APRIL 25, 2023 — Is anything ever safe and secure in today’s digital age? A group of graduate students in the Carlos Alvarez College of Business at UTSA were surprised to discover security vulnerabilities in a location-sharing mobile application designed to promote family safety.
As part of a semester-long research study, Posie Aagaard, an information technology graduate student, alumnus Omar Abduljabbar ’22 and alumnus Bijan Dinyarian ’22 conducted a forensic analysis of Life360, a popular application among families that provides location tracking, notifications and emergency services.
What began as a project in a digital forensics class ultimately resulted in a published paper and a valuable learning experience. Their paper, “Family Locating Sharing App Forensics: Life360 as a Case Study,” was published in the Forensic Science International: Digital Investigation journal this year.
“I take an experiential learning approach to facilitate students’ learning experiences in my classes,” said Raymond Choo, Cloud Technology Endowed Professor in the UTSA Department of Information Systems and Cyber Security. “In my graduate digital forensics course, the students complete a semester-long, open-ended research assignment, which is designed to foster and promote student creativity and engagement.”
The first task for the research team was finding something they could be hands-on with, said Aagaard, who also serves as assistant vice provost for collections and curriculum support at the UTSA Libraries.
“Professor Choo suggested that mobile forensics is a growing field to explore,” Aagaard said. “We looked at several different apps, but we chose this one because one of our group members had a family member who used it and it has a huge adoption rate. We thought it could make an interesting case study. We didn’t go into the project expecting specific forensic findings, so when we got our results they really stood out.”
As part of their study, the students looked at two main areas: the artifacts that were left behind on devices from the app and the networking or transmission of data from the app. Utilizing a variety of industry tools they looked for data that users might not want publicly disclosed.
“We really wanted the data to tell us what we were going to find,” said Aagaard. “We learned the way that data could be compromised. And there was a little bit of irony or concern because this is an app that was designed to make people feel safe.”
One of their key findings was that having access to one person’s device makes everybody in their circle vulnerable because of the way the data is shared across these overlapping social circles. They also discovered multiple forensic artifacts that comprised significant amounts of personal data.
For paid users, additional data such as driving safety is collected. The students found that driving data is pushed to third-party providers, which the company discloses. Even if you aren’t a user of this app, a passenger in your car could collect driving data from you through their participation.
“Our goal wasn’t for people to stop using the app, but just to bring awareness,” said Aagaard. “The premise of the app is to be able to share your location with people. You don’t need to drag somebody down into the technical details, but there are certain things people can do that will give you a better outlook of the vulnerabilities that do exist.”
While this wasn’t Aagaard’s first publication, it was her first technical paper. Hoping to graduate with her master’s degree by the end of the year, she is a huge fan of the college’s cyber security program.
“The program is great. I love that it integrates academia, government and industry,” she said. “I really feel like we’ve got great experts teaching the classes and students who really like the field.”
A lesson Aagaard hopes consumers can take away from this project is that when people think data is gone, it really isn’t.
“Devices and applications are collecting a lot of data that users don’t know exists, she said. “And even if they know it exists and they think it is secured, someone with the technical knowledge and time has the ability to find it.”
UTSA Today is produced by University Communications and Marketing, the official news source of The University of Texas at San Antonio. Send your feedback to news@utsa.edu. Keep up-to-date on UTSA news by visiting UTSA Today. Connect with UTSA online at Facebook, Twitter, Youtube and Instagram.
UTS Bold Careers hosts Student Technology Council where students have the opportunity to share feedback about technology needs to the UTS Leadership. The Leadership will also provide updates as to the technolgy projects for the campus.
Mesquite Room (SU 2.01.24,) Student Union, Main CampusJoin us for a hands-on workshop about the basics of copyright, both in education and as a researcher. We’ll dispel some common copyright myths, differences between copyright law and other intellectual property law, and teach you how to apply a Fair Use checklist to your scholarly work.
Virtual Event (Zoom)In this workshop, we will explore sentiment analysis, a method for identifying feelings in text, whether the tone is positive, negative, or neutral.
Group Spot B, John Peace LibraryLearn to use the simple but powerful features of EndNote®, a citation management tool. In this hands-on workshop, participants will learn to setup an EndNote library, save references and PDFs, and automatically create and edit a bibliography.
Virtual Event ( Zoom)The Urban Bird Project at UTSA will discuss urban bird populations, conservation efforts, and how you can get involved.
JPL Assembly Room (4.04.22,) Main CampusThe DMPTool is a free online resource that helps researchers create data management plans. This workshop will cover the main components of DMPs and how to create them using the DMPTool. Attendees will learn to: locate templates by funding agency, add research collaborators, and identify institutional guidance.
Virtual Event (Zoom)Join UTSA Libraries and Museums to learn more about the publishing discounts available for UTSA researchers. Current agreements include Elsevier, Cambridge University Press, Wiley, and more. Bring your questions and feedback for the library as we continue to pursue partnerships with publishers to reduce costs for our researchers.
Virtual Event (Zoom)The University of Texas at San Antonio is dedicated to the advancement of knowledge through research and discovery, teaching and learning, community engagement and public service. As an institution of access and excellence, UTSA embraces multicultural traditions and serves as a center for intellectual and creative resources as well as a catalyst for socioeconomic development and the commercialization of intellectual property - for Texas, the nation and the world.
To be a premier public research university, providing access to educational excellence and preparing citizen leaders for the global environment.
We encourage an environment of dialogue and discovery, where integrity, excellence, respect, collaboration and innovation are fostered.