首页> 外文会议>International Information Security Conference >Sudo Web: Minimizing Information Disclosure to Third Parties in Single Sign-on Platforms
【24h】

Sudo Web: Minimizing Information Disclosure to Third Parties in Single Sign-on Platforms

机译:sudo web:在单一登录平台中最大限度地减少对第三方的信息披露

获取原文

摘要

Over the past few months we are seeing a large and ever increasing number of Web sites encouraging users to log in with their Facebook, Twitter, or Gmail identity, or personalize their browsing experience through a set of plug-ins that interact with the users' social profile. Research results suggest that more than two million Web sites have already adopted Facebook's social plug-ins, and the number is increasing sharply. Although one might theoretically refrain from such single sign-on platforms and cross-site interactions, usage statistics show that more than 250 million people might not fully realize the privacy implications of opting-in. To make matters worse, certain Web sites do not offer even the minimum of their functionality unless the users meet their demands for information and social interaction. At the same time, in a large number of cases, it is unclear why these sites require all that personal information for their purposes. In this paper we mitigate this problem by designing and developing a framework for minimum information disclosure across third-party sites with single sign-on interactions. Our example case is Facebook, which combines a very popular single sign-on platform with information-rich social networking profiles. When a user wants to browse a Web site that requires authentication or social interaction with his Facebook identity, our system employs, by default, a Facebook session that reveals the minimum amount of information necessary. The user has the option to explicitly elevate that Facebook session in a manner that reveals more or all of the information tied to his social identity. This enables users to disclose the minimum possible amount of personal information during their browsing experience on third-party Web sites.
机译:在过去的几个月里,我们看到一个大量的网站,鼓励用户使用他们的Facebook,Twitter或Gmail身份登录,或者通过与用户互动的一组插件来个性化他们的浏览体验社交概况。研究结果表明,超过200万网站已经采用Facebook的社交插件,而且数字急剧增加。虽然人们可能理论上避免了这样的单一登录平台和跨场互动,但使用统计数据显示,超过2.5亿人可能无法完全实现开放的隐私含义。为了使事情更糟糕,除非用户满足他们对信息和社会互动的要求,否则某些网站甚至不提供它们的最低功能。与此同时,在大量的情况下,目前还没有明确为什么这些网站需要所有这些个人信息的目的。在本文中,我们通过在具有单一登录交互的第三方网站上设计和开发最小信息披露的框架来减轻这个问题。我们的示例案例是Facebook,它结合了一个非常流行的单点登录平台,具有丰富的信息丰富的社交网络配置文件。当用户想要浏览需要与他的Facebook身份进行身份验证或社交互动的网站时,我们的系统默认使用Facebook会话,该会话揭示了所需的最短信息量。用户可以选择以揭示与他的社会身份相关的更多或所有信息的方式明确提升Facebook会话。这使用户能够在第三方网站上浏览体验期间披露最低可能的个人信息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号