Assessing discrepancies between network traffic and privacy policies of public sector web services

Timi Heino, Robin Carlsson, Sampsa Rauti, V. Leppänen
{"title":"Assessing discrepancies between network traffic and privacy policies of public sector web services","authors":"Timi Heino, Robin Carlsson, Sampsa Rauti, V. Leppänen","doi":"10.1145/3538969.3539003","DOIUrl":null,"url":null,"abstract":"Online services are increasingly being used to complete everyday tasks, and ordinary users with very little technical knowledge have learned to use web services and applications. At the same time, many user applications are gradually moving from the traditional desktop environment to the web. Because of these developments, it is not surprising that user privacy has become a very important consideration when developing web services. In the current study, we assess the privacy of 34 web services provided and maintained by Finnish public sector bodies. We perform a network traffic analysis in order to find out what kind of personal data the studied services deliver to third party analytics services. We then take a look at the privacy policy documents of these web services and gauge their transparency and clarity by comparing their contents to the actual network data sent out by the web services. Our findings reveal numerous inconsistencies between what is said about handling personal data in the analyzed privacy policies and the actual traffic of the studied web services. Another prominent finding is the sheer amount of analytics services employed by the studied websites. We conclude that there is still an obvious need for web developers and public sector bodies to improve their awareness of existing privacy regulations and personal information their online services deliver to third parties. A lot of work also remains to be done in clearly and transparently communicating privacy-related matters to users.","PeriodicalId":306813,"journal":{"name":"Proceedings of the 17th International Conference on Availability, Reliability and Security","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2022-08-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 17th International Conference on Availability, Reliability and Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3538969.3539003","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

Online services are increasingly being used to complete everyday tasks, and ordinary users with very little technical knowledge have learned to use web services and applications. At the same time, many user applications are gradually moving from the traditional desktop environment to the web. Because of these developments, it is not surprising that user privacy has become a very important consideration when developing web services. In the current study, we assess the privacy of 34 web services provided and maintained by Finnish public sector bodies. We perform a network traffic analysis in order to find out what kind of personal data the studied services deliver to third party analytics services. We then take a look at the privacy policy documents of these web services and gauge their transparency and clarity by comparing their contents to the actual network data sent out by the web services. Our findings reveal numerous inconsistencies between what is said about handling personal data in the analyzed privacy policies and the actual traffic of the studied web services. Another prominent finding is the sheer amount of analytics services employed by the studied websites. We conclude that there is still an obvious need for web developers and public sector bodies to improve their awareness of existing privacy regulations and personal information their online services deliver to third parties. A lot of work also remains to be done in clearly and transparently communicating privacy-related matters to users.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
评估公共部门网络服务的网络流量和隐私政策之间的差异
在线服务被越来越多地用于完成日常任务,技术知识很少的普通用户已经学会了使用web服务和应用程序。与此同时,许多用户应用程序正逐渐从传统的桌面环境转向网络。由于这些发展,用户隐私成为开发web服务时非常重要的考虑因素也就不足为奇了。在当前的研究中,我们评估了芬兰公共部门机构提供和维护的34个网络服务的隐私。我们执行网络流量分析,以找出所研究的服务向第三方分析服务提供的个人数据类型。然后,我们查看这些web服务的隐私政策文档,并通过将其内容与web服务发送的实际网络数据进行比较来衡量其透明度和清晰度。我们的研究结果显示,在所分析的隐私政策中关于处理个人数据的说法与所研究的web服务的实际流量之间存在许多不一致之处。另一个突出的发现是,被研究的网站使用了大量的分析服务。我们的结论是,网络开发人员和公共部门机构仍然明显需要提高他们对现有隐私法规和他们的在线服务向第三方提供的个人信息的认识。在清晰透明地向用户传达与隐私相关的事项方面,还有很多工作要做。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Web Bot Detection Evasion Using Deep Reinforcement Learning Cyber-security measures for protecting EPES systems in the 5G area An Internet-Wide View of Connected Cars: Discovery of Exposed Automotive Devices Secure Mobile Agents on Embedded Boards: a TPM based solution SoK: Applications and Challenges of using Recommender Systems in Cybersecurity Incident Handling and Response
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1