When Push Comes to Shove: Empirical Analysis of Web Push Implementations in the Wild

When Push Comes to Shove: Empirical Analysis of Web Push Implementations in the Wild
复制标题

DOI:
10.1145/3627106.3627186
复制
发表时间:
2023-12
期刊:
Proceedings of the 39th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Alberto Carboneri;Mohammad Ghasemisharif;Soroush Karami;Jason Polakis
Alberto Carboneri;Mohammad Ghasemisharif;Soroush Karami;Jason Polakis
中科院分区:
其他
文献类型:
--
作者:
Alberto Carboneri;Mohammad Ghasemisharif;Soroush Karami;Jason Polakis

文献摘要

相似文献

Web推送通知正在成为现代Web应用程序越来越普遍的功能,旨在创建与用户的直接通信管道并提高用户参与度。推送通知看似简单的功能掩盖了底层设计和实现的复杂性,这偏离了Web生态系统中近乎普遍的实践:在成功完成身份验证过程后,从几乎任何浏览器或设备访问帐户(以及相关功能)的能力。相反,推送通知为特定的浏览器实例创建一个通信端点。因此,部署推送通知的挑战由于web应用和用户浏览行为的其他方面(例如,多设备环境、帐户和会话管理)。在本文中,我们对推送通知的实现进行了实证分析,并确定了常见的部署陷阱。我们还展示了一系列针对推送通知功能的攻击,包括一种新颖的订阅嗅探攻击,通过选择用例。为了更好地了解推送通知实施的当前实践,我们对其部署进行了大规模测量,并提供了第一个,据我们所知,探索和分析第三方服务提供商。最后,我们为开发人员提供了指导方针,并提出了一种在多浏览器,后认证设置中正确处理推送通知的方法。
Web push notifications are becoming an increasingly prevalent capability of modern web apps, intended to create a direct communication pipeline with users and increase user engagement. The seemingly straightforward functionality of push notifications obscures the complexities of the underlying design and implementation, which deviates from a near-universal practice in the web ecosystem: the ability to access an account (and the associated functionality) from practically any browser or device upon successful completion of the authentication process. Instead, push notifications create a communication endpoint for a specific browser instance. As a result, the challenges of deploying push notifications are further exacerbated due to the integration obstacles that arise from other aspects of web apps and user browsing behaviors (e.g., multi-device environments, account and session management). In this paper, we conduct an empirical analysis of push notification implementations in the wild, and identify common deployment pitfalls. We also demonstrate a series of attacks that target push notification functionality, including a novel subscription-sniffing attack, through a selection of use cases. To better understand current practices in push notifications implementations, we present a large-scale measurement of their deployment and also provide the first, to our knowledge, exploration and analysis of third-party service providers. Finally, we provide guidelines for developers and propose an approach for correctly handling push notifications in multi-browser, post-authentication settings.