Collected research
Security and Privacy of Social Logins
A master's thesis that reverse-engineers the Sign in with Apple, Google Sign-In and Facebook Login protocols, then audits how their SDKs and 63 real-world sites use postMessage for the popup handoff. Missing origin and destination checks let any website steal SSO tokens for account takeover or land DOM-based XSS, and prompt=none with login_hint gives XS-Leaks revealing which accounts and identity a visitor holds.
Record
- Researcher
- Louis Christopher Jannett
- Published by
- nds.ruhr-uni-bochum.de
- Format
- Whitepaper
- Topic
- Other
In the archive
Related sources
- Security and Privacy of Social Logins (I): Single Sign-On Protocols in the Wild
- Security and Privacy of Social Logins (II): PostMessage Security in Single Sign-On
- Security and Privacy of Social Logins (III): Privacy in Single Sign-On Protocols
- Research browser extension
Tags
This page is the archive's own catalogue record. The research is the work of Louis Christopher Jannett, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .