USENIX Security2022Top-tier venue
Neither Access nor Control: A Longitudinal Investigation of the Efficacy of User Access-Control Solutions on Smartphones
Masoud Mehrabi Koushki, Yue Huang, Julia Rubin, Konstantin Beznosov
Abstract
The incumbent all-or-nothing model of access control on smartphones has been known to dissatisfy users, due to high overhead (both cognitive and physical) and lack of device-sharing support. Several alternative models have been proposed. However, their efficacy has not been evaluated and compared empirically, due to a lack of detailed quantitative data on users' authorization needs. This paper bridges this gap with a 30-day diary study. We probed a near-representative sample (N = 55) of US smartphone users to gather a comprehensive list of tasks they perform on their phones and their authorization needs for each task. Using this data, we quantify, for the first time, the efficacy of the all-or-nothing model, demonstrating frequent unnecessary or missed interventions (false positive rate (FPR) = 90%, false negative rate (FNR) = 21%). In comparison, we show that app- or task-level models can improve the FPR up to 88% and the FNR up to 20%, albeit with a modest (up to 15%) increase in required upfront configuration. We also demonstrate that the context in which phone sharing happens is consistent up to 75% of the time, showing promise for context-based solutions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e7f5b5f5-14d3-46ef-bff4-a0e0ae1660deBuilds on4
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan et al.CCS 2016 · 385 citations
- How Well Do My Results Generalize? Comparing Security and Privacy Survey Results from MTurk, Web, and Telephone SamplesElissa M. Redmiles, Sean Kross, Michelle L. MazurekS&P 2019 · 222 citations
- This PIN Can Be Easily Guessed: Analyzing the Security of Smartphone Unlock PINsPhilipp Markert, Daniel V. Bailey, Maximilian Golla, Markus Dürmuth et al.S&P 2020 · 65 citations
- On Smartphone Users' Difficulty with Understanding Implicit AuthenticationMasoud Mehrabi Koushki, Borke Obada-Obieh, Jun Ho Huh, Konstantin BeznosovCHI 2021 · 8 citations
Related papers
- Can Systems Explain Permissions Better? Understanding Users' Misperceptions under Smartphone Runtime Permission ModelBingyu Shen, Lili Wei, Chengcheng Xiang, Yudong Wu et al.USENIX Security 2021 · 45 citations
- The Feasibility of Dynamically Granted Permissions: Aligning Mobile Privacy with User PreferencesPrimal Wijesekera, Arjun Baokar, Lynn Tsai, Joel Reardon et al.S&P 2017 · 156 citations
- A Deep Dive into User's Preferences and Behavior around Mobile Phone SharingRizu Paudel, Prakriti Dumaru, Ankit Shrestha, Huzeyfe Kocabas et al.CSCW 2023 · 19 citations
- A Large Scale Study of User Behavior, Expectations and Engagement with Android PermissionsWeicheng Cao, Chunqiu Xia, Sai Teja Peddinti, David Lie et al.USENIX Security 2021 · 42 citations
- What You Experience is What We Collect: User Experience Based Fine-Grained Permissions for Everyday Augmented RealityMelvin Abraham, Mark McGill, Mohamed KhamisCHI 2024 · 18 citations
