150 likes | 269 Views
18th Panhellenic Conference on Informatics Athens, 2-4 October 2014. Directions for Raising Privacy Awareness in SNS Platforms. Konstantina Vemou , Maria Karyda , Spyros Kokolakis. Department of Information and Communication Systems Engineering, University of the Aegean.
E N D
18th Panhellenic Conference on Informatics Athens, 2-4 October 2014. Directions for Raising Privacy Awareness in SNS Platforms Konstantina Vemou, Maria Karyda, Spyros Kokolakis Department of Information and Communication Systems Engineering, University of the Aegean
Introduction – Privacy Paradox Contents Privacy Awareness Goals Research Question– Method of Research Analyzing Current Awareness Practices Directions for Raising Privacy Awareness Further Research Questions
Introduction – Privacy Paradox (1/2) Exposure to privacy risks
Privacy awareness Introduction – Privacy Paradox (2/2) X
Show privacy risks • Show sources of privacy risks • Propose actions the user can take to protect their privacy Privacy Awareness Goals Several tools have been proposed (privacy mirrors, privacy wizards, personal containers, privacy signaling, etc) PROBLEM: Limited use of awareness tools and practices
1 Literature review Research Question – Method of Research How can embedded SNS awareness practices be improved ? 2 Identify and analyze currently employed privacy practices 3 Evaluate effectiveness 4 Provide Guidance
Terms of use and privacy policies Analyzing Current Awareness Practices (1/6) Links at the end of the sign up form and the footer of the webpage Links under the sign-up button, preselected, optional Rare notifications on terms of use changes Offer clear notifications on any changes in TOS
Audience management and visualization Analyzing Current Awareness Practices (2/6) Functionality to create groups of friends/ Audience Segregation “View As” mirroring tool Some still offer Private (all friends) vs Public view Statistics, report visitors-viewed info, visualization of networks
Third-Parties Access Analyzing Current Awareness Practices (3/6) Application permissions presented prior to installation List of installed applications in no predefined place Transitive access controls List of other parties granted access and purpose, Block transitive access controls in applications, Application center in the privacy settings, Report of accessed data by each application
Activity Logs Analyzing Current Awareness Practices (4/6) Log of profile owner activities No presentation of activities’ relation to privacy risks No predefined place in the user interface Organization of activity logs under privacy settings, Logs of accessed pieces of information
Notifications Analyzing Current Awareness Practices (5/6) Functionality to notify via e-mail or SMS on certain activities, e.g. tags, mentions Notifications only to some changes of T.O.S.. Notifications via e-mail selected by default, Notification when a user accesses the profile
Access to recorded data Analyzing Current Awareness Practices (6/6) Download files of collected data Vague Description of types of collected data in the privacy policy Process to access all collected data, Process to request correction or deletion of data
Analyze the actual use of privacy awareness tools Further Research Analyze Evaluate the effectiveness of privacy awareness tools Evaluate Use as input to design of privacy awareness practices for SNS Use