All your Google and Facebook logins are belong to us: A case for single sign-off

Vaibhav Rastogi, Ankit Agrawal

Research output: Chapter in Book/Report/Conference proceedingConference contribution

5 Scopus citations

Abstract

The websites of the modern Web integrate content from multiple parties to provide an enriched user experience. The so-called single sign-on forms part of this integration whereby a relying website enables a user to use her credentials on a third-party provider (such as Google or Facebook) to authenticate with itself and, if desired, authorize itself to use her resources on the provider. The user benefits by not remembering credentials for different websites separately and by allowing controlled use of her resources with a provider by other website. However, we observe that the current protocols for single sign-on do not have any provision of what we call single sign-off: once the user logs out of a relying website, the user still remains signed into the provider website. This can leave the user vulnerable if she forgets to sign out of the provider website after signing out of the relying website on a shared computer. We manually analyze the top twenty websites using Facebook or Google providers and conclude that the above problem is widespread. All but one website do not even warn the user with regard to this problem.

Original languageEnglish (US)
Title of host publication2015 8th International Conference on Contemporary Computing, IC3 2015
EditorsJ. Amudha, Deepa Gupta, Jaric Zola, Narendra Nanjangud, Animesh Pathak, Sushil K. Prasad, Tirumale Ramesh, Manish Parashar, Kishore Kothapalli, Purushotham Bangalore, Sanjay Chaudhary, K. V. Dinesha
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages416-421
Number of pages6
ISBN (Electronic)9781467379489
DOIs
StatePublished - Dec 3 2015
Event8th International Conference on Contemporary Computing, IC3 2015 - Noida, India
Duration: Aug 20 2015Aug 22 2015

Publication series

Name2015 8th International Conference on Contemporary Computing, IC3 2015

Other

Other8th International Conference on Contemporary Computing, IC3 2015
Country/TerritoryIndia
CityNoida
Period8/20/158/22/15

Keywords

  • Single sign-off
  • Single sign-on
  • Web security

ASJC Scopus subject areas

  • Software

Fingerprint

Dive into the research topics of 'All your Google and Facebook logins are belong to us: A case for single sign-off'. Together they form a unique fingerprint.

Cite this