding of the privacy implications of permissions.
    • Users typically decide whether to grant permissions based on their relevance to app functionality and potential privacy risks, but there is limited exploration of how developers perceive these privacy-related decisions.
  • Significance:

    • Investigating the differing understandings of permissions and privacy between developers and end-users can help optimize the permission ecosystem, reduce the risk of user privacy exposure, and enhance both developer efficiency and user trust.
  • Research Motivation and Related Work:

    • In recent years, excessive permission requests and their potential privacy intrusions have caused user dissatisfaction, yet the confusion developers face regarding permission management and its underlying causes remain underexplored.
    • Understanding developers' decision-making processes regarding permission usage and users' privacy attitudes can provide dual perspectives to address the challenges of permission management in the mobile ecosystem.

Solution

  • Methods and Research Design:

    • Employing a mixed research method:
      • Conducting interviews with 19 smartphone app developers to understand their perspectives and practices regarding permission decisions and privacy.
      • Administering a survey to 309 Android and iOS users to explore their attitudes toward permissions and compare these with developers' viewpoints.
    • Defining the main research questions:
      1. How do developers decide which permissions to request?
      2. How do developers understand permissions and their privacy implications?
      3. What are users' attitudes toward permissions, and how do these attitudes contrast with developers' perspectives?
  • Innovations:

    • This study is the first to empirically cover both key stakeholders in the ecosystem: developers and end-users.
    • It provides a detailed investigation of permission-related issues across different stages of the mobile development lifecycle.
  • Implementation Steps and Techniques:

    1. Developer Interviews:
      • Recruiting a diverse sample of developers to discuss their decision-making processes and specific experiences with permissions.
      • Preparing an interview guide covering technical and privacy aspects of permission usage.
    2. End-User Survey:
      • Conducting an online survey to understand users' attitudes, behaviors, and perceptions of privacy risks related to permissions.
      • Utilizing qualitative and quantitative data analysis tools (e.g., Miro, NVivo).

Research Findings

  • Specific Findings:

    • Developer Perspectives:
      • Permissions are primarily requested to enable functionalities (e.g., location permissions for map usage) or due to third-party library requirements, but confusion can lead to unnecessary permissions.
      • Ambiguity in permission scopes is a major reason for requesting additional permissions, such as the distinction between "precise location" and "approximate location."
      • Developers are partially influenced by operating system and app store privacy policies and consider user trust when managing permissions.
    • User Perspectives:
      • Most users believe permissions are closely tied to app functionality, with 68.6% perceiving potential privacy risks associated with permissions.
      • Users are most sensitive to permissions related to storage, location, and photos, but 31.4% of users fail to recognize potential risks of permission usage.
      • The majority of users do not actively modify granted permissions, often due to a lack of knowledge about how to revoke them.
  • Advantages Over Existing Methods:

    • The direct comparison of developer and user perspectives reveals how current permission designs are understood and utilized by different stakeholders.
    • Provides empirical recommendations for gradually improving permission models, such as refining permission scope definitions and offering clearer permission descriptions.
  • Experimental or Evaluation Results:

    • Developers tend to request permissions only when necessary, but third-party libraries often expand the scope of permissions.
    • Users express a clear demand for transparency in permission requests, but there is a significant knowledge gap in permission management.
  • Limitations and Future Directions:

    • The sample exhibits geographic and gender biases, limiting the generalizability of the findings to global developers and users.
    • Future research could explore user permission behaviors in other countries and cultural contexts to broaden understanding.
    • Efforts should focus on raising user awareness about revoking or managing permissions and providing developers with clear guidelines on permission scopes.

Conclusion

The study highlights the differences in perspectives between developers and end-users within the smartphone permission ecosystem and proposes feasible suggestions for improving permission systems. These findings not only address gaps in the literature but also provide a theoretical foundation for designing more transparent and user-friendly privacy protection mechanisms.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/96207/2023

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3544548.3581060
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2023
emoji_events
Award
No award tagged
group
Authors
3 authors
sell
Subtopics
Privacy by Design & User Control, Privacy Perception & Decision-Making
work
Professions
Software Engineers & Developers, UI/UX Designers, HCI Researchers
article
Content Status
Full text indexed
hub
Related Papers
2 related papers