Online services like Google provide a variety of application programming interfaces (APIs). These online APIs enable authenticated third-party services and applications (apps) to access a user's account data for tasks such as single sign-on (SSO), calendar integration, and sending email on behalf of the user, among others. Despite their prevalence, API access could pose significant privacy and security risks, where a third-party could have unexpected privileges to a user's account. To gauge users' perceptions and concerns regarding third-party apps that integrate with online APIs, we performed a multi-part online survey of Google users. First, we asked n = 432 participants to recall if and when they allowed third-party access to their Google account: 89% recalled using at least one SSO and 52% remembered at least one third-party app. In the second survey, we re-recruited n = 214 participants to ask about specific apps and SSOs they've authorized on their own Google accounts. We collected in-the-wild data about users' actual SSOs and authorized apps: 86% used Google SSO on at least one service, and 67% had at least one third-party app authorized. After examining their apps and SSOs, participants expressed the most concern about access to personal information like email addresses and other publicly shared info. However, participants were less concerned with broader -- and perhaps more invasive -- access to calendars, emails, or cloud storage (as needed by third-party apps). This discrepancy may be due in part to trust transference to apps that integrate with Google, forming an implied partnership. Our results suggest opportunities for design improvements to the current third-party management tools offered by Google; for example, tracking recent access, automatically revoking access due to app disuse, and providing permission controls.
翻译:谷歌等在线服务提供各种应用程序编程界面(APIs) 。 这些在线 API 使经认证的第三方服务和应用(应用程序) 能够访问用户账户数据, 以完成单签名、 日历整合和代表用户发送电子邮件等任务。 尽管使用率普遍, 但 API 访问可能带来巨大的隐私和安全风险, 第三方可能对用户账户拥有意想不到的特权。 为了衡量用户对与在线API整合的第三方应用程序的看法和关切, 我们对谷歌用户进行了多部分在线在线调查。 首先, 我们要求 = 432 参与者回忆是否允许第三方访问其谷歌账户: 89% 记得至少使用一个 SSO, 52% 记得至少一个第三方应用程序。 在第二次调查中, 我们再次邀请n= 214 参与者询问他们自己账户上授权的具体应用程序和SOO 工具。 我们从网上收集了关于用户实际存储服务器的更新数据, 并授权了应用程序: 86% 使用SOO 服务器访问后, 也表示他们最需要的服务器访问次数。