A Study of the Multiple Sign-in Feature in Web Applications
Autor: | Jidong Xiao, Daiping Liu, Fengwei Zhang, Marwan Albahar, Xing Gao, Gaby G. Dagher |
---|---|
Rok vydání: | 2019 |
Předmět: |
050101 languages & linguistics
Web server Computer science business.industry 05 social sciences Usability Context (language use) 02 engineering and technology Login computer.software_genre Internet security User experience design Feature (computer vision) Human–computer interaction 0202 electrical engineering electronic engineering information engineering Web application 020201 artificial intelligence & image processing 0501 psychology and cognitive sciences business computer |
Zdroj: | Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering ISBN: 9783030372309 SecureComm (2) |
DOI: | 10.1007/978-3-030-37231-6_26 |
Popis: | Nowadays, more and more web applications start to offer the multiple sign-in feature, allowing users to sign into multiple accounts simultaneously from the same browser. This feature significantly improves user experience. Unfortunately, if such a feature is not designed and implemented properly, it could lead to security, privacy, or usability issues. In this paper, we perform the first comprehensive study of the multiple sign-in feature among various web applications, including Google, Dropbox. Our results show that the problem is quite worrisome. All analyzed products that provide the multiple sign-in feature either suffer from potential security/privacy threats or are sacrificing usability to some extent. We present all issues found in these applications, and analyze the root cause by identifying four different implementation models. Finally, based on our analysis results, we design a client-side proof-of-concept solution, called G-Remember, to mitigate these issues. Our experiments show that G-Remember can successfully provide adequate context information for web servers to recognize users’ intended accounts, and thus effectively address the presented multiple sign-in threat. |
Databáze: | OpenAIRE |
Externí odkaz: |