Web Hack List

Collected research

An Expressive Model for the Web Infrastructure: Definition and Application to the BrowserID SSO System

A Dolev-Yao style formal model of the web infrastructure covering HTTP, DNS, browsers, cookies, web storage and cross-document messaging, precise enough to analyse real applications. Applied to Mozilla's BrowserID single sign-on it exposed critical flaws letting an attacker obtain an identity assertion and log in as a victim; the fixes were adopted by Mozilla.

Record

Researcher
Daniel Fett, Ralf Küsters and Guido Schmitz
Published by
ieee-security.org
Format
Whitepaper
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Daniel Fett, Ralf Küsters and Guido Schmitz, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .