Security and Privacy with Second-Hand Storage Devices: A User-Centric Perspective from Switzerland

Archive ouverte

Salehzadeh Niksirat, Kavous | Korka, Diana | Jacquemin, Quentin | Vanini, Céline | Humbert, Mathias | Cherubini, Mauro | Métille, Sylvain | Huguenin, Kévin

Edité par CCSD ; Privacy Enhancing Technologies Symposium -

International audience. Second-hand electronic devices are increasingly being sold online. Although more affordable and more environment-friendly than new products, second-hand devices, in particular those with storage capabilities, create security and privacy threats (e.g., malware or confidential data still stored on the device, aka remnant data). Previous work studied this issue from a technical point of view or only from the perspective of the sellers of the devices, but the perspective of the buyers has been largely overlooked. In this paper, we fill this gap and take a multi-disciplinary approach, focusing on the case of Switzerland. First, we conduct a brief legal analysis of the rights and obligations related to second-hand storage devices. Second, in order to understand the buyers’ practices related to these devices and their beliefs about their legal rights and obligations, we deploy a survey in collaboration with a major online platform for transactions of second-hand goods. We demonstrate that the risks highlighted in prior research might not materialize, as many buyers do not inspect the content of the bought devices (e.g., they format it directly). We also found that none of the buyers uses forensic techniques. We identified that the buyers’ decisions about remnant data depend on the type of data. For instance, for data with illegal content, they would keep the data to report it to the authorities, whereas for sensitive personal data they would either delete the data or contact the sellers. We identified several discrepancies between the actual legal rights/obligations and users’ beliefs

Suggestions

Du même auteur

Shadow Health-Related Data: Definition, Categorization, and User Perspectives

Archive ouverte | El Zein, Yamane | CCSD

International audience. Health-related data (HRD) about individuals are increasingly generated and processed. The sources and volume of such data have grown larger over the past years, including wearable devices, he...

KGP Meter: Communicating Kin Genomic Privacy to the Masses

Archive ouverte | Humbert, Mathias | CCSD

International audience. Direct-to-consumer genetic testing services are gaining momentum: As of today, companies such as 23andMe or AncestryDNA have already attracted 26 million customers. These services raise priva...

Exploring the Impact of Commercial Wearable Activity Trackers on Body Awareness and Body Representations: A Mixed-Methods Study on Self-tracking

Archive ouverte | Boldi, Arianna | CCSD

International audience. Wearable trackers are believed to enhance users’ self-knowledge, but their impact on the relationship that people have with their own bodies is relatively unexplored. This study aims to shed ...

Chargement des enrichissements...