• DocumentCode
    3130614
  • Title

    PoX: Protecting users from malicious Facebook applications

  • Author

    Egele, Manuel ; Moser, Andreas ; Kruegel, Christopher ; Kirda, Engin

  • Author_Institution
    Vienna Univ. of Technol., Vienna, Austria
  • fYear
    2011
  • fDate
    21-25 March 2011
  • Firstpage
    288
  • Lastpage
    294
  • Abstract
    Online social networks such as Facebook, MySpace, and Orkut store large amounts of sensitive user data. While a user can legitimately assume that a social network provider adheres to strict privacy standards, we argue that it is unwise to trust third-party applications on these platforms in the same way. Although the social network provider would be in the best position to implement fine-grained access control for third party applications directly into the platform, existing mechanisms are not convincing. Therefore, we introduce PoX, an extension for Facebook that makes all requests for private data explicit to the user and allows her to exert fine-grained access control over what profile data can be accessed by individual applications. By leveraging a client-side proxy that executes in the user´s web browser, data requests can be relayed to Facebook without forcing the user to trust additional third parties. Of course, the presented system is backwards compatible and transparently falls back to the original behavior if a client does not support our system. Thus, we consider PoX to be a readily available alternative for privacy-aware users that do not want to wait for privacy-relevant improvements to be implemented by Facebook itself.
  • Keywords
    authorisation; data privacy; online front-ends; social networking (online); MySpace; Orkut; PoX; Web browser; data requests; fine-grained access control; malicious Facebook applications; online social networks; privacy-aware users; user protection; Clocks;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Pervasive Computing and Communications Workshops (PERCOM Workshops), 2011 IEEE International Conference on
  • Conference_Location
    Seattle, WA
  • Print_ISBN
    978-1-61284-938-6
  • Electronic_ISBN
    978-1-61284-936-2
  • Type

    conf

  • DOI
    10.1109/PERCOMW.2011.5766885
  • Filename
    5766885