[OAUTH-WG] Threat Document (new revision)

Torsten Lodderstedt <torsten@lodderstedt.net> Sun, 12 August 2012 07:21 UTC

Return-Path: <torsten@lodderstedt.net>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D7CCC11E80DC for <oauth@ietfa.amsl.com>; Sun, 12 Aug 2012 00:21:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.249
X-Spam-Level:
X-Spam-Status: No, score=-2.249 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, HELO_EQ_DE=0.35]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QO2R7wp6bvf7 for <oauth@ietfa.amsl.com>; Sun, 12 Aug 2012 00:21:04 -0700 (PDT)
Received: from smtprelay05.ispgateway.de (smtprelay05.ispgateway.de [80.67.31.94]) by ietfa.amsl.com (Postfix) with ESMTP id 4F90911E80D5 for <oauth@ietf.org>; Sun, 12 Aug 2012 00:21:03 -0700 (PDT)
Received: from [91.2.84.120] (helo=[192.168.71.42]) by smtprelay05.ispgateway.de with esmtpsa (TLSv1:AES256-SHA:256) (Exim 4.68) (envelope-from <torsten@lodderstedt.net>) id 1T0STt-0001QT-5u; Sun, 12 Aug 2012 09:21:01 +0200
Message-ID: <50275959.2000406@lodderstedt.net>
Date: Sun, 12 Aug 2012 09:20:57 +0200
From: Torsten Lodderstedt <torsten@lodderstedt.net>
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:14.0) Gecko/20120713 Thunderbird/14.0
MIME-Version: 1.0
To: OAuth WG <oauth@ietf.org>, Mark Mcgloin <mark.mcgloin@ie.ibm.com>, Phil Hunt <phil.hunt@oracle.com>
Content-Type: text/plain; charset="ISO-8859-15"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Df-Sender: dG9yc3RlbkBsb2RkZXJzdGVkdC1vbmxpbmUuZGU=
Subject: [OAUTH-WG] Threat Document (new revision)
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 12 Aug 2012 07:21:05 -0000

Hi all,

this is to let you know we are working towards a new revision of the 
"OAuth 2.0 Threat Model and Security Considerations". It will cover 
token substitution and some editorial comments raised during IETF review.

regards,
Torsten.