Addressing the Address Books' (Interdependent) Privacy Issues
Kavous Salehzadeh Niksirat (Max Planck Institute for Security and Privacy)
34th USENIX Security Symposium (USENIX Security '25) · Day 3 · Privacy 3: Attacks
Overview
Kavous Salehzadeh Niksirat, from the Max Planck Institute for Security and Privacy, presented a critical examination of the often-overlooked privacy issues inherent in digital address books (DAPs). Co-authored with colleagues from the University of Lausanne, University of Zurich, and Masaryk University, this research highlights how DAPs are a textbook example of interdependent privacy, a concept where one individual's privacy is significantly impacted by the actions of others. The talk delves into the pervasive practice of storing personally identifiable information (PII) about contacts, often without their knowledge or consent, and the subsequent syncing of this data with online services and third-party applications.

Key moments
- 0:00 Introduction to interdependent privacy and digital address books
- 2:50 Privacy risks: profiling, linking, and data updates
- 4:00 Overview of three main research questions
- 4:45 Methodology: large-scale online user surveys
- 7:30 Finding: Widespread third-party app access to address book data
- 9:00 Finding: Strong user support for data subjects' rights
- 9:45 Users envision a privacy dashboard for managing contact data
Addressing the Address Books' (Interdependent) Privacy Issues
Speakers: Kavous Salehzadeh Niksirat
Conference: USENIX Security
YouTube: https://www.youtube.com/watch?v=pZHJXO_6ilY
Overview
Kavous Salehzadeh Niksirat, from the Max Planck Institute for Security and Privacy, presented a critical examination of the often-overlooked privacy issues inherent in digital address books (DAPs). Co-authored with colleagues from the University of Lausanne, University of Zurich, and Masaryk University, this research highlights how DAPs are a textbook example of interdependent privacy, a concept where one individual's privacy is significantly impacted by the actions of others. The talk delves into the pervasive practice of storing personally identifiable information (PII) about contacts, often without their knowledge or consent, and the subsequent syncing of this data with online services and third-party applications.
The significance of this research lies in its exploration of a domain previously underexplored despite its profound privacy implications. Digital address books are repositories of highly sensitive PII, which, when aggregated and linked, can be invaluable for user profiling, identity resolution, and data enrichment by service providers and other entities. This talk not only uncovers the extent of user practices and perceptions regarding DAP data but also quantifies the willingness of users to share this sensitive information, even for minimal financial incentives. The findings underscore a critical gap in current privacy frameworks and user awareness, proposing a paradigm shift towards granting data subjects greater control over their information stored in others' DAPs.
Background
▶ Watch: Introduction to interdependent privacy and digital address books (0:00)
The concept of interdependent privacy posits that an individual's privacy is not solely determined by their own actions but is significantly influenced by the behaviors of others. This phenomenon has been extensively studied in various contexts, including online social networks, location-sharing applications, and even genomics, where a person's genetic information can reveal details about their relatives. In some domains, particularly with technologies like voice assistants or smart homes, it's also referred to as bystander privacy. However, the digital address book, a ubiquitous tool used by billions, has remained surprisingly underexplored in this regard, despite being a prime example of interdependent privacy in action.
Digital address books (DAPs), also known as phone books or contact apps, are used to store personally identifiable information (PII) such as names, phone numbers, and email addresses in a structured format. A significant privacy risk arises from the common practice of syncing this data with online services like Google Contacts or Apple iCloud, or granting access to third-party applications such as instant messengers (e.g., WhatsApp) and social networks. Crucially, this often occurs without the knowledge or explicit consent of the individuals whose data is being stored and transmitted. These "contacts" (referred to as data subjects) may not even be users of the DAP service themselves, yet their PII is collected, processed, and potentially monetized by various entities.
The privacy implications are direct and substantial. DAP data is highly valuable for profiling, especially for linking disparate data points to create comprehensive user profiles or for updating existing ones. For instance, a contact card containing multiple unique identifiers—such as a phone number and an email address—signals that these identifiers belong to the same natural person. This allows service providers to link profiles tied to a phone number with those associated with an email address, or even connect old and new phone numbers to maintain an up-to-date profile. The talk presents a simplified overview of the DAP ecosystem, illustrating how an Alice (DAP user) stores John's (contact/data subject) information, which is then synced with service providers and potentially accessed by third-party apps, all without John's involvement or consent. This intricate web highlights the inherent vulnerability of data subjects in the current DAP paradigm.
Key Findings
▶ Watch: Overview of three main research questions (4:00)
The research was guided by three core questions: how people use DAPs and the completeness of their entries; user perceptions of privacy risks and data subject rights; and imagined privacy-preserving solutions. To answer these, two large-scale online surveys were conducted, gathering responses from over 900 participants.
Study 1: Self-Reported Practices and Perceptions
This study involved 463 respondents, focusing on users of Google Contacts or Apple iCloud. It employed a between-subject design, asking respondents to consider perspectives as both a DAP user and a data subject.
- DAP Access Patterns: Almost all users accessed DAPs via their phones, with 42% never using a web browser and nearly 30% using only a single platform (their phone). This suggests that end-to-end encryption (E2E) could be implemented without significantly disrupting most users' workflows, as data could be encrypted at rest on service provider servers with only the user holding the decryption key. Mainstream providers like Apple and Google currently do not offer this.
- Third-Party App Access: A striking 90% of users reported having at least one third-party app with permission to access their DAP, and over one-third (33%) had 10 or more such apps installed. The 199 unique apps identified were predominantly communication apps (e.g., WhatsApp, Gmail), followed by social networking, productivity, finance, and travel apps.
- Awareness of Provider Access: Over 80% of respondents agreed that DAP service providers could access their contact data in clear (unencrypted) form, indicating a relatively high level of awareness regarding the privacy implications of mainstream DAP services.
- Sensitive Data Fields: Addresses and photos were identified as the most sensitive types of information stored, a sentiment shared by both DAP users and data subjects.
- Support for Data Subject Rights: Respondents largely favored granting data subjects rights over their PII stored in others' DAPs, including the ability to prevent, delete, access, or correct data. Around 40% to 48% agreed with such rights, indicating broad support for enhanced data subject protections.
- Privacy-Preserving Solutions: When asked to imagine a dashboard for managing their data stored in others' DAPs, respondents proposed six main features. The most prominent was the ability to edit and delete information. While some believed user consent should be required for such changes, others argued for full control by data subjects, highlighting a tension between user agency and data subject rights.
Study 2: Behavioral Analysis and Willingness to Share
This study focused on actual user behavior and willingness to share DAP data, recruiting users of Google Contacts.
- Data Completeness: Analysis of actual contact cards showed that first name, phone number, and last name were the most common entries. While the median proportion of contact cards including a birthday was only 3.6%, a crucial "back-of-the-envelope" calculation demonstrated the interdependent privacy risk: if a data subject appears in 50 users' DAPs, there is an 86% chance that at least one service provider has their birthday, even with such a low individual inclusion rate. This underscores how rarely included fields can still lead to significant privacy breaches due to aggregation.
- Willingness to Share: Without any financial bonus, approximately 20% of respondents granted access to their Google Contacts data, with 10% providing usable data. As bonuses increased up to $5, willingness rose slightly but then plateaued, suggesting that some individuals value their contact data, including that of others, at just a few dollars.
- Reasons for Choices:
- Granting Access: Primary reasons were convenience (DDS method was easier), financial compensation, and a perceived lack of privacy issues.
- Manual Response/Withdrawal: Privacy concerns were central, with many explicitly mentioning interdependent privacy (e.g., "I don't want to reveal others' private contact information without their permission").
- Trust in Google vs. Researchers: Among those who refused to share data under any condition, many cited Google's reputation for privacy and accountability as a reason for trusting Google but not researchers. Others viewed Google's data access as a "necessary evil" for functionality, while expressing distrust towards "random researchers on the internet." Respondents requested a median compensation ranging from $12 to $35 to grant access if they had initially chosen manual entry.
Technical Deep Dive
▶ Watch: Methodology: large-scale online user surveys (4:45)
The core technical problem explored in this talk is the pervasive and under-addressed issue of interdependent privacy within digital address books (DAPs). This concept is foundational: even if an individual (the data subject) meticulously protects their own information, their privacy can be compromised by the actions of others (the DAP users) who store and share their PII.
The DAP ecosystem is complex, involving several entities. At its center is the DAP user (e.g., Alice) who stores PII about their contacts (e.g., John) on their mobile device. This data is then frequently synced with DAP service providers such as Google Contacts or Apple iCloud. Furthermore, many DAP users grant permissions to third-party applications (e.g., WhatsApp, Gmail, social media apps) to access their contact list via platform-specific permissioned APIs. The critical technical vulnerability here is that the data subject (John) is typically entirely outside this loop; his information is processed without his knowledge, consent, or ability to control it.
The types of PII stored in DAPs are extensive and highly sensitive. They include basic identifiers like names (first name, last name), phone numbers, and email addresses, but often extend to more intimate details such as physical addresses, birthdays, and even photos. This granular data, when aggregated, becomes a goldmine for various purposes. Service providers can use this information for profiling, enabling them to build comprehensive dossiers on individuals. For example, if a contact entry contains both a phone number and an email address for the same person, these disparate identifiers can be linked to a single individual's profile. This allows for identity resolution across different platforms and services, and enables profile updating to ensure that information remains current, even if a user changes their phone number or email address. The talk explicitly mentions the value of multiple unique identifiers in a contact card as a strong signal for linking and updating profiles.
A significant technical gap identified is the prevalent lack of end-to-end encryption (E2E) in mainstream DAP services. Despite the sensitive nature of the data, information is often stored in cleartext on service providers' servers. The research highlights an opportunity for E2E implementation: since a substantial portion of users (nearly 30%) access their DAPs solely from a single device (their phone), E2E encryption could be more readily adopted. In such a scenario, data could be encrypted at rest on the service provider's servers, with only the user possessing the decryption key, without significantly disrupting their workflow. The absence of this feature represents a critical security oversight.
The study also provides a tangible example of how even seemingly rare data points can lead to widespread privacy breaches due to the interdependent nature of DAPs. The "back-of-the-envelope" calculation regarding birthdays is a powerful illustration. While only a median of 3.6% of individual contact cards might contain a birthday, if a data subject appears in the DAPs of 50 different users, there's an 86% probability that at least one of those users has stored their birthday. This aggregation risk means that even sparsely collected PII fields become highly accessible to service providers and potentially third parties across the ecosystem.
For the behavioral study (Study 2), the researchers leveraged the Google Contacts API in conjunction with a tool called DDS to access participants' contact data (with their consent). This technical approach allowed for the collection of actual, not just self-reported, data completeness, providing empirical evidence of the information stored. While not a "technical exploit," the use of the API demonstrates the technical accessibility of this PII to authorized (or even unauthorized, given the right permissions) entities, underscoring the ease with which such data can be aggregated and analyzed.
In essence, the technical deep dive reveals a system where sensitive PII is widely collected, often unencrypted, aggregated across multiple users, and readily accessible to a network of service providers and third-party apps, all while the primary data subject remains unaware and disempowered.
Demo / Proof of Concept
▶ Watch: Finding: Strong user support for data subjects' rights (9:00)
While the talk did not feature a traditional "exploit demonstration" of a vulnerability, Study 2 of the research served as a compelling demonstration of the accessibility and value of DAP data through its experimental methodology. The researchers actively engaged participants to either grant access to their Google Contacts data or manually report on it, effectively showcasing how easily this sensitive information can be collected and analyzed.
For participants who chose to grant access, their data was imported using a specific tool called DDS (Data Download Service), which interfaced with the Google Contacts API. This process, conducted with explicit consent from the DAP users, illustrated the technical feasibility of programmatically accessing a user's entire contact list, including various PII fields. The ability of the researchers to extract, process, and then present personalized statistics about this data back to the participants served as a practical proof point for several key issues:
- Data Accessibility: It directly demonstrated that, given user consent (or in real-world scenarios, app permissions), a significant volume of PII can be programmatically extracted from DAPs. This highlights the technical ease with which service providers and third-party apps can access and aggregate this data.
- Data Completeness and Value: By analyzing the actual data extracted, the study provided concrete evidence of the types and completeness of PII stored, such as the median 3.6% inclusion of birthdays. This empirical data underscored the richness and value of DAP information for profiling and linking, as discussed in the technical deep dive.
- User Behavior and Willingness to Share: The experimental setup, which involved offering financial incentives, directly demonstrated the behavioral aspect of data sharing. The fact that approximately 20% of users initially granted access without a bonus, and that this willingness plateaued around a $5 incentive, provides tangible evidence of how users value (or undervalue) their contact data, including that of others.
- Interdependent Privacy in Action: By collecting real data, the study implicitly demonstrated the interdependent privacy problem. The extracted data likely contained information about individuals who were not participants in the study, yet their PII was shared, reinforcing the core premise that one person's actions (sharing their DAP) directly impacts another's privacy.
In essence, the methodology of Study 2, particularly the use of DDS with the Google Contacts API, served as a "proof of concept" for the technical ease of data collection from DAPs and the subsequent insights that can be derived from it, thereby underscoring the practical implications of interdependent privacy risks.
Defensive Implications
▶ Watch: Users envision a privacy dashboard for managing contact data (9:45)
The findings from this research have profound implications for various stakeholders in the digital ecosystem, necessitating a multi-faceted defensive strategy to mitigate the interdependent privacy risks in digital address books.
For Individual DAP Users:
- Be Mindful of Data Stored: Users should be more conscious about the extent and sensitivity of PII they store about others in their DAPs. This includes avoiding unnecessary details like birthdays, addresses, or photos if not essential for their interaction.
- Scrutinize App Permissions: Exercise extreme caution when granting third-party apps access to contact data. Regularly review app permissions on mobile devices and revoke access for apps that do not genuinely require it for core functionality. The finding that over 90% of users had at least one app, and 1/3 had 10 or more, highlights this critical vulnerability.
- Advocate for E2E Encryption: Demand and prioritize DAP services that offer end-to-end encryption (E2E) for contact data. The research indicates that E2E is technically feasible, especially for users who primarily access their DAPs from a single device, and would significantly enhance data security at rest.
For Data Subjects (Non-Users of a Specific DAP Service):
- Awareness and Advocacy: While direct control is limited, data subjects should be aware that their PII might be stored and shared by others. Advocacy for stronger data protection rights and privacy-enhancing features in DAPs is crucial.
- "Right to be Forgotten" and Access: Push for mechanisms that allow individuals to query, access, correct, or delete their data stored in others' DAPs or by service providers. The research shows broad support for such rights (40-48% of respondents).
For DAP Service Providers (e.g., Google, Apple):
- Implement End-to-End Encryption: This is perhaps the most critical defensive measure. Given the sensitive nature of PII and the potential for profiling, E2E encryption should be a standard feature for all contact data synced to their servers.
- Develop Data Subject Dashboards: Create user-friendly dashboards that allow data subjects to view, correct, or request deletion of their PII stored by others or by the provider itself. This aligns with user preferences identified in Study 1.
- Rethink Consent Models: Move beyond a user-centric consent model to one that incorporates the rights and consent of data subjects. This might involve granular controls for DAP users on what data fields can be synced or shared, or even notifications to data subjects when their PII is added to a DAP.
- Increase Transparency: Clearly communicate how contact data is accessed, processed, and shared with third parties.
For Third-Party App Developers:
- Minimize Data Collection: Adhere to the principle of least privilege; only request access to contact data that is absolutely necessary for the app's core functionality.
- Justify Data Use: Be transparent with users about why contact data access is required and how it will be used. Avoid "utility-driven justifications" that overshadow collective privacy harms.
- Secure Data Handling: Implement robust security measures for any contact data collected, including encryption in transit and at rest, and strict access controls.
For Policymakers and Regulators:
- Address Interdependent Privacy: Current privacy regulations (e.g., GDPR, CCPA) primarily focus on the relationship between an individual and a data controller. New frameworks or interpretations are needed to explicitly address interdependent privacy, particularly for data subjects who are not direct users of a service.
- Mandate Data Subject Rights: Consider mandating rights for data subjects to control their PII stored in others' DAPs, including access, correction, and deletion.
- Regulate Third-Party Access: Implement stricter regulations on how third-party applications can access and utilize contact data from DAPs.
By adopting these defensive strategies across the ecosystem, the pervasive and often invisible privacy risks associated with digital address books can be significantly mitigated, moving towards a more secure and privacy-respecting digital environment.
Key Takeaways
- Interdependent Privacy is a Critical, Under-Explored Issue in DAPs: Digital address books are a prime example of interdependent privacy, where one person's privacy is compromised by others' actions, yet this area has been largely overlooked by researchers and service providers.
- Non-Users Are Highly Vulnerable: Individuals who do not use a particular DAP service have no control over their PII stored and processed by others, creating a significant privacy gap and an "overlooked group" in current privacy frameworks.
- Pervasive Third-Party App Access Poses Significant Risks: Over 90% of users grant at least one third-party app access to their DAPs, often for functional reasons, leading to widespread data sharing that can have collective privacy harms when aggregated.
- End-to-End Encryption is Feasible and Necessary: The prevalence of single-device DAP access (nearly 30% of users) makes end-to-end encryption a technically viable solution that would not disrupt most workflows, yet mainstream services largely fail to offer it.
- Strong Support for Data Subject Rights: A significant portion of users (40-48%) believes data subjects should have rights over their PII stored in others' DAPs, including the ability to view, correct, or delete information, indicating a societal readiness for a paradigm shift in DAP privacy.
- PII is Undervalued by Users: While privacy concerns exist, a notable percentage of users are willing to share their contact data, including that of others, for minimal financial incentives (as low as a few dollars), highlighting a disconnect between perceived risk and behavioral action.
About the Speaker(s)
Kavous Salehzadeh Niksirat is a researcher from the Max Planck Institute for Security and Privacy. His work, as presented in this talk, focuses on critical aspects of digital privacy, particularly in the context of interdependent data relationships. For this specific research, he collaborated with colleagues from the University of Lausanne, University of Zurich, and Masaryk University, bringing together expertise from multiple institutions to conduct a comprehensive user-centered analysis of privacy issues in digital address books. His presentation highlights a strong understanding of both user behavior and technical implications in the realm of personal data security.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Legitimate academic privacy research on an underexplored surface — interdependent privacy in contact books is a real and underappreciated problem, and the empirical work (900+ respondents, actual Google Contacts data via API) gives it credibility. But this is solidly in the 'could have been a paper' category: no novel attack, no exploit, no systemic surprise that reframes how defenders should operate tomorrow.
Heather Calloway (CISO) — WEAK
Solid academic privacy research that surfaces a real structural problem — interdependent data exposure in address books — but stops well short of the governance and operational implications that would make it matter to security leaders or regulators. The findings are credible; the bridge to anyone who can act on them is nearly absent.
→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)
All talks from 34th USENIX Security Symposium (USENIX Security '25)