Analysis of privacy vulnerabilities in single sign-on mechanisms for multimedia websites
Analysis of privacy vulnerabilities in single sign-on mechanisms for multimedia websites
复制标题
多媒体网站单点登录机制隐私漏洞分析
DOI:
--
复制
发表时间:
2012
影响因子:
3.6
通讯作者:
D. Larrabeiti
中科院分区:
文献类型:
--
作者:
M. Urueña;Alfonso Muñoz;D. Larrabeiti
This paper studies the privacy risks for the users of two popular single sign-on platforms for web-based content access: OpenID and Facebook Connect. In particular we describe in detail a privacy vulnerability of the OpenID Authentication Protocol that leads to the exposure of the OpenID user identifier to third parties. We illustrate how OpenID agents leak the (potentially unique) OpenID identifiers of their users to third parties, like advertisement and traffic analysis corporations. This vulnerability is a real and widespread privacy risk for OpenID users. This paper also analyzes the privacy of Facebook Connect --the proprietary single sign-on platform that is gaining a lot of popularity recently-- and, we conclude that it is not affected by the same vulnerability but other important privacy issues remain. Finally, this paper studies the solution space of these problems and defines a number of possible countermeasures. In the case of the OpenID vulnerability, we propose three solutions to this problem: one for the long term to avoid the root cause of the vulnerability, and another two short-term mitigations.