Analysis of privacy vulnerabilities in single sign-on mechanisms for multimedia websites

Analysis of privacy vulnerabilities in single sign-on mechanisms for multimedia websites
复制标题

多媒体网站单点登录机制隐私漏洞分析

DOI:
--
复制
发表时间:
2012
影响因子:
3.6
通讯作者:
D. Larrabeiti
D. Larrabeiti
中科院分区:
计算机科学4区
文献类型:
--
作者:
M. Urueña;Alfonso Muñoz;D. Larrabeiti

文献摘要

被引文献

相似文献

本文研究了两个流行的基于Web的内容访问单点登录平台:OpenID和Facebook Connect的用户的隐私风险。特别是,我们详细描述了OpenID身份验证协议的隐私漏洞,导致OpenID用户标识符暴露给第三方。我们说明了如何OpenID代理泄漏(可能是唯一的)OpenID标识符的用户到第三方,如广告和流量分析公司。该漏洞对OpenID用户来说是一个真实的且广泛的隐私风险。本文还分析了Facebook Connect的隐私-最近越来越受欢迎的专有单点登录平台-我们得出结论,它不受相同漏洞的影响,但其他重要的隐私问题仍然存在。最后,本文研究了这些问题的解空间,并确定了一些可能的对策。在OpenID漏洞的情况下,我们提出了三个解决方案:一个是长期的,以避免漏洞的根本原因,另两个短期缓解。
This paper studies the privacy risks for the users of two popular single sign-on platforms for web-based content access: OpenID and Facebook Connect. In particular we describe in detail a privacy vulnerability of the OpenID Authentication Protocol that leads to the exposure of the OpenID user identifier to third parties. We illustrate how OpenID agents leak the (potentially unique) OpenID identifiers of their users to third parties, like advertisement and traffic analysis corporations. This vulnerability is a real and widespread privacy risk for OpenID users. This paper also analyzes the privacy of Facebook Connect --the proprietary single sign-on platform that is gaining a lot of popularity recently-- and, we conclude that it is not affected by the same vulnerability but other important privacy issues remain. Finally, this paper studies the solution space of these problems and defines a number of possible countermeasures. In the case of the OpenID vulnerability, we propose three solutions to this problem: one for the long term to avoid the root cause of the vulnerability, and another two short-term mitigations.