Web Hack List

Collected research

Security and Privacy of Social Logins

A master's thesis that reverse-engineers the Sign in with Apple, Google Sign-In and Facebook Login protocols, then audits how their SDKs and 63 real-world sites use postMessage for the popup handoff. Missing origin and destination checks let any website steal SSO tokens for account takeover or land DOM-based XSS, and prompt=none with login_hint gives XS-Leaks revealing which accounts and identity a visitor holds.

Record

Researcher
Louis Christopher Jannett
Published by
nds.ruhr-uni-bochum.de
Format
Whitepaper
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Louis Christopher Jannett, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .