TY - GEN
T1 - Casing the Vault
T2 - 21st Workshop on Privacy in the Electronic Society, WPES 2022 co-located with CCS 2022
AU - Ruffin, Margie
AU - Lopez-Toldeo, Israel
AU - Levchenko, Kirill
AU - Wang, Gang
N1 - ACKNOWLEDGMENTS. This work was supported in part by NSF grants 2030521, and the Graduate Research Fellowship Program under Grant No 21-46756.
PY - 2022/11/7
Y1 - 2022/11/7
N2 - Vault applications are a class of mobile apps used to store and hide users' sensitive files (e.g., photos, documents, and even another app) on the phone. In this paper, we perform an empirical analysis of popular vault apps under the scenarios of unjust search and filtration of civilians by authorities (e.g., during civil unrest). By limiting the technical capability of adversaries, we explore the feasibility of inferring the presence of vault apps and uncovering the hidden files without employing sophisticated forensics analysis. Our analysis of 20 popular vault apps shows that most of them do not adequately implement/configure their disguises, which can reveal their existence without technical analysis. In addition, adversaries with rudimentary-level knowledge of the Android system can already uncover the files stored in most of the vault apps. Our results indicate the need for more secure designs for vault apps.
AB - Vault applications are a class of mobile apps used to store and hide users' sensitive files (e.g., photos, documents, and even another app) on the phone. In this paper, we perform an empirical analysis of popular vault apps under the scenarios of unjust search and filtration of civilians by authorities (e.g., during civil unrest). By limiting the technical capability of adversaries, we explore the feasibility of inferring the presence of vault apps and uncovering the hidden files without employing sophisticated forensics analysis. Our analysis of 20 popular vault apps shows that most of them do not adequately implement/configure their disguises, which can reveal their existence without technical analysis. In addition, adversaries with rudimentary-level knowledge of the Android system can already uncover the files stored in most of the vault apps. Our results indicate the need for more secure designs for vault apps.
KW - android
KW - privacy
KW - vault app
UR - https://www.scopus.com/pages/publications/85143257170
UR - https://www.scopus.com/pages/publications/85143257170#tab=citedBy
U2 - 10.1145/3559613.3563204
DO - 10.1145/3559613.3563204
M3 - Conference contribution
AN - SCOPUS:85143257170
T3 - WPES 2022 - Proceedings of the 21st Workshop on Privacy in the Electronic Society, co-located with CCS 2022
SP - 175
EP - 180
BT - WPES 2022 - Proceedings of the 21st Workshop on Privacy in the Electronic Society, co-located with CCS 2022
PB - Association for Computing Machinery
Y2 - 7 November 2022 through 7 November 2022
ER -