Empirical Analysis and Privacy Implications in OAuth-based Single Sign-On Systems

Srivathsan G. Morkonda, S. Chiasson, P. V. Oorschot
{"title":"Empirical Analysis and Privacy Implications in OAuth-based Single Sign-On Systems","authors":"Srivathsan G. Morkonda, S. Chiasson, P. V. Oorschot","doi":"10.1145/3463676.3485600","DOIUrl":null,"url":null,"abstract":"Single sign-on authentication systems such as OAuth 2.0 are widely used in web services. They allow users to use accounts registered with major identity providers such as Google and Facebook to login to a wide variety of independent services (relying parties). These services can both identify users and access a subset of the user's data stored with the provider. We empirically investigate the end-user privacy implications of OAuth implementations by relying parties around the world. We collect data on the use of OAuth-based logins in the Alexa Top 500 sites per country for five countries. We categorize user data made available by four identity providers (Google, Facebook, Apple, and LinkedIn) and evaluate popular services accessing user data from the SSO platforms of these providers. Many services allow users to choose from multiple login options (with different identity providers). Our results reveal that services request different categories and amounts of personal data from different providers, often with at least one choice undeniably more privacy-intrusive. We find that privacy-friendly login choices tend to be listed last, suggesting a dark pattern favoring options that release more user data. These privacy choices (and their privacy implications) are highly invisible to users. Based on our analysis, we consider challenges (e.g., opposing goals of stakeholders) in addressing these concerns and discuss ideas for further exploration.","PeriodicalId":205601,"journal":{"name":"Proceedings of the 20th Workshop on Workshop on Privacy in the Electronic Society","volume":"30 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-11-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"10","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 20th Workshop on Workshop on Privacy in the Electronic Society","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3463676.3485600","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 10

Abstract

Single sign-on authentication systems such as OAuth 2.0 are widely used in web services. They allow users to use accounts registered with major identity providers such as Google and Facebook to login to a wide variety of independent services (relying parties). These services can both identify users and access a subset of the user's data stored with the provider. We empirically investigate the end-user privacy implications of OAuth implementations by relying parties around the world. We collect data on the use of OAuth-based logins in the Alexa Top 500 sites per country for five countries. We categorize user data made available by four identity providers (Google, Facebook, Apple, and LinkedIn) and evaluate popular services accessing user data from the SSO platforms of these providers. Many services allow users to choose from multiple login options (with different identity providers). Our results reveal that services request different categories and amounts of personal data from different providers, often with at least one choice undeniably more privacy-intrusive. We find that privacy-friendly login choices tend to be listed last, suggesting a dark pattern favoring options that release more user data. These privacy choices (and their privacy implications) are highly invisible to users. Based on our analysis, we consider challenges (e.g., opposing goals of stakeholders) in addressing these concerns and discuss ideas for further exploration.
基于oauth的单点登录系统的实证分析和隐私影响
像OAuth 2.0这样的单点登录认证系统在web服务中得到了广泛的应用。它们允许用户使用在b谷歌和Facebook等主要身份提供商注册的账户登录各种独立服务(依赖方)。这些服务既可以标识用户,也可以访问存储在提供程序中的用户数据子集。我们对世界各地依赖方的OAuth实现对最终用户隐私的影响进行了实证调查。我们收集了五个国家/地区Alexa 500强网站使用oauth登录的数据。我们对四个身份提供者(b谷歌、Facebook、Apple和LinkedIn)提供的用户数据进行了分类,并评估了从这些提供者的SSO平台访问用户数据的流行服务。许多服务允许用户从多个登录选项中进行选择(使用不同的身份提供者)。我们的研究结果表明,服务要求不同提供商提供不同类别和数量的个人数据,通常至少有一种选择无疑更具隐私侵犯性。我们发现,对隐私友好的登录选项往往排在最后,这表明一种暗模式倾向于释放更多用户数据的选项。这些隐私选择(及其隐私含义)对用户来说是高度不可见的。基于我们的分析,我们在处理这些问题时考虑挑战(例如,涉众的对立目标),并讨论进一步探索的想法。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信