David Rodríguez Torrado

dblp:349/6875 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
4since 2021 · last 2025
0000-0002-0911-4608ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 4 since 2021
YearPublicationVenuePosition
2025 Privacy Settings of Third-Party Libraries in Android Apps: A Study of Facebook SDKs
abstract
Previous studies have demonstrated that privacy issues in mobile apps often stem from the integration of third-party libraries (TPLs). To shed light on factors that contribute to these issues, we investigate the privacy-related configuration choices available to and made by Android app developers who incorporate the Facebook Android SDK and Facebook Audience Network SDK in their apps. We compile these Facebook SDKs' privacy-related settings and their defaults. Employing a multi-method approach that integrates static and dynamic analysis, we analyze more than 6,000 popular apps to determine whether the apps incorporate Facebook SDKs and, if so, whether and how developers modify settings. Finally, we assess how these settings align with the privacy practices that developers disclose in the apps’ privacy labels and policies. We observe widespread inconsistencies between practices and disclosures in popular apps. These inconsistencies often stem from privacy settings, including a substantial number of cases in which apps retain default settings over alternatives that offer greater privacy. We observe fewer possible compliance issues in potentially child-directed apps, but issues persist even in these apps. We discuss remediation strategies that SDK and TPL providers could employ to help developers, particularly developers with fewer resources who rely heavily on SDKs. Our recommendations include aligning default privacy settings with data minimization principles and other conservative practices and making privacy-related SDK information both easier to find and harder to miss.
David Rodríguez Torrado, Joseph A. Calandrino, José M. del Álamo, Norman M. Sadeh
Proc. Priv. Enhancing Technol.1
2024 Hunter: Tracing anycast communications to uncover cross-border personal data transfers
abstract
Cross-border personal data transfers are heavily regulated worldwide, with data protection authorities imposing huge fines on organizations that fail to meet their strict compliance requirements. However, network-level optimizations such as anycast addresses were not designed with personal data in mind, and their use may unwittingly divert personal data out of a legal boundary. This paper describes Hunter, an automated method to trace anycast communications and identify those threatening data protection compliance. We have applied Hunter in the wild to a set of Android apps to discover that all apps observed sending personal data to anycast addresses eventually carry out international transfers but fail to disclose them in their privacy policies. Our findings suggest that using anycast addresses to transmit personal data generally results in data protection compliance issues.
Hugo Pascual, José M. del Álamo, David Rodríguez Torrado, Juan C. Dueñas
Comput. Secur.3
2023 Automated GDPR compliance assessment for cross-border personal data transfers in android applications
abstract
The General Data Protection Regulation (GDPR) aims to ensure that all personal data processing activities are fair and transparent for the European Union (EU) citizens, regardless of whether these are carried out within the EU or anywhere else. To this end, it sets strict requirements to transfer personal data outside the EU. However, checking these requirements is a daunting task for supervisory authorities, particularly in the mobile app domain due to the huge number of apps available and their dynamic nature. In this paper, we propose a fully automated method for assessing the compliance of Android apps with the GDPR requirements for cross-border personal data transfers. We have applied the method to 4593 apps from the Google Play Store discovering that nearly half of the ones sending personal data are potentially non-compliant with GDPR requirements. These results reveal that there is still a very significant gap between what app providers do in practice and what is intended by the GDPR.
Danny S. Guamán, David Rodríguez Torrado, José M. del Álamo, Jose M. Such
Comput. Secur.2
2022 Identifying Organizations Receiving Personal Data in Android Apps
David Rodríguez Torrado, Miguel Cozar, José M. del Álamo
SECRYPT1