conference-paper Open access

Longitudinal Analysis of the Third-party Authentication Landscape

  • DiVA (Linkoping University)
Research footprint

At a glance

Citations
1
References
15
Comments
0
Paper overview

Öz

Many modern websites offer single sign-on (SSO) services, which allow the user to use an existing account with a third-party website such as Facebook to authenticate. When using SSO the user must approve an app-rights agreement that specifies what data related to the user can be shared between the two websites and any actions (e.g., posting comments) that the origin website is allowed to perform on behalf of the user on the third-party provider (e.g., Facebook). Both cross-site data sharing and actions performed on behalf of the user can have significant privacy implications. In this paper we present a longitudinal study of the third-party authentication landscape, its structure, and the protocol usage, data sharing, and actions associated with individual third-party relationships. The study captures the current state, changes in the structure, protocol usage, and information leakage risks.

Record transparency

Publication details

DOI
10.14722/ueop.2016.23008
OpenAlex
W2343126688
Document type
conference-paper
Language
EN
Source
DiVA (Linkoping University)
Last metadata update
Community

Comments

Oturum Açın to join the discussion.

  1. No comments yet. Start the discussion.