Does the Presence of Privacy and Security Relevant
Total Page:16
File Type:pdf, Size:1020Kb
Edinburgh Research Explorer Does the Presence of Privacy Relevant Information Affect App Market Choice? Citation for published version: Wolters, M, Yang, X, Li, S, Wang, H & Guo, Y 2020, Does the Presence of Privacy Relevant Information Affect App Market Choice? in CHI EA '20: Extended Abstracts of the 2020 CHI Conference on Human Factors in Computing SystemsCHI EA '20: Extended Abstracts of the 2020 CHI Conference on Human Factors in Computing Systems., LBW121, ACM, ACM CHI Conference on Human Factors in Computing Systems, Honolulu, Hawaii, United States, 25/04/20. https://doi.org/10.1145/3334480.3383078 Digital Object Identifier (DOI): 10.1145/3334480.3383078 Link: Link to publication record in Edinburgh Research Explorer Document Version: Peer reviewed version Published In: CHI EA '20: Extended Abstracts of the 2020 CHI Conference on Human Factors in Computing SystemsCHI EA '20: Extended Abstracts of the 2020 CHI Conference on Human Factors in Computing Systems General rights Copyright for the publications made accessible via the Edinburgh Research Explorer is retained by the author(s) and / or other copyright owners and it is a condition of accessing these publications that users recognise and abide by the legal requirements associated with these rights. Take down policy The University of Edinburgh has made every reasonable effort to ensure that Edinburgh Research Explorer content complies with UK legislation. If you believe that the public display of this file breaches copyright please contact [email protected] providing details, and we will remove access to the work immediately and investigate your claim. Download date: 30. Sep. 2021 CHI 2020 Late-Breaking Work CHI 2020, April 25–30, 2020, Honolulu, HI, USA Does the Presence of Privacy Relevant Information Affect App Market Choice? Maria K Wolters Xinyu Yang Abstract Centre for Design Informatics, School of Cyberspace Security While in most countries, Google Play and Apple App Store University of Edinburgh, UK Beijing University of Posts and dominate, Chinese mobile phone users can choose among Alan Turing Institute, London, UKTelecommunications, Beijing, dozens of different app markets, which differ greatly in the [email protected] China information presented. This makes the Chinese mobile [email protected] ecosystem a unique case study for investigating whether users actively choose app markets that conform to their Shuobing Li preferences. We investigated this question in a survey of School of Informatics, University 200 Chinese users aged 18-49. Scenarios covered apps of Edinburgh that require disclosure of different types of sensitive infor- mation (shopping, dating, health), with gaming as a base- Haoyu Wang Yao Guo line. Users preferred markets that were easy to use and School of Computer Science MOE Key Lab of HCST, had a wide choice of apps. Only nine users highlighted se- Beijing University of Posts and Dept of Computer Science, curity as a feature. Despite this, they primarily used only Telecommunications, Beijing, Peking University, Beijing, China one app market—the pre-installed one. App-market specific China [email protected] features were important for the game scenario, but less im- [email protected] portant for all others. We suggest that download decisions for most apps are made before users enter an app market, and discuss implications for presenting privacy and security information. Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation Author Keywords on the first page. Copyrights for third-party components of this work must be honored. app markets; privacy; security; understanding users. For all other uses, contact the owner/author(s). CHI ’20 Extended Abstracts, April 25–30, 2020, Honolulu, HI, USA. © 2020 Copyright is held by the author/owner(s). CCS Concepts ACM ISBN 978-1-4503-6819-3/20/04. DOI: https://doi.org/10.1145/3334480.3383078 •Human-centered computing ! Empirical studies in ubiquitous and mobile computing; •Social and profes- LBW121, Page 1 CHI 2020 Late-Breaking Work CHI 2020, April 25–30, 2020, Honolulu, HI, USA sional topics ! Cultural characteristics; •Security and APK, Anzhi, and LIQU). Only Apple App Store and Google privacy ! Usability in security and privacy; Play provided information about app quality, options for in- app purchases, and two features relevant to privacy and Introduction security, namely the existence of a privacy policy and the In many countries, there are only two dominant app mar- presence of ads. App quality ratings are based on down- kets: Google Play for Android phones, and Apple App Store loads, user comments, developer level and other metrics. for iPhones. China is different. Since Google Play is not Of the third-party app markets, Tencent and 360 have qual- routinely installed on Chinese Android phones, dozens of ity ratings, Baidu and 360 highlight in-app purchases, and alternative app markets have emerged. The biggest mar- Tencent, Baidu, 360, OPPO, Huawei, and 25PP alert users kets are typically maintained by established Internet compa- to ads. nies, such as Baidu or Tencent, or by mobile phone man- ufacturers, such as Huawei and Xiaomi [13, 12]. These Survey app markets differ greatly in the information they present to Data were collected as part of a survey on the effect of per- Age users, the security and quality checks they conduct on the sonality [6, 4] and privacy preferences [14] on app selection 18–24 83 (41.5%) apps in their store, and the number of apps provided [12]. priorities. Scores on the privacy scale range between 0 and 25–29 82 (41%) 63, where 63 reflects the highest level of privacy concerns. 30+ 35 (17.5%) There is a wealth of work on dashboards and interfaces to Gender support users in making app download decisions that take Participants were asked about the model of phone used, male 127 (63.5%) into account their privacy preferences [2, 3, 8, 11]. Rele- the types of apps that they used and their frequency of use, female 64 (32%) vant information includes whether an app has ads, what the and their knowledge and use of these 15 app markets. For not discl. 9 (4.5%) app’s privacy policy is, or what access permissions it needs. each app market, there were five choices: used frequently; Occupation While no Chinese app market explicitly implements these used sometimes; used rarely; known, but not used; and un- student 63 (31%) results, some app markets are better at providing relevant known. Participants were asked to provide comments on employed 127 (63%) information than others. In this study, we examine to what why they chose certain app markets, what they liked and other 14 (7%) extent users actively choose markets that have more secu- disliked about app markets, and what they used app mar- OS rity relevant information. kets for. We also asked participants about the frequency iOS 95 (47%) of use of different app categories, using a scale that was Android 104 (52%) Method similar to the one used for app markets. both 2 (1%) App Markets Used in the Study Participants were asked to imagine that they were going Phone Use For the purpose of our study, we selected 15 representative to search an app store for an app that allows them to com- every hour 155 (77%) app markets, including 2 official app markets (Apple App plete a relevant task. The scenarios were shopping, dating, every day 44 (22%) Store and Google Play), the top 3 app markets maintained gaming, obtaining medication from online pharmacy, and less 2 (1%) by large Chinese Internet companies (Tencent, Baidu and obtaining medical advice from online doctors. Both health 360), the top 5 app markets provided by smartphone ven- use cases are common in China [5]). Table 1: Participant dors (OPPO, Xiaomi, Meizu, Huawei and Lenovo), and 5 Demographics. Participants were specialized third-party app markets (25PP, Wandoujia, Hi- able to choose multiple occupations, and some listed two personal phones. LBW121, Page 2 CHI 2020 Late-Breaking Work CHI 2020, April 25–30, 2020, Honolulu, HI, USA The scenarios were designed to vary by the need to dis- RMB30 through WeChat Pay. This sum was established close sensitive personal information (health, dating), and as a fair incentive by consulting with people who had pre- by the need to disclose payment information (online shop- viously taken and distributed surveys in China. We sam- ping, health). Gaming served as a baseline. The two health pled both Android and Apple iPhone users. The study was scenarios were presented in two different versions, non- certified with the Ethics Panel of the School of Informatics, stigmatising (generic cold symptom: very bad cough) and University of Edinburgh, reference number 2019/60328. stigmatising (symptom occurring near the genital area: painful urination). For half of the participants, the doctor Analysis scenario was assigned to the stigmatising condition, and Differences in demographics between groups were as- the medication scenario to the non-stigmatising condition; sessed using Fisher tests and Kruskal-Wallis tests. Dif- for the other half, this was reversed. ferences in judgements across scenarios were assessed using the Friedman test. The Nemenyi method, which is Participants then indicated how likely they were to down- conservative in its calculation of significance, was used for load an app given seven different criteria, which were cho- assessing pairwise differences. The threshold for statistical sen to reflect key differences between Chinese app markets significance was set conservatively at 0:01. We used the as identified in [12]. Three of the seven criteria reflect cu- implementation provided in the R Package PMCMR.