论文标题
欺骗约翰尼授予网络权限
Tricking Johnny into Granting Web Permissions
论文作者
论文摘要
我们在流行的手机和桌面浏览器中研究了Web权限API对话框,发现它通常缺乏保护用户在单击太快时不知不觉地授予Web许可的措施。 我们开发了一个利用此问题的游戏,并欺骗用户授予网络摄像头许可。我们在桌面和移动浏览器上进行了三个实验,每个实验都有40个不同的参与者。结果表明,在没有预防机制的情况下,我们在欺骗95%和72%的参与者方面取得了相当高的成功率,分别在移动和桌面浏览器上。有趣的是,我们还欺骗了47%的参与者在存在预防机制的桌面浏览器上。
We studied the web permission API dialog box in popular mobile and desktop browsers, and found that it typically lacks measures to protect users from unwittingly granting web permission when clicking too fast. We developed a game that exploits this issue, and tricks users into granting webcam permission. We conducted three experiments, each with 40 different participants, on both desktop and mobile browsers. The results indicate that in the absence of a prevention mechanism, we achieve a considerably high success rate in tricking 95% and 72% of participants on mobile and desktop browsers, respectively. Interestingly, we also tricked 47% of participants on a desktop browser where a prevention mechanism exists.