Don't Bite off More Than You Can Chew: Investigating Excessive Permission Requests in Trigger-Action Integrations

Liuhuo Wan,Kailong Wang,Kulani Tharaka Mahadewa,Haoyu Wang,Guangdong Bai
DOI: https://doi.org/10.1145/3589334.3645721
2024-01-01
Abstract:Web-based trigger-action platforms (TAP) allow users to integrate Internet of Things (IoT) systems and online services into trigger-action integrations (TAIs), facilitating rich automation tasks known as applets. Despite their benefits, these integrations~(typically involving the TAP, trigger, and action service providers) pose significant security and privacy challenges, such as mis-triggering and data leakage. This work investigates cross-entity permission management within TAIs to address the underlying causes of these security and privacy issues, emphasizing permission-functionality consistency to ensure fairness in permission requests. We introduce PFCon, a system that leverages GPT-based language models for analyzing required and requested permissions, revealing excessive permission requests in a large-scale study of IFTTT TAP. Our findings highlight the need for service providers to enforce permission-functionality consistency, raising awareness of the importance of security and privacy in TAI.
What problem does this paper attempt to address?