Vulnerability warning some OpenID 2.0 implementations contain security risks

Source: Internet
Author: User
Tags openid

Vulnerability warning released by the OpenID official organization: Some OpenID 2.0 certification implementations do not comply with OpenID Authentication 2.0 specifications, leading to security vulnerabilities.

Vulnerability nature:

In section 11.4.2.1 of the OpenID 2.0 specification, it is described: "The OP must be signed and not verified on the private association ." However, some OpenID implementations do not differentiate private associations and shared associations, and directly perform signature verification on the shared associations.

Vulnerability impact:

By carefully crafted signatures built on shared associations, any dependent Party (RP) can be associated with a vulnerable OP through sharing. This also allows attackers to easily log on to the RP.

How to check whether this vulnerability exists:

You can use the following website for verification:
Http://test-id.org/OP/CheckAuthSharedSecret.aspx

I hope this notification will attract the attention of the community.

Don Thibeau
Executive Director of OpenID Foundation

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.