Calendar Of Updates: Twitter fanatic glimpses dark side of OAuth - Calendar Of Updates

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Twitter fanatic glimpses dark side of OAuth 'Secure' authentication can be anything but

#1 User is offline   Donna Icon

  • Solar
  • PipPipPipPipPipPipPipPipPip
  • View blog
  • Group: Admin - Site
  • Posts: 16,263
  • Joined: 11-October 03

Awards Bar:

Users Awards

Posted 05 November 2009 - 03:12 PM

Quote

A mobile enthusiast and professional internet strategist got a glimpse of OAuth's dark side recently when he received an urgent advisory from Twitter.

The dispatch, generated when Terence Eden tried to log in, said his Twitter account may have been compromised and advised he change his password. After making sure the alert was legitimate, he complied. That should have been the end of it, but it wasn't. It turns out Eden used OAuth to seamlessly pass content between third-party websites and Twitter, and even after he had changed his Twitter password, OAuth continued to allow those websites access to his account.

"Unless you revoke these tokens when you change your password, a malicious user will still have access to your twitter account," said Eden, who tackles customer usability issues for a large telecommunications company. "Twitter doesn't make that wonderfully clear."

In theory, OAuth is supposed to enhance security by eliminating the need to share Twitter login credentials with other sites. The problem is that the tokens the service uses to authenticate users have to be manually reset.


http://www.theregist...auth_dark_side/

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic


Disclaimer: While CalendarOfUpdates.com uses reasonable efforts to include accurate and up-to-date information, we make no warranties or representations as to the accuracy of the content and assume no liability or responsibility for any error or omission in the content. CalendarofUpdates.com does not represent or warrant that use of any content will not infringe rights of third parties. CalendarOfUpdates.com has no responsibility for actions of third parties or for content provided or posted by others.
All services are subject to the Terms of Service.
Except where otherwise stated, all content Copyright © 2003 - 2010 Dozleng, LLC