Collected research
The Devil is in the (Implementation) Details: An Empirical Analysis of OAuth SSO Systems
A black-box study of three OAuth 2.0 identity providers and 96 Facebook relying parties, tracing SSO credentials through browser HTTP traffic with a Firefox add-on and semi-automatic exploit tools. Access tokens leaked unencrypted on 32% of RPs, could be stolen via XSS on 91%, and 64% let an attacker impersonate a user by replaying an unbound SSO credential.
Record
- Researcher
- San-Tsai Sun and Konstantin Beznosov
- Published by
- css.csail.mit.edu
- Format
- Whitepaper
- Topic
- Identity
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of San-Tsai Sun and Konstantin Beznosov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .