SlideShare a Scribd company logo
Mobile App Privacy —
You’re Doing It Wrong
               (and so am I)
  Graham Lee, Smartphone Security Boffin,
           Fuzzy Aliens Limited



                              fuzzyaliens.com
Mobile App Privacy —
You’re Doing It Wrong
               (and so am I)
  Graham Lee, Smartphone Security Boffin,
           Fuzzy Aliens Limited
Mobile App Privacy —
      You’re Doing It Wrong
                          (and so am I)
             Graham Lee, Smartphone Security Boffin,
                      Fuzzy Aliens Limited
      Desktop
       Server
   Telecom CO
Particle Accelerator
Mobile App Privacy —
      You’re Doing It Wrong
                          (and so am I)
             Graham Lee, Smartphone Security Boffin,
                      Fuzzy Aliens Limited
      Desktop
       Server                 UX
   Telecom CO          Requirements Eng
Particle Accelerator       Dev Ops
                        Source Control
                              …
Pre-intro Disclaimer
Introductory Story
Introductory Story
•   I can’t explain why I did what I did
Introductory Story
•   I can’t explain why I did what I did

•   It’s not just hard to explain the
    rules, I don’t know them
Introductory Story
•   I can’t explain why I did what I did

•   It’s not just hard to explain the
    rules, I don’t know them

•   Ask me, I’ll not only give the
    wrong answer, I’ll do something
    different
Introductory Story
•   I can’t explain why I did what I did

•   It’s not just hard to explain the
    rules, I don’t know them

•   Ask me, I’ll not only give the
    wrong answer, I’ll do something
    different

•   My original plan got replaced at
    run-time in the face of new
    inputs
Erm…privacy?
Erm…privacy?
TAP HERE TO
     SMASH THEM
         PIGS




Erm…privacy?
Erm…privacy?
iOS Example
iOS Example
iOS Example
iOS Example
Historical Example
 “   The Platform for Privacy Preferences
     Project (P3P) enables Websites to
     express their privacy practices in a
     standard format that can be retrieved
     automatically and interpreted easily
     by user agents. P3P user agents will
     allow users to be informed of site
     practices (in both machine- and
     human-readable formats) and to
     automate decision-making based on
     these practices when appropriate.
     Thus users need not read the
     privacy policies at every site they
     visit.                                  ”
What can we draw
   from this?
What can we draw
      from this?
• People are capricious
What can we draw
      from this?
• People are capricious
• We can’t tell you what information we’ll
  use to make any decision
What can we draw
      from this?
• People are capricious
• We can’t tell you what information we’ll
  use to make any decision
• A rational choice made earlier can be
  overridden by novel changes in
  environment
What can we draw
      from this?
• People are capricious
• We can’t tell you what information we’ll
  use to make any decision
• A rational choice made earlier can be
  overridden by novel changes in
  environment                amme   rs a n d
                          Sp
                          phish e rs k n o w
                                 t his
Therefore, give users an
easily-digestible amount
       of pertinent
     information AT
   DECISION TIME
Just-in-time information


                what I’m trying to do

                   how it’s going
Social Media
Social Media


         Your mum can read what you post!
              Change privacy settings
Social Media
Social Media
               IN REPLY TO DM
Confidential Data
Confidential Data


           Warning: attachment includes credit card data.
                                     Delete Attachment
Summary
•   Users can help
    themselves to privacy…

•   …if app developers do
    their part and help out

•   AFFORDABILITY IS
    KEY (in everything)

•   Read these books ➡
Summary
•   Users can help
    themselves to privacy…

•   …if app developers do
    their part and help out

•   AFFORDABILITY IS
    KEY (in everything)

•   Read these books ➡
Summary
•   Users can help
    themselves to privacy…

•   …if app developers do
    their part and help out

•   AFFORDABILITY IS
    KEY (in everything)

•   Read these books ➡
Summary
•   Users can help
    themselves to privacy…

•   …if app developers do
    their part and help out

•   AFFORDABILITY IS
    KEY (in everything)

•   Read these books ➡
@iamleeg
@iamleeg


       fuzzyaliens.com
@iamleeg


       fuzzyaliens.com

More Related Content

PDF
Smartphone security
PPTX
Textil
PPTX
Cierre Habitantes por Alververas
PPTX
Performances
PDF
GALA breve presentazione maggio 2015
PPT
Helicia ftorrente objetoa
PPTX
Gallery Nights Octubre
PDF
Presentazione AD Mind 2012
Smartphone security
Textil
Cierre Habitantes por Alververas
Performances
GALA breve presentazione maggio 2015
Helicia ftorrente objetoa
Gallery Nights Octubre
Presentazione AD Mind 2012

Viewers also liked (8)

PDF
PDF
Data mining in support of fraud management
PDF
introduzione al data mining
PDF
Tackling Card not present Fraud
KEY
Cross platform Objective-C Strategy
PDF
Las obras en exhibición: Tercera Bienal Kosice
PDF
Crm value proposition
PDF
Studio Labsus v2009
Data mining in support of fraud management
introduzione al data mining
Tackling Card not present Fraud
Cross platform Objective-C Strategy
Las obras en exhibición: Tercera Bienal Kosice
Crm value proposition
Studio Labsus v2009
Ad

Similar to Smartphone security and privacy: you're doing it wrong (20)

PPTX
Fostering an Ecosystem for Smartphone Privacy
PPTX
Helping Developers with Privacy
PDF
Over The Air 2010: Privacy for Mobile Developers
PDF
Privacy Exposed: Ramifications of Social Media and Mobile Technology
PDF
Ft cmobileprivacyreport
PDF
UX STRAT USA, Dr. Jen Romano-Bergstrom, "Strategy and Privacy at Facebook"
PDF
Designing for privacy: 3 essential UX habits for product teams
PPTX
Designing for privacy in mobile applications
PDF
Privacy vs. Convenience. Challenges for UX with Privacy and Personalization
PDF
Privacy vs. Convenience. Challenges for UX with Privacy and Personalization
PPTX
Designing for Privacy in an Increasingly Public World
PDF
Privacy Jungle
PPT
Usability Professionals Don't Care About Privacy
PPTX
App Privacy
PPTX
Privacy on Mobile Apps
PDF
Your place in the new trust ecosystem for UCD Gathering 20202
PDF
Visualizing Privacy
PPTX
Mobileprivacyazahir
PDF
FTC Emphasizes Privacy Protections, Truth in Advertising in Business Guide fo...
PDF
Designing for Privacy
Fostering an Ecosystem for Smartphone Privacy
Helping Developers with Privacy
Over The Air 2010: Privacy for Mobile Developers
Privacy Exposed: Ramifications of Social Media and Mobile Technology
Ft cmobileprivacyreport
UX STRAT USA, Dr. Jen Romano-Bergstrom, "Strategy and Privacy at Facebook"
Designing for privacy: 3 essential UX habits for product teams
Designing for privacy in mobile applications
Privacy vs. Convenience. Challenges for UX with Privacy and Personalization
Privacy vs. Convenience. Challenges for UX with Privacy and Personalization
Designing for Privacy in an Increasingly Public World
Privacy Jungle
Usability Professionals Don't Care About Privacy
App Privacy
Privacy on Mobile Apps
Your place in the new trust ecosystem for UCD Gathering 20202
Visualizing Privacy
Mobileprivacyazahir
FTC Emphasizes Privacy Protections, Truth in Advertising in Business Guide fo...
Designing for Privacy
Ad

More from Graham Lee (13)

PPTX
Object-Oriented Programming in Functional Programming in Swift
PDF
The Principled Programmer
KEY
Taking a Test Drive: iOS Dev UK guide to TDD
KEY
Taking a Test Drive
KEY
Crypto storage
PDF
Beyond build and analyze
PDF
Sign your code
KEY
Unit testing for Cocoa developers
KEY
Security and Encryption on iOS
KEY
Dial M For Mitigation
ZIP
Presentations and Podcasts - OxMug July 2009
PDF
Intel Briefing Notes
ZIP
Designing a Secure Cocoa App
Object-Oriented Programming in Functional Programming in Swift
The Principled Programmer
Taking a Test Drive: iOS Dev UK guide to TDD
Taking a Test Drive
Crypto storage
Beyond build and analyze
Sign your code
Unit testing for Cocoa developers
Security and Encryption on iOS
Dial M For Mitigation
Presentations and Podcasts - OxMug July 2009
Intel Briefing Notes
Designing a Secure Cocoa App

Recently uploaded (20)

PPTX
Modernising the Digital Integration Hub
PDF
Getting Started with Data Integration: FME Form 101
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PDF
A novel scalable deep ensemble learning framework for big data classification...
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
Hybrid model detection and classification of lung cancer
PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
PPTX
cloud_computing_Infrastucture_as_cloud_p
PDF
2021 HotChips TSMC Packaging Technologies for Chiplets and 3D_0819 publish_pu...
PDF
August Patch Tuesday
PPTX
Tartificialntelligence_presentation.pptx
PDF
NewMind AI Weekly Chronicles – August ’25 Week III
PDF
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
PPT
What is a Computer? Input Devices /output devices
PDF
Hindi spoken digit analysis for native and non-native speakers
PDF
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
PDF
WOOl fibre morphology and structure.pdf for textiles
PDF
Web App vs Mobile App What Should You Build First.pdf
PPTX
TLE Review Electricity (Electricity).pptx
PDF
Univ-Connecticut-ChatGPT-Presentaion.pdf
Modernising the Digital Integration Hub
Getting Started with Data Integration: FME Form 101
Group 1 Presentation -Planning and Decision Making .pptx
A novel scalable deep ensemble learning framework for big data classification...
gpt5_lecture_notes_comprehensive_20250812015547.pdf
Hybrid model detection and classification of lung cancer
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
cloud_computing_Infrastucture_as_cloud_p
2021 HotChips TSMC Packaging Technologies for Chiplets and 3D_0819 publish_pu...
August Patch Tuesday
Tartificialntelligence_presentation.pptx
NewMind AI Weekly Chronicles – August ’25 Week III
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
What is a Computer? Input Devices /output devices
Hindi spoken digit analysis for native and non-native speakers
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
WOOl fibre morphology and structure.pdf for textiles
Web App vs Mobile App What Should You Build First.pdf
TLE Review Electricity (Electricity).pptx
Univ-Connecticut-ChatGPT-Presentaion.pdf

Smartphone security and privacy: you're doing it wrong

  • 1. Mobile App Privacy — You’re Doing It Wrong (and so am I) Graham Lee, Smartphone Security Boffin, Fuzzy Aliens Limited fuzzyaliens.com
  • 2. Mobile App Privacy — You’re Doing It Wrong (and so am I) Graham Lee, Smartphone Security Boffin, Fuzzy Aliens Limited
  • 3. Mobile App Privacy — You’re Doing It Wrong (and so am I) Graham Lee, Smartphone Security Boffin, Fuzzy Aliens Limited Desktop Server Telecom CO Particle Accelerator
  • 4. Mobile App Privacy — You’re Doing It Wrong (and so am I) Graham Lee, Smartphone Security Boffin, Fuzzy Aliens Limited Desktop Server UX Telecom CO Requirements Eng Particle Accelerator Dev Ops Source Control …
  • 7. Introductory Story • I can’t explain why I did what I did
  • 8. Introductory Story • I can’t explain why I did what I did • It’s not just hard to explain the rules, I don’t know them
  • 9. Introductory Story • I can’t explain why I did what I did • It’s not just hard to explain the rules, I don’t know them • Ask me, I’ll not only give the wrong answer, I’ll do something different
  • 10. Introductory Story • I can’t explain why I did what I did • It’s not just hard to explain the rules, I don’t know them • Ask me, I’ll not only give the wrong answer, I’ll do something different • My original plan got replaced at run-time in the face of new inputs
  • 13. TAP HERE TO SMASH THEM PIGS Erm…privacy?
  • 19. Historical Example “ The Platform for Privacy Preferences Project (P3P) enables Websites to express their privacy practices in a standard format that can be retrieved automatically and interpreted easily by user agents. P3P user agents will allow users to be informed of site practices (in both machine- and human-readable formats) and to automate decision-making based on these practices when appropriate. Thus users need not read the privacy policies at every site they visit. ”
  • 20. What can we draw from this?
  • 21. What can we draw from this? • People are capricious
  • 22. What can we draw from this? • People are capricious • We can’t tell you what information we’ll use to make any decision
  • 23. What can we draw from this? • People are capricious • We can’t tell you what information we’ll use to make any decision • A rational choice made earlier can be overridden by novel changes in environment
  • 24. What can we draw from this? • People are capricious • We can’t tell you what information we’ll use to make any decision • A rational choice made earlier can be overridden by novel changes in environment amme rs a n d Sp phish e rs k n o w t his
  • 25. Therefore, give users an easily-digestible amount of pertinent information AT DECISION TIME
  • 26. Just-in-time information what I’m trying to do how it’s going
  • 28. Social Media Your mum can read what you post! Change privacy settings
  • 30. Social Media IN REPLY TO DM
  • 32. Confidential Data Warning: attachment includes credit card data. Delete Attachment
  • 33. Summary • Users can help themselves to privacy… • …if app developers do their part and help out • AFFORDABILITY IS KEY (in everything) • Read these books ➡
  • 34. Summary • Users can help themselves to privacy… • …if app developers do their part and help out • AFFORDABILITY IS KEY (in everything) • Read these books ➡
  • 35. Summary • Users can help themselves to privacy… • …if app developers do their part and help out • AFFORDABILITY IS KEY (in everything) • Read these books ➡
  • 36. Summary • Users can help themselves to privacy… • …if app developers do their part and help out • AFFORDABILITY IS KEY (in everything) • Read these books ➡
  • 38. @iamleeg fuzzyaliens.com
  • 39. @iamleeg fuzzyaliens.com

Editor's Notes