Social login with OAuth for mobile applications: User's view

Lee Kah Ho, Norliza Katuk · 2016

Social network credentials can be used to login to native applications installed in smartphones or tablet computers. This approach is known as social login (SL) where its implementation is carried out using OAuth protocol. Communication between applications and social network servers involves with browser redirection. Applications could redirect token to any URL including malicious applications that intend to steal users' credential. This issue can be improved by developing a built-in module that handles the authorization process. An approach known as OAuth Manager Module is presented in this paper. A prototype application was developed to demonstrate the approach. Facebook SL was also provided as the authentication mechanism. The prototype is evaluated through a controlled experimentation of real users. The users interacted with the prototype and gave their views on the security of the module. The security of the module is compared with the common mobile browser implementation. The result suggests that users see that communication using the module is more secure than the mobile browsers.

Read the paper · More papers on PaperTik