Skip to main navigation Skip to search Skip to main content

Why Johnny can't make money with his contents: Pitfalls of designing and implementing content delivery apps

  • Sze Yiu Chau
  • , Omar Chowdhury
  • , Bincheng Wang
  • , Aniket Kate
  • , Jianxiong Wang
  • , Ninghui Li
  • Purdue University
  • University of Iowa

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

3 Scopus citations

Abstract

Mobile devices are becoming the default platform for multimedia content consumption. Such a thriving business ecosystem has drawn interests from content distributors to develop apps that can reach a large number of audience. The business-edge of content delivery apps crucially relies on being able to effectively arbitrate the purchase and delivery of contents, and govern the access of contents with respect to usage control policies, on a plethora of consumer devices. Content protection on mobile platforms, especially in the absence of Trusted Execution Environment (TEE), is a challenging endeavor where developers often have to resort to ad-hoc deterrence-based defenses. This work evaluates the effec-tiveness of content protection mechanisms embraced by vendors of content delivery apps, with respect to a hierarchy of adversaries with varying real-world capabilities. Our analysis of 141 vulnerable apps uncovered that, in many cases, due to developers' unjustified trust assumptions about the underlying technologies, adversaries can obtain unauthorized and unrestricted access to contents of apps, sometimes without even needing to reverse engineer the deterrence-based defenses. Some weaknesses in the apps can also severely impact app users' security and privacy. All our findings have been responsibly disclosed to the corresponding app vendors.

Original languageEnglish
Title of host publicationACM International Conference Proceeding Series
PublisherAssociation for Computing Machinery
Pages236-251
Number of pages16
ISBN (Electronic)9781450365697
DOIs
StatePublished - Dec 3 2018
Event34th Annual Computer Security Applications Conference, ACSAC 2018 - San Juan, United States
Duration: Dec 3 2018Dec 7 2018

Publication series

NameACM International Conference Proceeding Series

Conference

Conference34th Annual Computer Security Applications Conference, ACSAC 2018
Country/TerritoryUnited States
CitySan Juan
Period12/3/1812/7/18

Fingerprint

Dive into the research topics of 'Why Johnny can't make money with his contents: Pitfalls of designing and implementing content delivery apps'. Together they form a unique fingerprint.

Cite this