论文标题
如果此上下文,则疑虑:探索用户对IFTTT小程序的关注
If This Context Then That Concern: Exploring users' concerns with IFTTT applets
论文作者
论文摘要
最终用户越来越多地使用触发器平台,例如,这是(IFTTT)来创建APPLET来连接智能家居设备和服务。但是,使用此类小程序(即使是非疑问)存在固有的风险,因为敏感信息可能会在某些情况下(例如,设备所在的位置,可以观察到所得操作)泄漏。这项工作旨在了解最终用户如何评估这种风险。我们这样做是通过探索用户对使用IFTTT小程序的疑虑,更重要的是,这些关注以及这些关注如何根据不同的上下文因素而变化。通过对49个智能居家IFTTT小程序的386名参与者的机械TURK调查,我们发现参与者思考不同的用法环境,使他们更深入地思考相关的风险并提高他们的担忧。定性分析表明,参与者对上下文因素有细微的了解以及这些因素如何导致敏感数据泄漏,并允许未经授权访问小程序和数据。
End users are increasingly using trigger-action platforms like, If-This-Then-That (IFTTT) to create applets to connect smart home devices and services. However, there are inherent risks in using such applets -- even non-malicious ones -- as sensitive information may leak through their use in certain contexts (e.g., where the device is located, who can observe the resultant action). This work aims to understand how well end users can assess this risk. We do so by exploring users' concerns with using IFTTT applets and more importantly if and how those concerns change based on different contextual factors. Through a Mechanical Turk survey of 386 participants on 49 smart-home IFTTT applets, we found that nudging the participants to think about different usage contexts led them to think deeper about the associated risks and raise their concerns. Qualitative analysis reveals that participants had a nuanced understanding of contextual factors and how these factors could lead to leakage of sensitive data and allow unauthorized access to applets and data.