[OAUTH-WG] Endpoint Misconfiguration / Social Engineering Attack

2020-10-08 Thread Guido Schmitz
Hi, We just had a discussion in Stuttgart on the possibility of misconfigured endpoints, i.e., an honest client uses the wrong endpoints for interacting with some honest AS. Such a setting might be the outcome of a social engineering attack against the administrators of a client (e.g., the attacke

[OAUTH-WG] WGLC review of draft-ietf-oauth-security-topics-13

2019-11-22 Thread Guido Schmitz
Hi, All of my comments on oauth-security-topics-13 are remarks/questions/suggestions for clarification in the document, i.e., I do not have any fundamental objections. Overall, the draft is, in my opinion, in good shape to be published and as already discussed, open points can be updated later. I

Re: [OAUTH-WG] Multi-AS State Re-Use

2016-05-09 Thread Guido Schmitz
Hi all, can anybody confirm that this is a new / undocumented attack? Cheers, Guido, Daniel, and Ralf On 22.04.2016 16:23, Daniel Fett wrote: > Hi all, > > Besides the state leakage attack we found that another important fact > regarding state is underspecified: Each state value should only be

Re: [OAUTH-WG] State Leakage Attack

2016-04-23 Thread Guido Schmitz
Originalnachricht > Betreff: Re: [OAUTH-WG] State Leakage Attack > Von: Daniel Fett > An: Antonio Sanso > Cc: Guido Schmitz ,oauth@ietf.org,Ralf > Kuesters > > Am 22.04.2016 um 16:39 schrieb Antonio Sanso: >> hi Daniel >> >> On Apr 22, 2