From nobody Tue Nov  3 11:09:25 2020
Return-Path: <joseph@authlete.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id 72DB93A0100
 for <oauth@ietfa.amsl.com>; Tue,  3 Nov 2020 11:09:23 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.894
X-Spam-Level: 
X-Spam-Status: No, score=-1.894 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
 HTML_FONT_LOW_CONTRAST=0.001, HTML_IMAGE_ONLY_32=0.001,
 HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001,
 URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
 header.d=authlete-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id yE5WzGnF6Swv for <oauth@ietfa.amsl.com>;
 Tue,  3 Nov 2020 11:09:21 -0800 (PST)
Received: from mail-wm1-x333.google.com (mail-wm1-x333.google.com
 [IPv6:2a00:1450:4864:20::333])
 (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id CEB4D3A0D3A
 for <oauth@ietf.org>; Tue,  3 Nov 2020 11:09:08 -0800 (PST)
Received: by mail-wm1-x333.google.com with SMTP id d142so356910wmd.4
 for <oauth@ietf.org>; Tue, 03 Nov 2020 11:09:08 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=authlete-com.20150623.gappssmtp.com; s=20150623;
 h=from:message-id:mime-version:subject:date:in-reply-to:cc:to
 :references; bh=Y6IjfSSCGbTA+euPQFy/p5TCIU1Fb8btHrHfN3mhuLk=;
 b=0zG/m9vvbAGKnWwS8aUOcbbaYcUjUAgQO52uCXu3bJpOPVsnhto5TQgkg+KAZ92lFq
 cNusqg7uPIh6A4l11CqcKPda2Y+A7Ty2fD0lK9VmBXtRaq8zimhmzowpW8FTn8qi3qhN
 md6pFFXkNXNwGq3hyhYzsGMzWmDS3+CpwQ3ylFzFBU6NBM2mAlf8aNH2LIGwuVOPmYLd
 0JcvwZdElFbZ7O1nIi9MlOt1ShyrYLxkjMAjYQYGil2nc94OgagFFI+7BEdjjY2B6cyk
 dvyOpzroife0w1iUxdh0HZwZ3B5114wbZBVJS4OPgTbzwzp9RLFgphLfN933mZcbHOXD
 jklg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20161025;
 h=x-gm-message-state:from:message-id:mime-version:subject:date
 :in-reply-to:cc:to:references;
 bh=Y6IjfSSCGbTA+euPQFy/p5TCIU1Fb8btHrHfN3mhuLk=;
 b=ncXPuIn+MPRxG90iIW9IDbk2HbcvFW1t2Ac6patFzTzPBwL//I/F2vPXR/FtujHywp
 enAcVopERe6TGrwE/9I23SsyR9GZgbvg+ZXz3CpCuti5Hhtp3VSus/1yGBGRKOP4b1Nv
 Wrl+sEkPd39m+FceO5BS43aeCdJPJwP9ngFFozCwhdlU0tsB9KkpKP6lfxS5q4JRybrg
 nIer2Duu6a8XpOcXtQ3+VLFCXLnjCaXz/1liHaPaFTxnf+5J/7xKzzRitzsGe7b6UtRM
 +R7SR6sHoYHXGvxZPCXqFCN5KKiHAHOoqtaMvNj7fG3JWsEuPemRgh3an8A5oGI60S0j
 1wKQ==
X-Gm-Message-State: AOAM533nfFvY014GR+K3lYnRpdGc/qCKy/e5AU0icgfQsoWfruESBHX3
 2ghnCWZ0WsD344odD1iGwuQRmg==
X-Google-Smtp-Source: ABdhPJzYBgckhefTGYqV+N0DBroN8ZxeQoSBMKvx7URb8FgR0snqqjnTpGn9LD3AhYVuJaCRdNAhmQ==
X-Received: by 2002:a1c:9d94:: with SMTP id g142mr694974wme.66.1604430546050; 
 Tue, 03 Nov 2020 11:09:06 -0800 (PST)
Received: from dhcp121.sh2.org.uk (home.heenan.me.uk. [212.159.108.133])
 by smtp.gmail.com with ESMTPSA id z5sm27310274wrw.87.2020.11.03.11.09.05
 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
 Tue, 03 Nov 2020 11:09:05 -0800 (PST)
From: Joseph Heenan <joseph@authlete.com>
Message-Id: <65B3EF09-25F4-4F3E-96DD-05FA60F044D0@authlete.com>
Content-Type: multipart/alternative;
 boundary="Apple-Mail=_2366112A-8B23-42F3-B891-2A22A73F908C"
Mime-Version: 1.0 (Mac OS X Mail 13.4 \(3608.120.23.2.4\))
Date: Tue, 3 Nov 2020 19:09:04 +0000
In-Reply-To: <CAD9ie-tixMTAbPOtzPUjZdM7oa6_Rw2Gfbup2NQHUHJMu9LBTg@mail.gmail.com>
Cc: oauth <oauth@ietf.org>
To: Dick Hardt <dick.hardt@gmail.com>
References: <CAD9ie-tixMTAbPOtzPUjZdM7oa6_Rw2Gfbup2NQHUHJMu9LBTg@mail.gmail.com>
X-Mailer: Apple Mail (2.3608.120.23.2.4)
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/gvVUZ28xyheY2GT_HlOzbeSK6YU>
Subject: Re: [OAUTH-WG] Android App Links (AKA Universal Links)
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>,
 <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>,
 <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 03 Nov 2020 19:09:23 -0000


--Apple-Mail=_2366112A-8B23-42F3-B891-2A22A73F908C
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Hi Dick

I didn=E2=80=99t attend the call so don=E2=80=99t know the background of =
this and the exact situation, but the general problem is mostly where =
the Authorization Server=E2=80=99s app is *not* installed. In that case =
Android falls back to much weaker mechanisms that allow other apps to =
get a look in. App links also aren=E2=80=99t consistently supported =
across all commonly used android browsers which causes further problems.

In general to do app2app oauth redirections securely on Android it=E2=80=99=
s necessary for both apps to fetch the /.well-known/assetlinks.json for =
the url they want to redirect to, and verify that the intent the app =
intends to launch to handle the url is signed using the expected =
certificate. Web2app flows are trickier, on both iOS and on Android. =
There were lengthy discussions on at least the Android case at OAuth =
Security Workshop this year (recordings available).

Joseph


> On 20 Oct 2020, at 00:09, Dick Hardt <dick.hardt@gmail.com> wrote:
>=20
> Hey Vittorio
>=20
> (cc'ing OAuth list as this was brought up in the office hours today)
>=20
> https://developer.android.com/training/app-links =
<https://developer.android.com/training/app-links>
>=20
> An app is the default handler and the developer has verified ownership =
of the HTTPS URL. While a user can override the app being the default =
handler in the system settings -- I don't see how a malicious app can be =
the default setting.
>=20
> What am I missing?
>=20
> /Dick
> =E1=90=A7
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth


--Apple-Mail=_2366112A-8B23-42F3-B891-2A22A73F908C
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D"">Hi =
Dick<div class=3D""><br class=3D""></div><div class=3D"">I didn=E2=80=99t =
attend the call so don=E2=80=99t know the background of this and the =
exact situation, but the general problem is mostly where the =
Authorization Server=E2=80=99s app is *not* installed. In that case =
Android falls back to much weaker mechanisms that allow other apps to =
get a look in. App links also aren=E2=80=99t consistently supported =
across all commonly used android browsers which causes further =
problems.</div><div class=3D""><br class=3D""></div><div class=3D"">In =
general to do app2app oauth redirections securely on Android it=E2=80=99s =
necessary for both apps to fetch the /.well-known/assetlinks.json for =
the url they want to redirect to, and verify that the intent the app =
intends to launch to handle the url is signed using the expected =
certificate. Web2app flows are trickier, on both iOS and on Android. =
There were lengthy discussions on at least the Android case at OAuth =
Security Workshop this year (recordings available).</div><div =
class=3D""><br class=3D""></div><div class=3D"">Joseph</div><div =
class=3D""><br class=3D""><div><br class=3D""><blockquote type=3D"cite" =
class=3D""><div class=3D"">On 20 Oct 2020, at 00:09, Dick Hardt &lt;<a =
href=3D"mailto:dick.hardt@gmail.com" =
class=3D"">dick.hardt@gmail.com</a>&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><div dir=3D"ltr" =
class=3D"">Hey Vittorio<div class=3D""><br class=3D""></div><div =
class=3D"">(cc'ing OAuth list as this was brought up in the office hours =
today)</div><div class=3D""><br class=3D""></div><div class=3D""><a =
href=3D"https://developer.android.com/training/app-links" =
class=3D"">https://developer.android.com/training/app-links</a><br =
class=3D""></div><div class=3D""><br class=3D""></div><div class=3D"">An =
app is the default handler and the developer has verified ownership of =
the HTTPS URL. While a user can override the app being the default =
handler in the system settings -- I don't see how a malicious app can be =
the default setting.</div><div class=3D""><br class=3D""></div><div =
class=3D"">What am I missing?</div><div class=3D""><br =
class=3D""></div><div class=3D"">/Dick</div></div><div =
hspace=3D"streak-pt-mark" style=3D"max-height:1px" class=3D""><img =
alt=3D"" style=3D"width:0px;max-height:0px;overflow:hidden" =
src=3D"https://mailfoogae.appspot.com/t?sender=3DaZGljay5oYXJkdEBnbWFpbC5j=
b20%3D&amp;type=3Dzerocontent&amp;guid=3D753a4eae-4c54-40f0-a603-09ea6cdfe=
434" class=3D""><font color=3D"#ffffff" size=3D"1" =
class=3D"">=E1=90=A7</font></div>
_______________________________________________<br class=3D"">OAuth =
mailing list<br class=3D""><a href=3D"mailto:OAuth@ietf.org" =
class=3D"">OAuth@ietf.org</a><br =
class=3D"">https://www.ietf.org/mailman/listinfo/oauth<br =
class=3D""></div></blockquote></div><br class=3D""></div></body></html>=

--Apple-Mail=_2366112A-8B23-42F3-B891-2A22A73F908C--

