Simon Willison’s Weblog

Subscribe

Thursday, 23rd April 2009

The First Ten Things the New CEO of MySpace Should Do. From the always thought provoking Jason Calacanis.

# 11:30 am / jason-calacanis, ceo, myspace, socialnetworks

OAuth Security Advisory 2009.1. It’s a show-stopper: an attacker can start an OAuth permission request flow from a consumer site, then trick another user from the same site in to completing that flow and hence authorising the attacker to act on their behalf. A fix to the spec is forthcoming; in the meantime, don’t start an OAuth flow from an untrusted location.

# 3:06 pm / ouath, security, sessionfixation