Login | Register

On Analyzing SSO Permissions Across Web and Android Platforms

Title:

On Analyzing SSO Permissions Across Web and Android Platforms

Rezaei, Fahimeh ORCID: https://orcid.org/0009-0001-4816-4034 (2025) On Analyzing SSO Permissions Across Web and Android Platforms. Masters thesis, Concordia University.

[thumbnail of Rezaei_MASc-F2025.pdf]
Preview
Text (application/pdf)
Rezaei_MASc-F2025.pdf - Accepted Version
Available under License Spectrum Terms of Access.
3MB

Abstract

Federated Single Sign-On (SSO) is a widely used authentication method that delegates user login to Identity Providers (IdPs) such as Google and Facebook. While convenient, SSO raises privacy and security concerns, particularly, as we observed, when permissions vary across different platforms (web vs.\ mobile, even different versions of an app). Existing work on SSO logins completely lacks the exploration of such variances, and their privacy consequences, even though many users may use a service both via web and mobile platforms. This study examines such discrepancies at scale, alongside an analysis of dangerous permissions specifically requested on websites and Android apps. We developed a framework to automate SSO logins on both platforms, systematically measuring permission discrepancies. Our analysis, based on 661 and 318 successful logins using Google and Facebook SSO, respectively, across both the Android app and its corresponding website for the same service, reveals a 12.58\% discrepancy in Facebook SSO permissions and a 3.48\% discrepancy in Google SSO permissions between web and Android platforms. These findings, along with our analysis of top-5K Tranco websites, indicate that Android apps tend to request more intrusive permissions, underscoring the need for incremental authorization mechanisms to minimize unnecessary data exposure.

Divisions:Concordia University > Gina Cody School of Engineering and Computer Science > Concordia Institute for Information Systems Engineering
Item Type:Thesis (Masters)
Authors:Rezaei, Fahimeh
Institution:Concordia University
Degree Name:M.A. Sc.
Program:Information Systems Security
Date:May 2025
Thesis Supervisor(s):Mannan, Mohammad and Youssef, Amr
ID Code:995531
Deposited By: Fahimeh Rezaei
Deposited On:04 Nov 2025 16:54
Last Modified:04 Nov 2025 16:54
All items in Spectrum are protected by copyright, with all rights reserved. The use of items is governed by Spectrum's terms of access.

Repository Staff Only: item control page

Downloads per month over past year

Research related to the current document (at the CORE website)
- Research related to the current document (at the CORE website)
Back to top Back to top