Voice-controlled smart speaker devices have gained a foothold in many modern households. Their prevalence combined with their intrusion into core private spheres of life has motivated research on security and privacy intrusions, especially those performed by third-party applications used on such devices. In this work, we take a closer look at such third-party applications from a less pessimistic angle: we consider their potential to provide personalized and secure capabilities and investigate measures to authenticate users (``PIN'', ``Voice authentication'', ``Notification'', and presence of ``Nearby devices''). To this end, we asked 100 participants to evaluate 15 application categories and 51 apps with a wide range of functions. The central questions we explored focused on: users' preferences for security and personalization for different categories of apps; the preferred security and personalization measures for different apps; and the preferred frequency of the respective measure. After an initial pilot study, we focused primarily on 7 categories of apps for which security and personalization are reported to be important; those include the three crucial categories finance, bills, and shopping. We found that ``Voice authentication'', while not currently employed by the apps we studied, is a highly popular measure to achieve security and personalization. Many participants were open to exploring combinations of security measures to increase the protection of highly relevant apps. Here, the combination of ``PIN'' and ``Voice authentication'' was clearly the most desired one. This finding indicates systems that seamlessly combine ``Voice authentication'' with other measures might be a good candidate for future work.
翻译:在许多现代家庭里,声音控制的智能扬声器装置已经赢得了立足点。它们的流行,加上它们侵入核心私人生活领域,促进了对安全和隐私侵入的研究,特别是使用这类装置的第三方应用程序。在这项工作中,我们从不太悲观的角度更仔细地审视这种第三方应用程序:我们认为它们有可能提供个性化和安全能力,并调查验证用户的措施(“PIN”、“语音认证”、“通知”和“早期设备”的存在)。为此,我们要求100名参与者评估15个应用程序类别和51个应用程序,并具有广泛的功能。我们探讨的中心问题侧重于:用户对不同类别应用程序的安全和个性化偏好;不同应用程序的首选的安全和个性化措施;以及相应措施的偏好频率。在进行初步试点研究后,我们主要侧重于7类应用程序,据报告安全和个性化非常重要;这包括三个关键的金融、帐单和购物类别。我们发现,大多数的认证措施都是为了安全性化措施,而我们目前采用的是高度安全性化措施的组合,而现在采用的一种是高度安全性化措施,而现在采用的是高度安全性化的组合。