Longitudinal Analysis of the Third-party Authentication Landscape
At a glance
- Citations
- 1
- References
- 15
- Comments
- 0
Öz
Many modern websites offer single sign-on (SSO) services, which allow the user to use an existing account with a third-party website such as Facebook to authenticate. When using SSO the user must approve an app-rights agreement that specifies what data related to the user can be shared between the two websites and any actions (e.g., posting comments) that the origin website is allowed to perform on behalf of the user on the third-party provider (e.g., Facebook). Both cross-site data sharing and actions performed on behalf of the user can have significant privacy implications. In this paper we present a longitudinal study of the third-party authentication landscape, its structure, and the protocol usage, data sharing, and actions associated with individual third-party relationships. The study captures the current state, changes in the structure, protocol usage, and information leakage risks.
Publication details
- DOI
- 10.14722/ueop.2016.23008
- OpenAlex
- W2343126688
- Document type
- conference-paper
- Language
- EN
- Source
- DiVA (Linkoping University)
- Last metadata update
Comments
Oturum Açın to join the discussion.