Lune

WWW2024Top-tier venue

Don't Bite Off More than You Can Chew: Investigating Excessive Permission Requests in Trigger-Action Integrations

Liuhuo Wan, Kailong Wang, Kulani Mahadewa, Haoyu Wang, Guangdong Bai

2024Year
4Citations
1Top-tier citations

Abstract

Web-based trigger-action platforms (TAP) allow users to integrate Internet of Things (IoT) systems and online services into triggeraction integrations (TAIs), facilitating rich automation tasks known as applets. Despite their benefits, these integrations (typically involving the TAP, trigger, and action service providers) pose significant security and privacy challenges, such as mis-triggering and data leakage. This work investigates cross-entity permission management within TAIs to address the underlying causes of these security and privacy issues, emphasizing permission-functionality consistency to ensure fairness in permission requests. We introduce PFCon, a system that leverages GPT-based language models for analyzing required and requested permissions, revealing excessive permission requests in a large-scale study of IFTTT TAP. Our findings highlight the need for service providers to enforce permission-functionality consistency, raising awareness of the importance of security and privacy in TAI. CCS CONCEPTS • Security and privacy → Web application security; • Networks → Network privacy and anonymity.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 110f98d5-e839-419c-a31e-5fa67f6135ad

Cited by top-tier papers1

Ask how each one uses it

Builds on17

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines