Symposium on Usable Privacy and Security (SOUPS 2026) - Day 2
Welcome to the Symposium on Usable Security and Privacy happening in Hannover, Germany and being hosted by CISPA.
Blog posts:
Session 1: Privacy Notices, Permissions & Labels
How Effective are Privacy Labels at Informing Users About App Data Handling Practices?
Presenter: Sophia Walsh, University of Bristol
Do the short data notices on app stores properly inform users?
The study looks at users ability to understand the labels in app store notices. They used a card matching approach where they gave users popular apps on one set of cards and a print-out of the short privacy notice icons on another. They then asked the participants to try and match the two sets while doing a think aloud.
Unsupprisingly, they find that users do not know how to map the permissions information to the features that exist in apps. They also find that the information can be overwhelming and causes users to give up.
I don’t know what I’ve all granted. Does it really matter? – Understanding Users’ Awareness of Different Permission Types on Android
Presenter: Verena Winterhalter, LMU Munich
More than 372 apps installed on a given phone.
Each of these apps has permissions that control how it can collect and use user data. Users’ awareness of these permissions is poor to start with and can get worse with time since permissions can change over time.
Studied users understandings of what permissions that the user has installed and uses.
Recommends:
- Focus on permissions where user has agency
- Improve visabiliity & reviwability of installtime permissions
- App usage recency as indicator for suggesting app deletion
- Different intervention approach per type of misconception
Nudging Developers Toward Privacy: Evaluating the Impact of Personalized App Review Reports
Presenter: Nina Taft, Google
It can be challenging for developers who are building an app to get privacy right. They use libraries, but may not know what those libraries do. But users sometimes have allot to say about the topic in reviews.
This project attempts to give developers personalized reports about their app.
Study is multi-stage. Stage-1: survey of developers about their concerns, privacy perceptions, and odds of taking action. Stage-2: showed them a personalized privacy report. Stage-3: measured their understanding.
The report:
- Top 3 privacy concerns from their users’ reviews
- Focused on one of those concerns, showed them Volume and Trends
- Peer benchmark - compared their app to their peers
- Emotions - emotion words
Studied people who work in the privacy field, or at least someone who can make decisions involving the privacy design of the app.
Asked developers about the approaches they have for lookimg at their own reviews, particularly privacy-related. Some read the 1 star reviews. Some have software that reads and summarizes reviews, though not specifically for privacy.
76% of respondants found it useful. The remaining 24% had a “I already knew that” response. 69% say that they are likely to do something about the user concerns after seeing the report.