<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>End-user license agreement - threat to information security: a real life experiment</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Žygimantas Kaupas</string-name>
          <email>zygimantas.kaupas@ktu.edu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Faculty of Informatics Kaunas University of Technology Kaunas</institution>
          ,
          <country country="LT">Lithuania</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Jonas Čeponis</institution>
        </aff>
      </contrib-group>
      <fpage>55</fpage>
      <lpage>60</lpage>
      <abstract>
        <p>-This paper analyses end-user license agreement (EULA) and its impact on security of information and information technologies. Popular opinion suggests that people tend to accept EULA legal statements without good understanding of potential impact on their confidential data. To have a clear picture about current situation, real life experiment with specifically created license text was conducted. The results reveal serious information security flaws.</p>
      </abstract>
      <kwd-group>
        <kwd>end-user license agreement</kwd>
        <kwd>EULA</kwd>
        <kwd>acceptance without reading</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>INTRODUCTION</p>
      <p>As more and more data is stored online and the number of
internet users is constantly increasing, creators of malicious
software are persistently looking for some innovative ways to
acquire valuable confidential information.</p>
      <p>When recent malware, spyware, ransomware and other
digital attacks were disclosed publicly and attracted a lot of
attention [1], common trust in online information decreased
notably. It is a commendable general practice to use an
antivirus solution, do not open suspicious links or give your
confidential data to an untrusted source. However, one attack
vector is often forgotten.</p>
      <p>Digital world is no longer imaginable without countless
number of various software. Almost all of it asks the user to
accept the end-user license agreement (EULA) before the start
of an installation process. Following part is frequently
overlooked by most of the users, even though real security
threats might be hidden there.</p>
      <p>This work analyses the concept of EULA and its
drawbacks. Users trust in the information found online is tested
with a software, which is made for this experiment and has a
specifically designed EULA text. Obtained results enable
identification of the problem scope and propose actions, which
could help in closing this security gap.</p>
      <p>II.</p>
    </sec>
    <sec id="sec-2">
      <title>END-USER LICENSE AGREEMENT ANALYSIS</title>
      <p>End-user license agreement is a legal contract between a
software application author or publisher and the user of that
application [2]. This document should be used for protecting
software creators from copyright infringements and liabilities
when something goes wrong because of the mistakes in their</p>
    </sec>
    <sec id="sec-3">
      <title>Copyright © 2017 held by the authors 55</title>
      <p> by clicking on “I agree” button during the software
installation;
 by opening the shrink wrap on the package;
 by breaking the seal on the case;
 by sending a special card back to the software
publisher;
 by executing a downloaded file (applicable more to</p>
      <p>UNIX systems);
 by using the software.</p>
      <p>Users trust in the information found online will be tested
with the first of the above-mentioned methods, since it is the
most common one used in practice nowadays.</p>
      <p>From the acceptance methods list it is already obvious that
notifying the user about EULA terms is the least important
objective for the software developers. Even more, this
drawback is only the first one of many criticism objects related
to this document.</p>
      <p>
        One of the most criticized aspects of EULA is its length [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
On average, it reaches 3000 words (11 pages with double
spacing), but on some cases this number is more than 10 times
bigger (in 2012 PayPal EULA contained 36 275 words [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]).
Unfortunately, there is no data available how many (if any)
users read these documents at all.
      </p>
      <p>In addition, difficult legal terminology is always used in
EULA language. This significantly decreases documents’
readability and contradicts the main idea, that all people should
be able to read and understand it. Also, terms that may be
harmful to user system or information confidentiality can be
well hidden among those legal phrases.</p>
      <sec id="sec-3-1">
        <title>B. Common Harmful EULA Terms</title>
        <p>
          Even well-known companies use EULA for specific
purposes. User monitoring is very often mentioned in this
document. For example, in order to have a fully functional user
assistant Cortana in Microsoft Windows 10 operating system,
agreement on user data (installed programs, browsing history,
etc.) collection by default is included into EULA. These
settings can be disabled later, but that would cost some time,
knowledge and effort for the end user [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ].
        </p>
        <p>
          Facebook on the other hand claims that it can use any
digital content posted by its users for any companies’
objectives as long as this media is not deleted from the website.
Users’ photos or videos could be included in an advertising
material without any official notifications [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ].
        </p>
        <p>
          The restriction to criticize the software or compare it with
similar products can be also found in EULA text. Even though
in 2003 global computer security company McAfee was
penalized for forbidding benchmark publications in such way,
today well-known software products like Microsoft SQL
Server or VMware Workstation still use similar restrictions in
their EULA [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ]. It is obvious that some terms are so desirable,
that even financial punishment does not frighten software
creators.
        </p>
        <p>
          Finally, some IT giants like Microsoft or Google granted
themselves the right to change users operating system state
(uninstall programs, change settings, etc.) based on EULA.
Officially this could be easily explained as a basic user
protection; however, it does not exclude a possibility to delete
some unwanted software or change required settings without
any warning or justifying cause. Furthermore, Google allows
itself to change EULA without a warning at any time. The
underlying presumption is that user will check the latest
version of this document from time to time [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ]. Even though
authors do not think that these well-known companies would
risk their good name to exploit terms mentioned above, but
there are number of those, who certainly would.
        </p>
      </sec>
      <sec id="sec-3-2">
        <title>C. Legal EULA Analysis</title>
        <p>There are many discussions online where EULA’s legal
obligations are debated. Usually people tend to think that this
document is like an informational message or standard
instruction, despite its usual start with the words “important
legal agreement”. Situation is even more complicated in
Lithuania, since there are no judicial practices related to this
question and even the EULA document itself most of the time
is written in English language.</p>
        <p>
          The Republic of Lithuania Law on Electronic
Communications states that it is forbidden to gather any digital
confidential information except when the user is informed and
gave his agreement [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]. Similar principles are echoed in other
legal documents about access to personal data. EULA perfectly
fits the aforementioned principle – inform and receive a
consent.
        </p>
        <p>
          Situation in European Union is very similar to Lithuania’s –
there is still a shortage of court decisions related to the
discussed document. According to E-commerce directive [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ],
each member state could exclude electronic agreement from
binding documents list. However, as of 2011, none has selected
this option and no information is present that it is chosen by
anyone today [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ].
        </p>
        <p>
          Finally, even birthplace of EULA – USA – has no common
verdict regarding legal obligations of this document. Related
judgements are always made ad hoc. However, statistics are in
favor of EULA and some widely-publicized trials ended in
supporting this document and thus strengthened its legal power
even more [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ].
        </p>
      </sec>
      <sec id="sec-3-3">
        <title>D. EULA’s research and known solutions.</title>
        <p>There is not a lot of academic attention to this document
neither in Lithuania nor in the world. No published research
could be found in Lithuanian language where EULA is the
main analysis object. This document is seldom mentioned only
in the context of intellectual property protection, but nowhere
the potential threat of the software license agreement to
confidential information or IT infrastructure is discussed.</p>
        <p>
          Somewhat more research was done regarding the user
familiarity with EULA text (before accepting it) worldwide.
One of the most famous and extensive experiments was made
in 2010 by Rainer Böhme and Stefan Köpsell [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ]. They
evaluated 80 000 respondents and concluded that less than 8%
of them spent enough time to read the presented EULA text
before clicking the accept button.
        </p>
        <p>
          Other experiments gave similar results. In 2005 antivirus
company PC Pitstop included information about the 1000$
prize in their EULA text. It was granted to the first responder
who will write them a letter about it. The winner showed up
only after 4 months and 3000 downloads [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ]. Similar results
occurred when cyber security solutions company F-Secure
decided to do a Wi-Fi experiment and gave free public access
to a specific hotspot only if the user agreed to give away his
firstborn child [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ]. In only 30 minutes 33 connections were
made and there were no complaints about that tricky clause
whatsoever.
        </p>
        <p>
          On the other hand, there are just a few solutions to evaluate
and automatically guard yourself against potential threats
written in EULA. In the middle of 2012 the project called
“Terms of Service; Didn't Read” started with a lot of public
attention [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ]. It rated and labeled websites terms &amp; privacy
policies into five groups and specified pros and cons from their
agreements. Sadly, the last entry is dated July 2014 and it
appears as the project is no longer active. Similar situation is
with an application that automatically analyses EULA –
“EULAlyzer” [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ]. Though this program is still the best
solution at the moment, it is also no longer developed and left
with very limited functionality.
        </p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>EXPERIMENT OF USERS TRUST IN THE EULA</title>
      <sec id="sec-4-1">
        <title>A. Research environment and collected data</title>
        <p>This experiment was performed at the end of 2016. 653
first year students of Informatics faculty of Kaunas University
of Technology were selected for this investigation. The defined
scope helped in achieving several goals:
 to have a limited and known respondents number;
 to make sure that users do have greater than minimum
computer literacy skills;
 to analyze the behavior of users which have a
motivation to participate.</p>
        <p>Experiment was carried out in the form of knowledge
testing application for a specific university course. Students
received a link to the downloadable application Quizza via an
email from the course lecturer. It was specifically stated that
this program is a personal project with potential programming
errors. If the student answered more than 50% of test questions
correctly, he received a link to the bonus material. No other
information about the experiment was given in the email text.
Even though the email sender in this case was not fake (in
reallife phishing scenarios attacker tries to mimic the valid source),
publication method and the fact that Quizza program was
presented only once (no references were made during live
lectures) should have raised at least some mistrust.</p>
        <p>When user wanted to install the testing application on either
Windows operating system machine or Android mobile device,
it prompted the EULA to be accepted otherwise installation
will be canceled. Every step of this experiment was made to
replicate real world scenario as close as possible.</p>
        <p>If users accepted the specifically modified EULA
document, the installed software not only performed expected
and visible functions, but also collected and sent some data
from the machine it was running in. Actions with personal data
are very restrictive and in most cases need various user
approvals even for research purposes, therefore only a limited
set of parameters for data collecting was chosen, which
demonstrated access possibilities and security risks, but did not
allow the exact person identification. This set included number
of attached memory devices (hard drive, USB, CD/DVD),
letter assigned to each drive (in Windows operating system)
and the amount of free/occupied space. For the software to
access these parameters it needs to have high privileges in the
system. In comparison, it would be impossible to get this
information by using a malicious web application.</p>
      </sec>
      <sec id="sec-4-2">
        <title>B. Design of special EULA</title>
        <p>
          Specific EULA text was developed for this experiment.
Antivirus software Kaspersky license agreement was selected
as a base model [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ]. One difference from the standard EULA
sample was that this time the document was written in
Lithuanian language. Such modification made the EULA
compliant to the country’s law. It also helped evaluating
whether the language does any difference to the readability of
EULA and if that raises some questions for end users, why an
unknown simple application would bother to use native
language in its license agreement.
        </p>
        <p>Other details were selected according to the standard
license agreement: length of 3000 words, difficult legal
language, liability limitations of software developer, etc.
Several specific statements were created to trigger reader’s
attention and placed in the middle of EULA document text.</p>
        <p>The first statement was labeled “Technical assistance” and
had an active link to the application’s support page. When
visiting it, user could get an access to the desired bonus content
without installing malicious application. Users who entered this
page during the experiment and downloaded resources from it,
were categorized as those who have read the EULA.</p>
        <p>
          The next specific statement was a mixture of indications
that this document is not a standard sample. One piece stated
that “user data will be sent to the developer to have a better
application security” (without any detailed explanation why or
what exactly will be shared). Another part was a reference to
the Republic of Lithuania Law On Legal Protection Of
Personal Data [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ] and data collection for scientific reasons.
Finally, the last statement advised to cancel the installation and
visit technical assistance page if the user does not agree with
the license text.
        </p>
      </sec>
      <sec id="sec-4-3">
        <title>C. Applications for Windows and Android operating systems</title>
        <p>
          Two environment options were presented for the users in
the experiment: Windows .msi or Android .apk installer files of
a Quizza application. Both operating systems are the most
popular in their domain with highest usage count [
          <xref ref-type="bibr" rid="ref21">21</xref>
          ].
        </p>
        <p>In the Windows environment EULA usually has an
additional dialog window where “Next” or “I agree” button has
to be pressed in order to proceed. One common safeguard was
added in our experiment to stop the user from automatically
pressing the same button (usually “Next”) throughout all
installation process: additional agreement checkbox had to be
selected before continuing to the next step.</p>
        <p>The unsophisticated testing environment would be loaded
afterwards, where users have to answer five out of ten
questions correctly in order to get the desired extra content.
Experimental application for devices running Windows was
developed using Java programming language. It is a very
lightweight solution where minimal code complexity is added
only because of GUI (JavaFX package was used for its
development). During the test user received a random question
from a .txt file where the list of 30+ of them is present. Final
score was counted after 10 questions. If minimal amount of 5
points is not reached, user can retry the attempt with another
random set of questions.</p>
        <p>In parallel to this activity, Quizza application used standard
Java libraries to collect information about memory devices and
third party email client Gmail to send data to the mailbox
prepared for this experiment. None of the existing user’s
accounts were used for this process – the mail address of the
sender was also created for this project and hardcoded into the
application.</p>
        <p>From the architectural point of view, two classes in
application were separate and not connected to the quiz type
functionality. SpaceIO class had 4 variables (driveLetter,
driveType, driveTotalSpace and driveFreeSpace) and
calculateSpace() method. If the method succeeded without any
exceptions, all these 4 parameters were passed to Email class
and sendEmail() method was invoked.</p>
        <p>This class had several variables already hardcoded, like
username, password, recipient, port, host, etc. Such solution
enables keeping all code execution within an application. No
calls to other programs or services are required. From this short
description is obvious that experimental application is very
simple and could be created by anyone having even limited
programming skills. Still even this is enough to gather
important data or invoke malicious code inside another user
system.</p>
        <p>Android application did not have any major differences
neither with respect to functionality, nor related to hidden
processes. Its Application Programming Interface (API)
enables accessing many system parameters, however to do so it
asks the user to grand rights in a special “App permissions”
dialog before installing the application. During the testing stage
it was noticed that Android version is more stable and reliable
because mobile devices usually do not have any antivirus or
other security software, which could block the outbound traffic.</p>
        <p>Compared to Windows version, Android Quizza
application is even less complicated, because GUI and part of
system resources could be manipulated directly. In the Android
environment it is easy to track whether the user has already
accepted the EULA for a specific program version even after it
is reinstalled many times in the same system. This enables the
reduction of the amount of data being sent to the “attacker” and
removes all possibilities of information duplication.</p>
        <p>On one hand, there are almost no obstacles for malicious
processes to perform hidden actions once the program is
installed in the Android device. On the other hand, special
permission window is displayed to the user before successful
application installation. If the user pays attention to this dialog
and has an idea how the program should work, any
unnecessary privileges included in the list would certainly
cause suspicion. This might result in user terminating the
process before the attacker gathers any valuable data from that
device.</p>
      </sec>
      <sec id="sec-4-4">
        <title>D. Distribution environment of created programs</title>
        <p>For the successful experiment, one needs to have not only
prepared applications, but also the way to share them without
causing any doubt about their legitimacy. Having this in mind,
a bogus website quizza.tk was created. Only free services were
used for its creation: .tk domain name and free Lithuanian
hosting provider. Similar approach would allow an attacker to
make a number of identical copies/alternatives of the
distribution environment without spending a cent. In addition,
during the registration for these services no real personal
information was entered and no trackable financial payments
were made thus allowing the real owner to stay hidden.</p>
        <p>Main quizza.tk page during the whole experiment displayed
notification “Site under maintenance. We’ll be back soon”.
This fraud was applied in order to save time needed for a
detailed website creation herewith creating a false expectation
that such page really exists. In addition, it removed the
possibility of navigation inside the page, which was needed to
monitor how many students visited one or another link
(prevented browsing through all the resources at once).</p>
        <p>Furthermore, information about applications and website
was sent from the mailbox of course instructor to all students.
In our case, the sender was not falsified, but nowadays it is
quite straightforward to alter this data and present it as coming
from non-related legit source. Multiple links (separate for
Windows and Android applications) were included in the email
message. In practice, such method (well know source and some
references to additional material) is commonly used for fraud
purposes.</p>
        <p>All links had a server side PHP script, which monitored
how many times each of these references were clicked by the
user. Three counters were set-up for each application to have
versatile results of the experiment: how many times it was
downloaded, how many people read the EULA and visited the
“technical assistance page”, how many students agreed with
the license, solved the test and downloaded bonus content
afterwards.</p>
        <p>IV.</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>RESULTS OF THE EXPERIMENT From the initial email with details about these programs until the disclosure of the experiment two weeks were given for students.</title>
      <p>As it is observable from Table I, more than a half of
downloads ended up with application being installed and test
passed. However, this statistic does not mean that similar
number of students read the EULA and reached extra content
via different link. Alternative route has not been visited at all,
so EULA has not been read even once. What is more, almost
80% of those who passed the test shared their system data
unknowingly.</p>
      <p>Biggest interest in experimental application was during the
next day after the announcement – data about 62 devices (60%
from total amount) was received. As it was expected, not only
hard drives, but also USB devices and CDs/DVDs were
monitored. Even though during the testing stage, some
antivirus solutions proved that they would stop “malicious”
traffic from leaving user computer, other ones did the opposite.
For example, specific Avast versions even inserted additional
text to the email that was sent without user awareness –
“--This email has been checked for viruses by Avast antivirus
software. https://www.avast.com/antivirus”. Even after
experiment disclosure was made, 13 students used the
application and thus shared their data to the author (1 from
those even after 1.5 month from that date). It looks like people
still trust the program despite knowing that it did things with
their machine without their awareness.</p>
      <p>Result of Android application experiment are presented in
Table II. In general they are very similar to Windows version,
however even less students who downloaded the application
bothered to finish the test with required result (probably they
wanted just to see the application’s appearance, expected to get
different practice questions or just installed it on multiple
various devices). Surprisingly that even though there are
usually no security solutions in the mobile environment, 10%
less (70% on Android compared to 80% on Windows) data was
successfully gathered from this malicious application. Overall,
none of the students bothered to read the EULA and check the
link included in its text.</p>
      <p>In conclusion, the conducted experiment confirmed that
users tend to skip the EULA and agree with any text written in
it. The expected R/D ratio of 1/2 was not reached as nobody
accessed the alternative link in license agreement text thus
setting this ratio to the lowest minimum - 0.</p>
      <p>Since this agreement is a legal document, all included terms
must meet strict law regulations. However, even official
applications could collect considerable amount of confidential
data or track user behavior without breaking any laws.</p>
      <p>In addition, this experiment showed more alarming IT
security trends. First of all, if the attacker manages to trick the
user with the initial source validity, other steps to the complete
control over his system might be very easy. More than 60% of
data received came within the first 24 hours from the start of
the experiment. This tendency favors zero-day exploits or new
fraud schemas and as it was visible no home antivirus solutions
provide sufficient protection against data theft.</p>
      <p>Furthermore, received data disclosed that home users do
not benefit by virtualization technology to increase their
systems security. During the experiment malicious application
has monitored hard drives with plenty of storage accessible.
Also, in many instances connected external USB flash drives
were detected when user installed this untrusted application.
That could be easily used for further spread of the malware.
Finally, data from 17 new devices was received after the
disclosure of this experiment. It shows that either information
does not reach all parties even in a relatively small group or
some people still use digital resources after their malicious
behavior (potentially only one of many) is known.</p>
      <p>There are lots of security solutions from the simplest free
versions to expensive professional programs, yet it seems that
lessons from 5 thousand years’ legend about Trojan Horse are
still not learned. Why bother breaking down multiple security
layers if the user himself will take you inside?
http://eur</p>
      <p>Available:
Read”. Available: https://tosdr.org/</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <string-name>
            <given-names>M.</given-names>
            <surname>Ward</surname>
          </string-name>
          , “
          <article-title>'Alarming' rise in ransomware tracked”</article-title>
          . Available: http://www.bbc.com/news/technology-36459022
          <source>[Accessed: 22 February</source>
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <given-names>M.</given-names>
            <surname>Rouse</surname>
          </string-name>
          , “
          <article-title>End User License Agreement (EULA)”</article-title>
          . Available: http://searchcio.techtarget.com/definition/End-User
          <source>-License-Agreement [Accessed: 21 February</source>
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>J.</given-names>
            <surname>Newman</surname>
          </string-name>
          , “Top EULA Gotchas:
          <article-title>Website Fine-Print Hall of Shame”</article-title>
          . Available: http://www.pcworld.com/article/249396/top_eula_gotchas_website_fine _print_hall_of_shame.
          <source>html [Accessed: 22 February</source>
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>R. W.</given-names>
            <surname>Gomulkiewicz</surname>
          </string-name>
          , “
          <article-title>Getting Serious about User-Friendly Mass Market Licensing for Software” George Mason Law Review</article-title>
          , vol.
          <volume>12</volume>
          , pp.
          <fpage>687</fpage>
          -
          <lpage>718</lpage>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>S.</given-names>
            <surname>Jary</surname>
          </string-name>
          , “Apple iTunes
          <string-name>
            <surname>T</surname>
          </string-name>
          &amp;
          <article-title>Cs 10% longer than Shakespeare's Macbeth”</article-title>
          . Available: http://www.pcadvisor.co.uk/feature/apple/apple-itunes-tcs10
          <string-name>
            <surname>-</surname>
          </string-name>
          longer
          <string-name>
            <surname>-</surname>
          </string-name>
          than
          <string-name>
            <surname>-</surname>
          </string-name>
          shakespeares-macbeth-
          <volume>3346281</volume>
          / [Accessed: 22
          <source>February</source>
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>D.</given-names>
            <surname>Goldman</surname>
          </string-name>
          , “
          <article-title>Is Windows 10 really a privacy nightmare?</article-title>
          ” Available: http://money.cnn.com/
          <year>2015</year>
          /08/17/technology/windows-10-privacy/ [Accessed: 22
          <source>February</source>
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          <article-title>[7] Facebook Statement of Rights and Responsibilities</article-title>
          . Available: https://www.facebook.com/legal/terms [Accessed: 22
          <source>February</source>
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>A.</given-names>
            <surname>Newitz</surname>
          </string-name>
          , “
          <article-title>Dangerous Terms: A User's Guide to EULAs”</article-title>
          . Available: https://www.eff.org/wp/dangerous-terms
          <article-title>-users-guide-eulas [</article-title>
          <source>Accessed: 22 February</source>
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>Google</given-names>
            <surname>Chrome Terms</surname>
          </string-name>
          of Service. Available: https://www.google.lt/intl/eng/chrome/browser/privacy/eula_text.
          <source>html [Accessed: 22 February</source>
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <article-title>The Republic of Lithuania Law on Electronic Communications</article-title>
          . Available: https://www.e-tar.lt/portal/en/legalAct/TAR.82D8168D3049
          <source>[Accessed: 21 February</source>
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <article-title>Directive on electronic commerce</article-title>
          . Available: lex.europa.eu/legal-content/en/ALL/?uri=
          <source>CELEX:32000L0031 [Accessed: 21 February</source>
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>M.</given-names>
            <surname>Webber</surname>
          </string-name>
          , L. Rubin, “
          <article-title>Liability matters under end user licence agreements”</article-title>
          .
          <source>E-Commerce Law and Policy</source>
          , vol.
          <volume>13</volume>
          (
          <issue>4</issue>
          ),
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>N.</given-names>
            <surname>Anderson</surname>
          </string-name>
          , “No,
          <article-title>you don't own it: Court upholds EULAs, threatens digital resale”</article-title>
          . Available: https://arstechnica.com/techpolicy/2010/09/the-end
          <article-title>-of-used-major-ruling-upholds-tough-softwarelicenses/ [</article-title>
          <source>Accessed: 22 February</source>
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>R.</given-names>
            <surname>Böhme</surname>
          </string-name>
          , S. Köpsell, “
          <article-title>Trained to accept?: a field experiment on consent dialogs”</article-title>
          <source>CHI '10 Proceedings of the SIGCHI Conference on Human Factors in Computing Systems</source>
          , pp.
          <fpage>2403</fpage>
          -
          <lpage>2406</lpage>
          ,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <article-title>“It Pays To Read License Agreements (7 Years Later)”</article-title>
          . Available: http://techtalk.pcpitstop.com/
          <year>2012</year>
          /06/12/it-pays-to-read-licenseagreements-7
          <string-name>
            <surname>-</surname>
          </string-name>
          years-later/ [Accessed: 21
          <source>February</source>
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16] “Tainted Love:
          <article-title>How Wi-fi betrays us”</article-title>
          . https://fsecureconsumer.files.wordpress.com/
          <year>2014</year>
          /09/wi-fiexperiment
          <source>_uk_2014.pdf [Accessed: 21 February</source>
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          <source>[17] “Terms of Service; Didn't [Accessed: 22 February</source>
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18] “EULAnalyzer”. Available: https://www.brightfort.com/eulalyzer.
          <source>html [Accessed: 21 February</source>
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Kaspersky</surname>
            <given-names>EULA</given-names>
          </string-name>
          . Available: http://www.kaspersky24.lt/kis/Licence%20agreement%
          <fpage>20LT</fpage>
          .
          <source>pdf [Accessed: 22 February</source>
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <article-title>Republic of Lithuania Law on Legal Protection of Personal Data</article-title>
          . Available: https://www.e-tar.lt/portal/lt/legalAct/TAR.5368B592234C
          <source>[Accessed: 22 February</source>
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <article-title>“Operating System Market Share Worldwide”</article-title>
          . Available: http://gs.statcounter.com/os-market-share
          <source>[Accessed: 22 February</source>
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>