Collected research
Do not trust me: Using malicious IdPs for analyzing and attacking Single Sign-On
Uses an attacker-controlled identity provider to examine OpenID discovery, association and token verification. OpenID Attacker tests recipient confusion, key confusion, identity spoofing and discovery spoofing against 16 implementations, compromising 11. The paper traces failures to missing bindings between identities, provider URLs, cryptographic keys and session state.
Record
- Researcher
- Christian Mainka, Vladislav Mladenov and Jörg Schwenk
- Published by
- arxiv.org
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Christian Mainka, Vladislav Mladenov and Jörg Schwenk, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .