Conference proceeding
Why Johnny Can't Make Money With His Contents: Pitfalls of Designing and Implementing Content Delivery Apps
Proceedings of the 34th Annual Computer Security Applications Conference, pp.236-251
ACSAC '18
12/03/2018
DOI: 10.1145/3274694.3274752
Abstract
Mobile devices are becoming the default platform for multimedia content consumption. Such a thriving business ecosystem has drawn interests from content distributors to develop apps that can reach a large number of audience. The business-edge of content delivery apps crucially relies on being able to effectively arbitrate the purchase and delivery of contents, and govern the access of contents with respect to usage control policies, on a plethora of consumer devices. Content protection on mobile platforms, especially in the absence of Trusted Execution Environment (TEE), is a challenging endeavor where developers often have to resort to ad-hoc deterrence-based defenses. This work evaluates the effectiveness of content protection mechanisms embraced by vendors of content delivery apps, with respect to a hierarchy of adversaries with varying real-world capabilities. Our analysis of 141 vulnerable apps uncovered that, in many cases, due to developers' unjustified trust assumptions about the underlying technologies, adversaries can obtain unauthorized and unrestricted access to contents of apps, sometimes without even needing to reverse engineer the deterrence-based defenses. Some weaknesses in the apps can also severely impact app users' security and privacy. All our findings have been responsibly disclosed to the corresponding app vendors.
Details
- Title: Subtitle
- Why Johnny Can't Make Money With His Contents: Pitfalls of Designing and Implementing Content Delivery Apps
- Creators
- Sze ChauBincheng WangJianxiong WangOmar ChowdhuryAniket KateNinghui Li
- Resource Type
- Conference proceeding
- Publication Details
- Proceedings of the 34th Annual Computer Security Applications Conference, pp.236-251
- Series
- ACSAC '18
- DOI
- 10.1145/3274694.3274752
- Publisher
- ACM
- Grant note
- DOI: 10.13039/100000183, name: Army Research Office, award: W911NF-16-1-0127; DOI: 10.13039/100000001, name: National Science Foundation, award: 1657124
- Language
- English
- Date published
- 12/03/2018
- Academic Unit
- Computer Science
- Record Identifier
- 9984002589102771
Metrics
33 Record Views