Feed Sign in with OpenID OpenID

Simon Willison’s Weblog

OAuth Security Advisory 2009.1. It’s a show-stopper: an attacker can start an OAuth permission request flow from a consumer site, then trick another user from the same site in to completing that flow and hence authorising the attacker to act on their behalf. A fix to the spec is forthcoming; in the meantime, don’t start an OAuth flow from an untrusted location.

Tagged , ,

2 comments

  1. The description by Eran Hammer-Lahav is also quite informative.

    Adam Lowry - 23rd April 2009 17:30 - #

  2. Why would anyone ever start an OAuth flow from an untrusted location? >:(

    Jeremy Dunck - 23rd April 2009 20:10 - #

Comments are closed.
A django site