The Digital-Safety Risks of Financial Technologies for Survivors of Intimate Partner Violence

Rosanna Bellini, Kevin Lee, Megan A. Brown, Jeremy Shaffer, Rasika Bhalerao, Thomas Ristenpart

    Research output: Chapter in Book/Report/Conference proceedingConference contribution

    Abstract

    Digital technologies play a growing role in exacerbating financial abuse for survivors of intimate partner violence (IPV). While abusers of IPV rarely employ advanced technological attacks that go beyond interacting via standard user interfaces, scant research has examined how consumer-facing financial technologies can facilitate or obstruct IPV-related attacks on a survivor’s financial well-being. Through an audit of 13 mobile banking and 17 peer-to-peer payment smartphone applications and their associated usage policies, we simulated both close-range and remote attacks commonly used by IPV adversaries. We discover that mobile banking and peer-to-peer payment applications are generally ill-equipped to deal with user-interface bound (UI-bound) adversaries, permitting unauthorized access to logins, surreptitious surveillance, and, harassing messages and system prompts. To assess our discoveries, we interviewed 12 financial professionals who offer or oversee frontline services for vulnerable customers. While professionals expressed an interest in implementing mitigation strategies, they also highlight barriers to institutional approaches to intimate threats, and question professional responsibilities for digital safety. We conclude by providing recommendations for how digital financial service providers may better address UI-bound threats, and offer broader considerations for professional auditing and evaluation approaches to technology-facilitated abuse.

    Original languageEnglish (US)
    Title of host publication32nd USENIX Security Symposium, USENIX Security 2023
    PublisherUSENIX Association
    Pages87-104
    Number of pages18
    ISBN (Electronic)9781713879497
    StatePublished - 2023
    Event32nd USENIX Security Symposium, USENIX Security 2023 - Anaheim, United States
    Duration: Aug 9 2023Aug 11 2023

    Publication series

    Name32nd USENIX Security Symposium, USENIX Security 2023
    Volume1

    Conference

    Conference32nd USENIX Security Symposium, USENIX Security 2023
    Country/TerritoryUnited States
    CityAnaheim
    Period8/9/238/11/23

    ASJC Scopus subject areas

    • Computer Networks and Communications
    • Information Systems
    • Safety, Risk, Reliability and Quality

    Fingerprint

    Dive into the research topics of 'The Digital-Safety Risks of Financial Technologies for Survivors of Intimate Partner Violence'. Together they form a unique fingerprint.

    Cite this