"I have no idea how to make it safer": Studying Security and Privacy Mindsets of Browser Extension Developers
Shubham Agarwal, Rafael Mrowczynski, Maria Hellenthal, Ben Stock
摘要
Browser extensions play a vital role in the Web ecosystem: they enable users to customize their experience while browsing. However, the higher privileges of extensions compared to the Web applications require in-depth security considerations to not threaten the security and privacy (S&P) of their users; the security and privacy mindset of developers has not been studied yet, though. In this paper, we close this research gap. To that end, we conducted a qualitative study with extension developers from diverse backgrounds and experience levels (N=21) to identify the root causes for vulnerable extensions existing in the ecosystem. Our findings suggest that developers often implicitly acknowledge the S&P risks associated with their extensions, but they frequently lack the necessary knowledge and resources to implement effective security and privacy-protecting mechanisms. Additionally, socio-technical barriers, such as insufficient incentives and external pressures, including platform-imposed restrictions, further hinder secure development practices. Based on our findings, we offer empirically grounded takeaways for the browser extension ecosystem to help strengthen security practices and ultimately provide better protection for users. Related Work In this section, we discuss various research studies related to our work that highlight the S&P issues with browser extensions. We also refer to other related developer-centric studies focused on the security and privacy mindsets of software developers since they also inspired our study design.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper21
- Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application SecurityFelix Fischer, Konstantin Böttinger, Huang Xiao, Christian Stransky 等S&P 2017 · 被引用 293 次
- XHOUND: Quantifying the Fingerprintability of Browser ExtensionsOleksii Starov, Nick NikiforakisS&P 2017 · 被引用 104 次
- Mystique: Uncovering Information Leakage from Browser ExtensionsQuan Chen, Alexandros KapravelosCCS 2018 · 被引用 88 次
- EmPoWeb: Empowering Web Applications with Browser ExtensionsDolière Francis SoméS&P 2019 · 被引用 60 次
- Fingerprinting in Style: Detecting Browser Extensions via Injected Style SheetsPierre Laperdrix, Oleksii Starov, Quan Chen, Alexandros Kapravelos 等USENIX Security 2021 · 被引用 49 次
相关 Paper
- Experimental Security Analysis of Sensitive Data Access by Browser ExtensionsAsmit Nayak, Rishabh Khandelwal, Earlence Fernandes, Kassem FawazWWW 2024 · 被引用 12 次
- Peeking through the window: Fingerprinting Browser Extensions through Page-Visible Execution Traces and InteractionsShubham Agarwal, Aurore Fass, Ben StockCCS 2024 · 被引用 4 次
- Detection of Inconsistencies in Privacy Practices of Browser ExtensionsDuc Bui, Brian Tang, Kang G. ShinS&P 2023
- A Qualitative Study of Dependency Management and Its Security ImplicationsIvan Pashchenko, Duc-Ly Vu, Fabio MassacciCCS 2020 · 被引用 84 次
- Extending a Hand to Attackers: Browser Privilege Escalation Attacks via ExtensionsYoung Min Kim, Byoungyoung LeeUSENIX Security 2023
