Hazhirpasand, Mohammadreza; Ghafari, Mohammad; Nierstrasz, Oscar (April 2020). Tricking Johnny into Granting Web Permissions. In: Evaluation and Assessment in Software Engineering, EASE 2020. EASE 2020 (pp. 276-281). New York, NY, USA: Association for Computing Machinery 10.1145/3383219.3383248
Text
Hazh20b.pdf - Published Version Restricted to registered users only Available under License Publisher holds Copyright. Download (1MB) |
We studied the web permission API dialog box in popular mobile and desktop browsers, and found that it typically lacks measures to protect users from unwittingly granting web permission when clicking too fast. We developed a game that exploits this issue, and tricks users into granting webcam permission. We conducted three experiments, each with 40 different participants, on both desktop and mobile browsers. The results indicate that in the absence of a prevention mechanism, we achieve a considerably high success rate in tricking 95% and 72% of participants on mobile and desktop browsers, respectively. Interestingly, we also tricked 47% of participants on a desktop browser where a prevention mechanism exists.
Item Type: |
Conference or Workshop Item (Paper) |
---|---|
Division/Institute: |
08 Faculty of Science > Institute of Computer Science (INF) 08 Faculty of Science > Institute of Computer Science (INF) > Software Composition Group (SCG) [discontinued] |
UniBE Contributor: |
Hazhirpasand Barkadehi, Mohammadreza, Ghafari, Mohammad, Nierstrasz, Oscar |
Subjects: |
000 Computer science, knowledge & systems 500 Science > 510 Mathematics |
ISBN: |
9781450377317 |
Series: |
EASE 2020 |
Publisher: |
Association for Computing Machinery |
Funders: |
[4] Swiss National Science Foundation |
Language: |
English |
Submitter: |
Oscar Nierstrasz |
Date Deposited: |
20 Apr 2021 12:11 |
Last Modified: |
05 Dec 2022 15:49 |
Publisher DOI: |
10.1145/3383219.3383248 |
Uncontrolled Keywords: |
scg-pub security snf-asa3 scg20 jb20 snf-imad |
BORIS DOI: |
10.48350/154502 |
URI: |
https://boris.unibe.ch/id/eprint/154502 |