OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

security-services message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Analysis reveals flaws at popular Web SSO sites


Some highlights -

1) its based on actual deployment traces at popular authentication websites (Google, Facebook etc)

2) Requiring use of TLS does not remedy the flaws

3) I wonder how relevant these attacks are to SAML Web SSO

https://research.microsoft.com/pubs/160659/websso-final.pdf


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]