USENIX Security2022Top-tier venue
Security and Privacy Perceptions of Third-Party Application Access for Google Accounts
David G. Balash, Xiaoyuan Wu, Miles Grant, Irwin Reyes, Adam J. Aviv
Abstract
Online services like Google provide a variety of application programming interfaces (APIs). These online APIs enable authenticated third-party services and applications (apps) to access a user's account data for tasks such as single sign-on (SSO), calendar integration, and sending email on behalf of the user, among others. Despite their prevalence, API access could pose significant privacy and security risks, where a thirdparty could have unexpected privileges to a user's account. To gauge users' perceptions and concerns regarding third-party apps that integrate with online APIs, we performed a multipart online survey of Google users. First, we asked n = 432 participants to recall if and when they allowed third-party access to their Google account: 89% recalled using at least one SSO and 52% remembered at least one third-party app. In the second survey, we re-recruited n = 214 participants to ask about specific apps and SSOs they've authorized on their own Google accounts. We collected in-the-wild data about users' actual SSOs and authorized apps: 86% used Google SSO on at least one service, and 67% had at least one third-party app authorized. After examining their apps and SSOs, participants expressed the most concern about access to personal information like email addresses and other publicly shared info. However, participants were less concerned with broader-and perhaps more invasive-access to calendars, emails, or cloud storage (as needed by third-party apps). This discrepancy may be due in part to trust transference to apps that integrate with Google, forming an implied partnership. Our results suggest opportunities for design improvements to the current third-party management tools offered by Google; for example, tracking recent access, automatically revoking access due to app disuse, and providing permission controls.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8e6b2dd3-1614-4c79-bb92-e71072800626Cited by top-tier papers6
- Uncovering Privacy and Security Challenges In K-12 SchoolsJake Chanenson, Brandon Sloane, Navaneeth Rajan, Amy Morrill et al.CHI 2023 · 26 citations
- DISTINCT: Identity Theft using In-Browser Communications in Dual-Window Single Sign-OnLouis Jannett, Vladislav Mladenov, Christian Mainka, Jörg SchwenkCCS 2022 · 11 citations
- Is It Safe to Share Your Files? An Empirical Security Analysis of Google WorkspaceLiuhuo Wan, Kailong Wang, Haoyu Wang, Guangdong BaiWWW 2024 · 6 citations
- Don't Bite Off More than You Can Chew: Investigating Excessive Permission Requests in Trigger-Action IntegrationsLiuhuo Wan, Kailong Wang, Kulani Mahadewa, Haoyu Wang et al.WWW 2024 · 4 citations
- I Can Tell Your Secrets: Inferring Privacy Attributes from Mini-app Interaction History in Super-appsYifeng Cai, Ziqi Zhang, Mengyu Yao, Junlin Liu et al.USENIX Security 2025
Builds on5
- How Well Do My Results Generalize? Comparing Security and Privacy Survey Results from MTurk, Web, and Telephone SamplesElissa M. Redmiles, Sean Kross, Michelle L. MazurekS&P 2019 · 222 citations
- The Feasibility of Dynamically Granted Permissions: Aligning Mobile Privacy with User PreferencesPrimal Wijesekera, Arjun Baokar, Lynn Tsai, Joel Reardon et al.S&P 2017 · 156 citations
- Oh, the Places You've Been! User Reactions to Longitudinal Transparency About Third-Party Web Tracking and InferencingBen Weinshel, Miranda Wei, Mainack Mondal, Euirim Choi et al.CCS 2019 · 73 citations
- O Single Sign-Off, Where Art Thou? An Empirical Analysis of Single Sign-On Account Hijacking and Session Management on the WebMohammad Ghasemisharif, Amrutha Ramesh, Stephen Checkoway, Chris Kanich et al.USENIX Security 2018 · 63 citations
- Are Privacy Dashboards Good for End Users? Evaluating User Perceptions and Reactions to Google's My ActivityFlorian M. Farke, David G. Balash, Maximilian Golla, Markus Dürmuth et al.USENIX Security 2021 · 48 citations
Related papers
- Hazard Integrated: Understanding Security Risks in App Extensions to Team Chat SystemsMingming Zha, Jice Wang, Yuhong Nan, Xiaofeng Wang et al.NDSS 2022
- "Only as Strong as the Weakest Link": On the Security of Brokered Single Sign-On on the WebTommaso Innocenti, Louis Jannett, Christian Mainka, Vladislav Mladenov et al.S&P 2025
- Take Over the Whole Cluster: Attacking Kubernetes via Excessive Permissions of Third-party ApplicationsNanzi Yang, Wenbo Shen, Jinku Li, Xunqi Liu et al.CCS 2023 · 15 citations
- The Nuanced Nature of Trust and Privacy Control Adoption in the Context of GoogleEhsan Ul Haque, Mohammad Maifi Hasan Khan, Md Abdullah Al FahimCHI 2023 · 7 citations
- The Privacy-Utility Trade-off in the Topics APIMário S. Alvim, Natasha Fernandes, Annabelle McIver, Gabriel H. NunesCCS 2024 · 3 citations
