Skip to main content
User Image

Noura Nassir AlOmar نوره بنت ناصر العمر

Lecturer

College of Computer and Information Sciences , Software Engineering Department.

علوم الحاسب والمعلومات
Building 6, 3rd floor, office# 22
publication
Conference Paper
2023

Lessons in VCR repair: Compliance of android app developers with the california consumer privacy act (CCPA)

The California Consumer Privacy Act (CCPA) provides California residents with a range of enhanced privacy protections and rights. Our research investigated the extent to which Android app developers comply with the provisions of the CCPA that require them to provide consumers with accurate privacy notices and respond to “verifiable consumer requests” (VCRs) by disclosing personal information that they have collected, used, or shared about consumers for a business or commercial purpose. We compared the actual network traffic of 109 apps that we believe must comply with the CCPA to the data that apps state they collect in their privacy policies and the data contained in responses to “right to know” requests that we submitted to the app’s developers. Of the 69 app developers who substantively replied to our requests, all but one provided specific pieces of personal data (as opposed to only categorical information). However, a significant percentage of apps collected information that was not disclosed, including identifiers (55 apps, 80%), geolocation data (21 apps, 30%), and sensory data (18 apps, 26%) among other categories. We discuss improvements to the CCPA that could help app developers comply with “right to know” requests and other related regulations.

Publisher Name
Proceedings on Privacy Enhancing Technologies
Conference Location
Lausanne, Switzerland
Conference Name
Proceedings on Privacy Enhancing Technologies
more of publication
publications
by Noura Alomar, Joel Reardon, Aniketh Girish, Narseo Vallina-Rodriguez, Serge Egelman
2025
Published in:
The 25th Privacy Enhancing Technologies Symposium
publications

The Time-based One-Time Password (TOTP) algorithm is a 2FA method that is widely deployed because of its relatively low implementation costs and purported security benefits over SMS 2FA.

by Conor Gilsenan, Fuzail Shakir, Noura Alomar, Serge Egelman
Published in:
USENIX Association
publications

The California Consumer Privacy Act (CCPA) provides California residents with a range of enhanced privacy protections and rights.

by Nikita Samarin, Shayna Kothari, Zaina Siyed, Oscar Bjorkman, Reena Yuan, Primal Wijesekera, Noura Alomar, Jordan Fischer, Chris Hoofnagle, Serge Egelman
2023
Published in:
Proceedings on Privacy Enhancing Technologies