Top Banner
What You See Is What They Get Protecting users from unwanted use of microphones, cameras, and other sensors Jon Howell & Stuart Schechter Microsoft Research
17

Jon Howell & Stuart Schechter Microsoft Research

Dec 31, 2015

Download

Documents

brent-vinson

What You See Is What They Get Protecting users from unwanted use of microphones , cameras, and other sensors. Jon Howell & Stuart Schechter Microsoft Research. Who’s watching you?. user’s model is not “ I trust chatroulette ”, but - PowerPoint PPT Presentation
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Jon Howell & Stuart Schechter Microsoft Research

What You See Is What They GetProtecting users from unwanted use of

microphones, cameras, and other sensors

Jon Howell & Stuart SchechterMicrosoft Research

Page 2: Jon Howell & Stuart Schechter Microsoft Research

Who’s watching you?

Page 3: Jon Howell & Stuart Schechter Microsoft Research
Page 4: Jon Howell & Stuart Schechter Microsoft Research
Page 5: Jon Howell & Stuart Schechter Microsoft Research
Page 6: Jon Howell & Stuart Schechter Microsoft Research
Page 7: Jon Howell & Stuart Schechter Microsoft Research
Page 8: Jon Howell & Stuart Schechter Microsoft Research

user’s model is not “I trust chatroulette”, butI don’t mind chatroulette taking my picture

when I know I’m chatting.

can’t trust app to describe activity must rely on user

display effective access policy [Reeder]

Page 9: Jon Howell & Stuart Schechter Microsoft Research

strawpersons

• dialog box every time– annoying

• LED / static icon– fades into visual clutter– too late

Page 10: Jon Howell & Stuart Schechter Microsoft Research

the Sensor-Access Widget

• live feedback• absence implies privacy• shows effective access policy• access control point• configuration control point

Page 11: Jon Howell & Stuart Schechter Microsoft Research

What You See Is What They Get

Page 12: Jon Howell & Stuart Schechter Microsoft Research

Policies

• Hide Widget and Allow (HWA)• Show Widget and Allow (SWA)• Show Widget and Allow After Input and Delay

(SWAAID)• Show Widget and Deny (SWD)• Hide Widget and Deny (HWD)

Page 13: Jon Howell & Stuart Schechter Microsoft Research

SWAAID Show Widget and Allow After Input and Delay

• Show Widget:The widget appears unobstructedin the requesting application’s display

• Input:The user has directed a click or keystrokeat the requesting application

• DelayA five-second waiting period sincevisibility and input were satisfied

54321

Page 14: Jon Howell & Stuart Schechter Microsoft Research

Policies

• Hide Widget and Allow (HWA)• Show Widget and Allow (SWA)• Show Widget and Allow After Input and Delay

(SWAAID)• Show Widget and Deny (SWD)• Hide Widget and Deny (HWD)

data accessiblewithoutuser veto

accessrequireshassling user

Page 15: Jon Howell & Stuart Schechter Microsoft Research

other devices

microphone accelerometer location

Page 16: Jon Howell & Stuart Schechter Microsoft Research

limitations

• conveying subtle threats

• inadequate fidelity

• display crowding

• accidental input

Page 17: Jon Howell & Stuart Schechter Microsoft Research

Summary

• the Sensor-Access Widget mechanism– live data stream of your environment– what you see is what they get

• Show Widget and Allow After Input and Delay(SWAAID) policy– a good default:• doesn’t hassle user• avoids inadvertent privacy leaks