Re: [OAUTH-WG] draft-parecki-oauth-browser-based-apps-00

Hans Zandbelt <hans.zandbelt@zmartzone.eu> Mon, 19 November 2018 10:03 UTC

Return-Path: <hans.zandbelt@zmartzone.eu>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0714112F1A5 for <oauth@ietfa.amsl.com>; Mon, 19 Nov 2018 02:03:19 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=zmartzone-eu.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CgZ9hBK24Omi for <oauth@ietfa.amsl.com>; Mon, 19 Nov 2018 02:03:16 -0800 (PST)
Received: from mail-io1-xd2a.google.com (mail-io1-xd2a.google.com [IPv6:2607:f8b0:4864:20::d2a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 73ABD128A5C for <oauth@ietf.org>; Mon, 19 Nov 2018 02:03:16 -0800 (PST)
Received: by mail-io1-xd2a.google.com with SMTP id r200so16277883iod.11 for <oauth@ietf.org>; Mon, 19 Nov 2018 02:03:16 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=zmartzone-eu.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=p3VpJoIfNOORQZP2Ky8vf7A8w/+2IIGdYxKewOSVffo=; b=eh2uHtyECbeI84XSi2NH3UFjfLrip0KXOGKKGh0pVY1k2kWZ0uC/zVVfGCbFoJVPmz M+jSn+Rns+uUxVRgtbZU4d4TGmnosz2TE+Z38+aoK/snBXJQR9/jg5TQ2T0M8tcw47Y7 XvjD0daZtoXa2s+OJ6cYwMZQn/ibIhAl81nxK6fXohzTzVRdjcvNrC6KGIEP8g8xeYJ8 NkzwFQvZy3mCF6RPoOv/tmGdBTBMTLeq3xB3PwN8O1gANYQXF9IBPe4kjeDHQSgBeS/O 9h1f2EP5R0mSHNqNnvrSbiX5rD68uMJvwC2HX0Ku5uBq0/2eYaw5HpF9vYPFlAVm+ftN EB9A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=p3VpJoIfNOORQZP2Ky8vf7A8w/+2IIGdYxKewOSVffo=; b=qyhgdFZgxy/hJakFZUh3oG6uB1Y+7pOu+xL8tDZ3oTpad+zL3y/4CqJszE+fzwnWCN GANuVpyMHz3qTupNxL3OoxBlLCYbam0RSASC+KVRrcE9UCrqSLsMftLuLcxPDgSLtead 2gJecc94aAc08UQo+M2EqxtaIKR0biuDPPIgBNx1AcCyNubEouBXtCsp5fB2sWTSEMpC JiEUIO6T+A4Pca5SvEsX+nTbapph7ggF0d2lVCtrltz6mM6TrBpR5LsW7vbW1KR65gGo I3Qq1Lo0kDNa0ZCJJxZNw43YYeGiCTkvQS6hV2ok5DO5JH62xeCTZKuPI+DaZm76Mn1C Mg5Q==
X-Gm-Message-State: AGRZ1gJVS6iSTyTS1/oc80pmVURsUqhExrvwryOByt13b1w7A8u/M5VY osy3VkTqmPK+GiYUUFFmTtKCNHGuDeOeM09xxV8Qlk5nMHg=
X-Google-Smtp-Source: AFSGD/WKY+Fdnbj+vkCCD8Mzkq+Xbe9z1F+k8rPDThNfK8tAXVPIngntGraY7Zjac/yxR3hWCPmk9JeOS1DV+59qQbM=
X-Received: by 2002:a6b:5f14:: with SMTP id t20mr18046910iob.268.1542621795707; Mon, 19 Nov 2018 02:03:15 -0800 (PST)
MIME-Version: 1.0
References: <VI1PR0801MB211299BED6B61582DC33B873FACB0@VI1PR0801MB2112.eurprd08.prod.outlook.com> <CAGBSGjqHKVveZor-oKUWzsQ0Rg5Fk_d2dns_eQFqfvXJynyQaQ@mail.gmail.com> <9347fff8-f3b9-4ee9-84d3-5eebc8dd13f4@getmailbird.com> <309DAA7D-E9B9-4A89-B30E-5BE37DC6CC85@lodderstedt.net> <27627bee-aaab-44fd-9821-b58f7b33bc13@getmailbird.com> <7A852312-B129-4A0F-9914-8DC7E63FD12C@lodderstedt.net> <64a7f649-d2d8-4983-a564-5193adb4314a@getmailbird.com> <915498670.1574190.1542373190714@mail.yahoo.com> <A96E37F1-B09D-41C9-9F5F-DA7C133B00E2@lodderstedt.net> <57c8f36a-29dc-0365-af4f-96282e253702@connect2id.com>
In-Reply-To: <57c8f36a-29dc-0365-af4f-96282e253702@connect2id.com>
From: Hans Zandbelt <hans.zandbelt@zmartzone.eu>
Date: Mon, 19 Nov 2018 11:03:04 +0100
Message-ID: <CA+iA6ugTpEAZe22=uwb31x+F2zVVdM9wUHrar1eiL6UO5e9xuw@mail.gmail.com>
To: Vladimir Dzhuvinov <vladimir@connect2id.com>
Cc: "oauth@ietf.org" <oauth@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000002802a4057b01a0e0"
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/a02V4XO6KcZXzamHcg8q948Zdts>
Subject: Re: [OAUTH-WG] draft-parecki-oauth-browser-based-apps-00
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Nov 2018 10:03:19 -0000

+1 to the suggestions that Vladimir raises; I've seen a fair number of
requests  in the field for exactly that

Hans.

On Mon, Nov 19, 2018 at 10:59 AM Vladimir Dzhuvinov <vladimir@connect2id.com>
wrote:

> On 17/11/2018 13:26, Torsten Lodderstedt wrote:
>
> To start with, the AS may use refresh token rotation in combination with automatic revocation in case of detected replay attempts.
>
> How does it work? The AS issues a new refresh token with every refresh and invalidate the old one. This restricts the lifetime of a refresh token. If someone (might be the legit client or an attacker) submits one of the older, invalidated refresh token, the AS might interpret this as a signal indicating token leakage and revoke the valid refresh token as well. We used this technique at Deutsche Telekom since our first OAuth 2.0 implementation back in 2012.
>
> This is a clever solution. Did you experience any false positives, e.g.
> due to HTTP response timeouts on slow / poor connections?
>
> We were also thinking of additionally binding the refresh token to the
> end-user session at the AS / OP:
>
>    - A valid refresh causing the session to be refreshed too
>    - AS / OP logout or session expiration invalidating the refresh token
>
>
> Vladimir
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth
>


-- 
hans.zandbelt@zmartzone.eu
ZmartZone IAM - www.zmartzone.eu