We still need to add the text addressing the points described in John Bradley’s reply to you sent while in London.
-- Mike From: OAuth <oauth-boun...@ietf.org> On Behalf Of Eric Rescorla Sent: Friday, April 13, 2018 6:00 PM To: oauth@ietf.org Subject: [OAUTH-WG] Follow up on draft-ietf-oauth-device-flow-08 Hi folks, I just looked at the -08 diffs and I see a new section on brute forcing the token but not describing the confused deputy attack. Did I miss something, or were you still planning to add more text? Thanks -Ekr
_______________________________________________ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth