Web Hack List

Collected research

SpoofedMe — Intruding Accounts using Social Login Providers

SpoofedMe: Intruding Accounts using Social Login Providers

Examines social-login impersonation when providers issue unverified email attributes and relying applications use them to locate or link accounts. The paper compares LinkedIn, Amazon and MYDIGIPASS flows, separating provider authentication, ownership of an email address and authorization to attach an identity to an existing account.

Record

Document
SpoofedMe: Intruding Accounts using Social Login Providers
Researcher
Or Peles and Roee Hay
Published by
IBM Security Systems
Date
Format
Slides
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Or Peles and Roee Hay, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .