Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-v2-threatmodel-07.txt

Torsten Lodderstedt <torsten@lodderstedt.net> Thu, 16 August 2012 17:19 UTC

Return-Path: <torsten@lodderstedt.net>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 42BBD21F8672 for <oauth@ietfa.amsl.com>; Thu, 16 Aug 2012 10:19:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[AWL=0.153, BAYES_00=-2.599, HELO_EQ_DE=0.35]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vl4js5ldhtjp for <oauth@ietfa.amsl.com>; Thu, 16 Aug 2012 10:19:35 -0700 (PDT)
Received: from smtprelay01.ispgateway.de (smtprelay01.ispgateway.de [80.67.18.13]) by ietfa.amsl.com (Postfix) with ESMTP id A98CE21F8671 for <oauth@ietf.org>; Thu, 16 Aug 2012 10:19:35 -0700 (PDT)
Received: from [79.253.20.219] (helo=[192.168.71.42]) by smtprelay01.ispgateway.de with esmtpsa (TLSv1:AES256-SHA:256) (Exim 4.68) (envelope-from <torsten@lodderstedt.net>) id 1T23jJ-0006As-9s for oauth@ietf.org; Thu, 16 Aug 2012 19:19:33 +0200
Message-ID: <502D2BA4.9010305@lodderstedt.net>
Date: Thu, 16 Aug 2012 19:19:32 +0200
From: Torsten Lodderstedt <torsten@lodderstedt.net>
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:14.0) Gecko/20120713 Thunderbird/14.0
MIME-Version: 1.0
To: oauth@ietf.org
References: <20120816171445.29317.99704.idtracker@ietfa.amsl.com>
In-Reply-To: <20120816171445.29317.99704.idtracker@ietfa.amsl.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Df-Sender: dG9yc3RlbkBsb2RkZXJzdGVkdC1vbmxpbmUuZGU=
Subject: Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-v2-threatmodel-07.txt
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Aug 2012 17:19:36 -0000

Hi all,

the new revision covers token substitution, which has been added to the 
core spec lately. Additionally, it describes a similar attack on the 
code flow, which is prevented by forcing the authorization server to 
validate that an authorization code had been issued to the calling client.

We also made the references to core and bearer spec normative.

regards,
Torsten.

Am 16.08.2012 19:14, schrieb internet-drafts@ietf.org:
> A New Internet-Draft is available from the on-line Internet-Drafts directories.
>   This draft is a work item of the Web Authorization Protocol Working Group of the IETF.
>
> 	Title           : OAuth 2.0 Threat Model and Security Considerations
> 	Author(s)       : Torsten Lodderstedt
>                            Mark McGloin
>                            Phil Hunt
> 	Filename        : draft-ietf-oauth-v2-threatmodel-07.txt
> 	Pages           : 70
> 	Date            : 2012-08-16
>
> Abstract:
>     This document gives additional security considerations for OAuth,
>     beyond those in the OAuth specification, based on a comprehensive
>     threat model for the OAuth 2.0 Protocol.
>
>
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-oauth-v2-threatmodel
>
> There's also a htmlized version available at:
> http://tools.ietf.org/html/draft-ietf-oauth-v2-threatmodel-07
>
> A diff from the previous version is available at:
> http://www.ietf.org/rfcdiff?url2=draft-ietf-oauth-v2-threatmodel-07
>
>
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth