Hi Marc,

You're right, the report I referred to is not a formal analysis.

Thanks for the reference to the your lab's analysis of OAuth 1.0a.  I had a 
quick look at it, and at the Canetti tutorial on the underlying methodology 
that the paper refers to.  It's interesting, but so complicated!

It's a pity that your colleagues missed the flaw in OAuth 1.0a.  In section 5.4 
they say "We assume that the Consumer and Service Providers have public keys 
(and certificates) and that the end-user communicates with theses server 
entities over secure channels (SSL/TLS)".  If instead of assuming it they had 
checked the spec they would have seen that that's not true for the consumer, 
and they would have been able to claim an important practical result :-)


Hi Francisco

Yes, I have seen that report in the past and it is good and informative but
is not a substitute for formal analysis. Here is another example of the
type of analysis I am looking for, this one covering Oauth 1.0a from our
research lab



