Wear's my Data? Understanding the Cross-Device Runtime Permission Model in Wearables

Doguhan Yeke, Muhammad Ibrahim, Güliz Seray Tuncay, Habiba Farrukh, Abdullah Imran, Antonio Bianchi

IEEE Symposium on Security and Privacy 2024 · Day 2 · Continental Ballroom 4

Overview

This talk, "Wear's my Data? Understanding the Cross-Device Runtime Permission Model in Wearables," presented by researchers from Purdue University, Google, and the University of Florida, delves into the often-misunderstood security and privacy implications of how permissions are handled across paired wearable devices, specifically focusing on the Wear OS ecosystem. The speakers, Doguhan Yeke, Muhammad Ibrahim, and Güliz Seray Tuncay, highlight a critical disconnect between user expectations and the technical reality of data flow between smartphones and smartwatches. Their work uncovers significant vulnerabilities stemming from the dual permission models employed by these interconnected devices.

Watch on YouTube

Visual summary for Wear's my Data? Understanding the Cross-Device Runtime Permission Model in Wearables by Doguhan Yeke, Muhammad Ibrahim, Güliz Seray Tuncay, Habiba Farrukh, Abdullah Imran, Antonio Bianchi
Visual summary for Wear's my Data? Understanding the Cross-Device Runtime Permission Model in Wearables by Doguhan Yeke, Muhammad Ibrahim, Güliz Seray Tuncay, Habiba Farrukh, Abdullah Imran, Antonio Bianchi

Key moments

  1. 2:55 Core privacy issue: Data accessible on both devices
  2. 3:50 Malicious redirection prompts as an attack vector
  3. 5:55 Introducing Flowfinder: Tool for detecting cross-device data flows
  4. 7:05 Findings: Significant number of apps have cross-device data flows
  5. 7:25 Common cross-device flow patterns and reasons
  6. 8:12 Lack of transparency: Apps don't inform users about flows
  7. 8:50 Platform's role: Wear OS also fails to adequately inform users

Wear's my Data? Understanding the Cross-Device Runtime Permission Model in Wearables

Speakers: Doguhan Yeke, PhD Student, Purdue University; Muhammad Ibrahim, PhD Student, Purdue University; Güliz Seray Tuncay, Google; Habiba Farrukh, Purdue University; Abdullah Imran, University of Florida; Antonio Bianchi, Purdue University

Conference: IEEE S&P

YouTube: https://www.youtube.com/watch?v=EWrEsDJ084c

Overview

This talk, "Wear's my Data? Understanding the Cross-Device Runtime Permission Model in Wearables," presented by researchers from Purdue University, Google, and the University of Florida, delves into the often-misunderstood security and privacy implications of how permissions are handled across paired wearable devices, specifically focusing on the Wear OS ecosystem. The speakers, Doguhan Yeke, Muhammad Ibrahim, and Güliz Seray Tuncay, highlight a critical disconnect between user expectations and the technical reality of data flow between smartphones and smartwatches. Their work uncovers significant vulnerabilities stemming from the dual permission models employed by these interconnected devices.

The core of the problem lies in the design of runtime permission models, which, while effective on individual devices, create privacy gaps when sensitive data can flow freely between a smartphone and its paired smartwatch, even if permissions are explicitly denied on one device. This talk is crucial because it exposes how malicious actors could exploit these cross-device data channels and user misunderstandings to gain unauthorized access to highly sensitive information, such as location, health data, or camera access. The research provides both a static analysis tool to identify these flows in real-world applications and a user study demonstrating widespread confusion among users regarding their data's accessibility.

The implications of this research are far-reaching, impacting not only app developers and platform providers like Google but also the end-users who entrust their most personal data to these ubiquitous devices. As wearables become increasingly integrated into daily life, understanding and mitigating these cross-device privacy risks is paramount to maintaining user trust and ensuring the security of personal information. The talk concludes with proposed countermeasures and discusses ongoing platform-level efforts to address these complex challenges, emphasizing a shift towards a more user-centric permission paradigm.

Background

▶ Watch: Core privacy issue: Data accessible on both devices (2:55)

The evolution of permission models on mobile platforms has been a continuous journey towards enhanced user privacy and control. Prior to Android 6, the install-time permission model granted applications all requested permissions upon installation, leaving users with little granular control over sensitive data access post-installation. This model was largely replaced by the runtime permission model starting with Android 6, which requires applications to explicitly request user consent at the point of accessing highly sensitive data such as location, camera, or contacts. This shift empowered users to make informed decisions about their data, allowing them to grant or deny permissions as needed during app usage.

The advent of wearables, particularly smartwatches, has introduced a new layer of complexity to this established security paradigm. Devices like those running Wear OS (Google's operating system for smartwatches) have gained immense popularity for their convenience in fitness tracking, activity monitoring, and mobile payments. These devices often handle data that is arguably even more sensitive than that on smartphones, including vital signs, physical activities, and precise location information. Consequently, wearable platforms have adopted permission models derived from their smartphone counterparts to protect this data.

However, the unique challenge arises from the inherent "paired device" architecture. A smartphone and a smartwatch typically operate as a connected ecosystem, sharing data and functionalities. While both devices have their own permission models, an critical observation from Android developer guides states that "a wear app can't assume the permissions granted in a phone app." This implies that the permission models on the phone and watch should be considered exclusive, requiring separate consent for each device. Despite this apparent exclusivity, communication channels between these devices allow for the transfer of sensitive data. For instance, if a phone app obtains location permission, it can send that location data to the watch. Conversely, if a watch app gains access to vital signs, it can transmit this data to the phone. This creates a situation where data, once granted on one device, becomes effectively accessible on both, potentially violating user expectations and privacy if they believe their data remains confined to the device where permission was granted.

Beyond implicit data flows, the talk also highlights an adversarial technique involving redirection prompts. These are developer-controlled dialogues shown before a permission request is triggered on the other device. An attacker can craft these prompts to mislead users. For example, a prompt might mention the need for "storage access" while the subsequent permission dialogue on the companion device actually requests "camera" access. User research indicates that users are more likely to grant storage permission than camera permission. An adversary can exploit this by showing a less sensitive request in the redirection prompt, then requesting a more sensitive one on the companion device, banking on users not paying close attention to the second prompt. Alternatively, an adversary could mention a previously granted permission in the redirection prompt, leveraging the user's high likelihood to re-grant permissions they believe they've already approved. These techniques allow adversaries to inadvertently obtain permissions that users would typically deny, further exacerbating the privacy risks in cross-device ecosystems.

Key Findings

▶ Watch: Introducing Flowfinder: Tool for detecting cross-device data flows (5:55)

The research presented in "Wear's my Data?" uncovers several critical findings regarding cross-device permission models and user understanding in wearable ecosystems:

  1. Prevalence of Cross-Device Data Flows in Real-World Apps: Through their static analysis tool, FlowFinder, the researchers analyzed a dataset of 150 paired watch and phone applications. They discovered that 28 out of these 150 applications (18.7%) exhibited sensitive cross-device data flows. This demonstrates that the issue is not theoretical but is actively present in a significant portion of apps available to users.
  • Directionality of Flows: The majority of identified flows (as shown in their results table) were from the phone to the watch. This is largely attributed to the prevalence of watch face applications in their dataset, which often lack the capability to directly request permissions on the watch but require data (like location) from the phone to function. Conversely, sensor data flows were predominantly from the watch to the phone, as the phone typically lacks the specialized biometric and activity sensors present on smartwatches.
  1. Lack of User Notification by Apps: A crucial finding was the almost complete absence of transparency from applications regarding these cross-device data transfers.
  • In-App Information: None of the 28 apps found to have cross-device data flows informed users about these transfers from within the application's user interface during interaction.
  • Store Descriptions: Only two of the analyzed apps mentioned any form of data transfer in their store descriptions.
  • Privacy Policies: A mere one app explicitly stated the type and purpose of data being transferred in its privacy policy. This significant lack of disclosure leaves users entirely unaware that their data might be flowing between devices.
  1. Platform-Level Misinformation and Evolution: The study also examined how the Wear OS platform itself informs users.
  • Wear OS 2: During device pairing, Wear OS 2 presented a location notice stating that turning off location in watch settings would "keep your watch from using location data from phone and watch." However, the research confirmed that even with this setting toggled off, the watch could still access the phone's location via cross-device data flows, rendering the platform's claim misleading.
  • Wear OS 3: While Wear OS 3 no longer makes this specific misleading claim about location, the underlying cross-device data flow issue persists, indicating a partial but incomplete recognition of the problem by the platform.
  1. Widespread User Misconceptions about Permissions: A user study involving 63 Android and Wear OS users revealed profound misunderstandings regarding how permissions operate in a cross-device context.
  • Cross-Device Data Flow Understanding (RQ1): In a scenario where a user granted location permission on the phone but denied it on the watch, 66% of participants believed that only the phone app could access the phone's location. Only 31% correctly understood that both apps could access the phone's location due to cross-device flows. This demonstrates a significant mental model mismatch, where users expect data to be contained within the device where permission was granted or denied.
  • Vulnerability to Redirection Prompt Phishing (RQ2): The study confirmed the efficacy of redirection prompt phishing. When participants saw a redirection prompt mentioning "photos, media, and files" but the actual permission request was for "camera," the number of people who believed the app could not access storage data increased from 0% (control group) to 17% (experimental group). While this percentage might seem modest, it indicates that a portion of users were successfully misled, and the researchers anticipate this number would increase if semantically more distinct permissions were used in the phishing attempt. This highlights a clear path for adversaries to trick users into granting sensitive permissions.
  1. Preliminary Analysis of Other Ecosystems (iOS/watchOS): While the primary focus was Wear OS, preliminary analysis on iOS and watchOS revealed a different approach: permission synchronization. In this model, a user's decision to grant or deny a permission on one device (e.g., iPhone) is automatically applied to the companion device (watchOS app). This synchronization is often unidirectional (phone to watch) and occurs at runtime without explicit notification. Furthermore, revocation of such synchronized permissions is typically only possible from the phone, with the option disabled on the watch. While this aligns better with the reality of data flow, it still requires users to be informed to prevent privacy violations, as a majority of users still expect device-centric data containment.

These findings collectively paint a picture of a complex and often opaque permission landscape in wearables, where technical realities, platform behaviors, and user expectations are frequently misaligned, creating significant privacy risks.

Technical Deep Dive

▶ Watch: Findings: Significant number of apps have cross-device data flows (7:05)

The technical foundation of this research lies in the development and application of FlowFinder, a static analysis tool designed to identify sensitive cross-device data flows within paired Android and Wear OS applications. The methodology employed by FlowFinder is systematic and robust, leveraging established program analysis techniques.

The process begins by converting each APK (Android Package Kit) of the phone and watch applications into an intermediate representation. The speakers mention "GLE ir" and then clarify "jimble IR" which is Jimple IR, a three-address code representation commonly used by the Soot framework for static analysis of Java bytecode. This conversion is crucial as it normalizes the application's code into a format amenable to detailed program analysis.

Once in Jimple IR, FlowFinder performs specific instrumentation to enhance the subsequent taint analysis. Taint analysis is a security-focused static analysis technique that tracks the flow of "tainted" data (sensitive information) from sources (where sensitive data originates) to sinks (where sensitive data might be leaked or used in an insecure way). FlowFinder's instrumentation addresses several complexities:

  • Handling Callbacks: Mobile applications heavily rely on callbacks for event handling and inter-component communication. FlowFinder adds taint wrappers around these callbacks to ensure that taint information is correctly propagated across these asynchronous and often indirect execution paths.
  • Complex Data Flows: For more intricate data manipulation and transformations, additional taint wrappers are introduced. These wrappers ensure that even when data undergoes various operations, its taint status is maintained and accurately tracked.
  • Explicit Functions for Data Sources: Some data sources might not have explicit function calls that are easily identifiable by a standard taint analysis framework. FlowFinder addresses this by adding explicit functions that mark such data as tainted, ensuring comprehensive coverage of sensitive data origins.

With the instrumented Jimple IR, FlowFinder then utilizes FlowDroid, a well-known static taint analysis framework for Android applications. FlowDroid requires a comprehensive list of sources and sinks to perform its analysis.

  • Sources: The researchers gathered a list of sensitive data sources by consulting previous academic works on Android security and by meticulously analyzing the Android Open Source Project (AOSP) code. This ensures that a wide array of sensitive data types—such as location, contacts, camera data, sensor readings, and personal identifiers—are correctly identified as starting points for taint propagation.
  • Sinks: Identifying sinks for cross-device data flows is a unique challenge. The team systematically analyzed the Wear OS data layer, a critical component responsible for communication between the phone and the smartwatch. They specifically identified functions and APIs within this data layer that are involved in transferring data between the two devices. These inter-device communication functions serve as the sinks, indicating points where sensitive data might leave one device and arrive at the other.

After performing the taint analysis using FlowDroid, FlowFinder generates a list of potential sensitive cross-device data flows. This raw list then undergoes a crucial verification step. For each identified data flow, the tool confirms that the target application (either on the phone or the watch) possesses the corresponding permissions required for accessing the sensitive data involved in that flow. This verification step helps to filter out false positives and ensure that the identified flows represent genuine privacy risks where an app could legitimately obtain data on one device and transfer it to the other.

The application of FlowFinder to a dataset of 150 paired watch and phone applications yielded concrete results, identifying 28 apps with cross-device sensitive data flows. This technical approach demonstrates a practical method for uncovering systemic privacy vulnerabilities that arise from the unique architectural design of wearable ecosystems.

Demo / Proof of Concept

▶ Watch: Lack of transparency: Apps don't inform users about flows (8:12)

The talk effectively demonstrated its core findings through two primary proof-of-concept methodologies: the FlowFinder static analysis tool and a comprehensive user study.

1. FlowFinder: Demonstrating Cross-Device Data Flows in the Wild

FlowFinder, as detailed in the "Technical Deep Dive," served as the primary proof-of-concept for identifying the existence and prevalence of cross-device sensitive data flows. While the talk didn't feature a live code demo of FlowFinder, the researchers presented its methodology and the quantitative results derived from its application to a real-world dataset.

  • Methodology as PoC: The explanation of FlowFinder's architecture—converting APKs to Jimple IR, instrumenting for taint analysis, defining sources (from AOSP and prior work) and sinks (from Wear OS data layer), and using FlowDroid—serves as a technical demonstration of how such flows can be systematically detected. This shows that the problem is not theoretical but can be programmatically identified.
  • Empirical Evidence: The most compelling "demo" from FlowFinder was the quantitative result: 28 out of 150 real-world paired applications were found to exhibit sensitive cross-device data flows. The talk presented a table summarizing these flows, indicating permissions like ACCESS_FINE_LOCATION, BODY_SENSORS, and READ_CONTACTS being transferred. This empirical evidence directly proves that applications are indeed leveraging (or inadvertently creating) these channels for sensitive data transfer between devices.
  • Directionality: The findings about the directionality of flows (e.g., phone-to-watch for location in watch face apps, watch-to-phone for sensor data) further illustrated the practical implications and specific scenarios where these flows occur, making the problem tangible.

2. User Study: Demonstrating User Misconceptions and Phishing Vulnerability

The user study served as a crucial proof-of-concept for the human element of the problem, demonstrating how users perceive permissions and how easily they can be misled. This was a semi-structured interview study conducted with 63 Android and Wear OS users, involving three scenarios.

  • Scenario 1: Cross-Device Data Flow Understanding (RQ1):
  • Setup: Users interacted with a phone, granting location permission to a phone app. Then, they opened a companion watch app and denied location permission on the watch.
  • Demonstration: The question posed was: "Which app can access the phone's location?" The results were a stark demonstration of user misunderstanding: 66% of participants incorrectly believed only the phone app had access, while only 31% correctly identified that both apps had access due to cross-device flows. This scenario directly proved that the majority of users have a flawed mental model regarding cross-device data accessibility, making them vulnerable to unexpected data sharing.
  • Scenario 2: Redirection Prompt Phishing (RQ2):
  • Setup: Participants were divided into a control group (G1) and an experimental group.
  • Control (G1): Saw a redirection prompt stating "App needs your camera access," then granted camera permission.
  • Experimental: Saw a redirection prompt stating "App needs access to photos, media and files" (a less sensitive request), then saw the actual permission prompt for "camera access" and granted it.
  • Demonstration: The follow-up question was: "Do you think the phone app can access files, photos, and videos?" The results demonstrated the effectiveness of phishing: In the control group, 0% believed the app could not access storage. In the experimental group, this increased to **17% who believed the app could not access storage**, implying that the redirection prompt successfully misled the remaining participants into thinking they were granting storage access or were confused about what they had granted. This directly proved that redirection prompts could be used to trick users into granting permissions they might not intend. The speakers also noted that with "semantically separate permissions," this success rate would likely be even higher.

Together, FlowFinder provided the technical proof of concept for the existence of the problem in code, while the user study provided the human-centric proof of concept for the impact of the problem on user privacy and security decisions.

Defensive Implications

▶ Watch: Platform's role: Wear OS also fails to adequately inform users (8:50)

The findings presented in "Wear's my Data?" necessitate a multi-faceted defensive strategy to protect user privacy in the cross-device wearable ecosystem. The proposed countermeasures target various layers, from user education and UI/UX design to platform-level policy enforcement and app market scrutiny.

  1. Enhanced Information Prompts:
  • Concept: Implement additional, explicit prompts to inform users about the possibility of sensitive data flowing between paired devices. This addresses the significant gap in user understanding identified by the user study.
  • Challenges: The effectiveness heavily relies on careful UI/UX design. Prompts must be concise, clear, and actionable to avoid "permission fatigue" or being overlooked. As the speakers noted, if prompts are too long, confusing, or users simply don't read them, their impact will be minimal. Further user studies are required to determine the optimal wording, placement, and timing for these notifications.
  • Goal: Shift user mental models from device-centric to ecosystem-centric awareness regarding data accessibility.
  1. User-Centric Permission Model with Consent-Driven Synchronization:
  • Concept: Move away from independent permission decisions on each device towards a model where a user's permission choice for a specific data type (e.g., location) on one device automatically applies to the companion device. This aligns with what was observed in iOS/watchOS.
  • Crucial Caveat: Unlike the current iOS/watchOS model which synchronizes without notification, the researchers emphasize that users must still be explicitly informed and give consent for this synchronization. Given that 66% of users in their study expected data to remain on the granting device, implementing synchronization by default without consent would violate user expectations and privacy.
  • Benefit: This model reflects the technical reality of data flow more accurately and reduces the cognitive load on users, but only if accompanied by clear communication and explicit consent for the synchronization itself.
  • Platform Development: The talk highlights that Android and Wear OS are actively working on a platform-level solution moving towards a user-centric model with unidirectional synchronization (phone to watch) and plans to educate users. This feature, while not yet active, represents a significant step towards addressing the problem at its root.
  1. App Market Analysis and Vetting:
  • Concept: Utilize static analysis tools, such as the developed FlowFinder, at the app market level (e.g., Google Play Store) to proactively identify applications that exhibit sensitive cross-device data flows.
  • Mechanism: Apps found to transfer sensitive data between devices without adequate disclosure could be flagged, required to update their privacy policies, or even prevented from being published until compliant.
  • Limitations: This approach is primarily effective for apps distributed through official app markets. It would miss "side-loaded" applications installed outside of these official channels, which could still pose a significant threat.
  • Complementary Role: App market analysis serves as a critical gatekeeper, preventing malicious or privacy-violating apps from reaching a wide audience.
  1. Combination of Solutions:
  • The speakers advocate for a combination of these approaches to address the issues from multiple angles. No single solution is a panacea. User education, platform-level policy changes, and app market enforcement must work in concert to create a robust defense.
  1. Mitigation of Redirection Prompt Phishing:
  • Platform Control: Platforms could restrict the content or nature of redirection prompts to prevent developers from displaying misleading information. This might involve standardizing prompt templates or requiring explicit declarations of what permission will be requested next.
  • User Education: Continued user education on vigilance against mismatched prompts and the importance of reading actual permission dialogues remains crucial.

In essence, the defensive implications call for a fundamental re-evaluation of how permissions are conceived and communicated in interconnected device ecosystems. The shift towards a user-centric model, coupled with transparency and strong enforcement mechanisms, is vital to restore user trust and ensure privacy in the age of wearables.

Key Takeaways

  • Cross-device data flows are prevalent and problematic: A significant portion (18.7%, 28 of 150) of real-world paired phone and watch apps exhibit sensitive data transfers between devices, even if permissions are denied on one.
  • User mental models are misaligned with reality: A large majority of users (66%) incorrectly believe that data is confined to the device where permission was granted or denied, failing to account for cross-device flows.
  • Apps and platforms lack transparency: Most apps do not inform users about cross-device data transfers in-app, in store descriptions, or in privacy policies, and platform notices (e.g., Wear OS 2) have historically been misleading.
  • Redirection prompts are a phishing vector: Adversaries can exploit developer-controlled redirection prompts to trick users into granting sensitive permissions by misrepresenting the actual permission being requested on the companion device.
  • Multi-layered countermeasures are essential: A combination of explicit user information prompts, a user-centric permission model with consent-driven synchronization, and app market static analysis (like FlowFinder) is needed to address these issues.
  • Future platform changes are underway: Android and Wear OS are actively working towards a platform-level, user-centric permission model with unidirectional synchronization from phone to watch, aiming to improve user education and address current misconceptions.

About the Speaker(s)

The talk "Wear's my Data? Understanding the Cross-Device Runtime Permission Model in Wearables" was presented by a collaborative team of researchers.

Doguhan Yeke is a PhD student at Purdue University, where he is involved in research concerning the security and privacy of mobile and wearable computing platforms.

Muhammad Ibrahim is also a PhD student at Purdue University, contributing to the understanding and analysis of security vulnerabilities in modern computing systems.

Güliz Seray Tuncay is associated with Google, bringing industry perspective and expertise to the research, particularly relevant given Google's role in developing the Wear OS platform.

The work also involved collaborators Habiba Farrukh and Antonio Bianchi from Purdue University, and Abdullah Imran from the University of Florida, indicating a broad academic collaboration on this significant security and privacy topic.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This research uncovers critical, systemic privacy vulnerabilities in the Wear OS cross-device permission model, demonstrating how sensitive data flows between paired devices often bypass user expectations and explicit denials. The team's static analysis tool, FlowFinder, provides concrete evidence of these flows in real-world apps, while their user study highlights widespread misconceptions and a practical phishing vector via redirection prompts. This is essential work that directly impacts platform design and user trust in wearable ecosystems.

Heather Calloway (CISO) — STRONG ACCEPT

This research uncovers critical privacy vulnerabilities in wearable ecosystems, demonstrating how cross-device data flows and user misunderstandings create significant risk. It provides compelling evidence of platform and app developer accountability gaps, offering clear, actionable paths for platform providers and organizations to enhance security governance and protect sensitive user data.

→ Top-rated talks at IEEE Symposium on Security and Privacy 2024

All talks from IEEE Symposium on Security and Privacy 2024