Author:
Al-Ameen Mahdi Nasrullah,Chauhan Apoorva,Ahsan M.A. Manazir,Kocabas Huzeyfe
Abstract
Purpose
With the rapid deployment of internet of things (IoT) technologies, it has been essential to address the security and privacy issues through maintaining transparency in data practices. The prior research focused on identifying people's privacy preferences in different contexts of IoT usage and their mental models of security threats. However, there is a dearth in existing literature to understand the mismatch between user's perceptions and the actual data practices of IoT devices. Such mismatches could lead users unknowingly sharing their private information, exposing themselves to unanticipated privacy risks. The paper aims to identify these mismatched privacy perceptions in this work.
Design/methodology/approach
The authors conducted a lab study with 42 participants, where they compared participants’ perceptions with the data practices stated in the privacy policy of 28 IoT devices from different categories, including health and exercise, entertainment, smart homes, toys and games and pets.
Findings
The authors identified the mismatched privacy perceptions of users in terms of data collection, sharing, protection and storage period. The findings revealed the mismatches between user's perceptions and the data practices of IoT devices for various types of information, including personal, contact, financial, heath, location, media, connected device, online social media and IoT device usage.
Originality/value
The findings from this study lead to the recommendations on designing simplified privacy notice by highlighting the unexpected data practices, which in turn, would contribute to the secure and privacy-preserving use of IoT devices.
Subject
Management of Technology and Innovation,Information Systems and Management,Computer Networks and Communications,Information Systems,Software,Management Information Systems
Reference36 articles.
1. Exploring the potential of geopass: a geographic location-password scheme;Interacting with Computers,2017
2. The impact of cues and user interaction on the memorability of system-assigned recognition-based graphical passwords,2015
3. ‘Most companies share whatever they can to make money!’: comparing user’s perceptions with the data practices of IoT devices,2020
4. We don’t give a second thought before providing our information: understanding users’ perceptions of information collection by apps in urban Bangladesh,2020
5. Why phishing still works: user strategies for combating phishing attacks;International Journal of Human-Computer Studies,2015
Cited by
5 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献