首页> 外文会议>International Conference on Contemporary Computing >All your Google and Facebook logins are belong to us: A case for single sign-off
【24h】

All your Google and Facebook logins are belong to us: A case for single sign-off

机译:您所有的Google和Facebook登录名都属于我们:单点登录的情况

获取原文

摘要

The websites of the modern Web integrate content from multiple parties to provide an enriched user experience. The so-called single sign-on forms part of this integration whereby a relying website enables a user to use her credentials on a third-party provider (such as Google or Facebook) to authenticate with itself and, if desired, authorize itself to use her resources on the provider. The user benefits by not remembering credentials for different websites separately and by allowing controlled use of her resources with a provider by other website. However, we observe that the current protocols for single sign-on do not have any provision of what we call single sign-off: once the user logs out of a relying website, the user still remains signed into the provider website. This can leave the user vulnerable if she forgets to sign out of the provider website after signing out of the relying website on a shared computer. We manually analyze the top twenty websites using Facebook or Google providers and conclude that the above problem is widespread. All but one website do not even warn the user with regard to this problem.
机译:现代Web的网站将来自多方的内容集成在一起,以提供丰富的用户体验。所谓的单点登录是此集成的一部分,依靠该网站,用户可以使用户使用其在第三方提供商(例如Google或Facebook)上的凭据进行身份验证,并在需要时授权其使用她在提供者上的资源。用户不会因为分别记住不同网站的凭据,而允许其他网站通过提供商控制地使用她的资源,从而从中受益。但是,我们注意到,当前的单点登录协议没有任何我们称为单点退出的规定:用户退出依赖网站后,用户仍保持登录提供者网站的状态。如果用户在共享计算机上退出依赖网站后忘记退出提供者网站,这可能会使用户容易受到攻击。我们使用Facebook或Google提供程序手动分析了排名前20位的网站,并得出上述问题普遍存在的结论。除一个网站外,所有网站甚至都未就此问题警告用户。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号