End users are increasingly using trigger-action platforms like, If-This-Then-That (IFTTT) to create applets to connect smart home devices and services. However, there are inherent risks in using such applets -- even non-malicious ones -- as sensitive information may leak through their use in certain contexts (e.g., where the device is located, who can observe the resultant action). This work aims to understand how well end users can assess this risk. We do so by exploring users' concerns with using IFTTT applets and more importantly if and how those concerns change based on different contextual factors. Through a Mechanical Turk survey of 386 participants on 49 smart-home IFTTT applets, we found that nudging the participants to think about different usage contexts led them to think deeper about the associated risks and raise their concerns. Qualitative analysis reveals that participants had a nuanced understanding of contextual factors and how these factors could lead to leakage of sensitive data and allow unauthorized access to applets and data.
翻译:终端用户越来越多地使用触发行动平台,比如“如果这个”然后(IFTTT)来创建小程序来连接智能家用设备和服务。然而,使用这些小程序(甚至是非恶意的小程序)存在内在风险,因为敏感信息可能在某些场合(例如,设备所在,谁可以观察由此产生的行动)通过使用而泄漏。这项工作的目的是了解终端用户能够如何很好地评估这一风险。我们这样做的方法是探索用户对使用IFTT小程序的关切,更重要的是,如果以及这些因素是如何根据不同背景因素变化的。我们通过对49个智能家IFTTT小程序的386名参与者进行的机械化土耳其调查发现,让参与者思考不同的使用环境导致他们更深入地思考相关风险并提出他们的关切。定性分析表明,参与者对背景因素有细微的了解,这些因素如何可能导致敏感数据泄漏,并允许未经授权访问小程序和数据。