Archive

tag: Open ID Connect

Events

Overview and Future Outlook of Trust Framework for Student IDs 

On May 17, 2012, the OpenID Foundation Japan's Student Identity Trust Framework WG held a seminar titled "Trust Framework Seminar Vol. 2: Let's Utilize Student IDs to Provide Online Student Discount Services," featuring Professor Motonori Nakamura of the National Institute of Informatics and Shingo Yamanaka of the OpenID Foundation Japan as speakers…

identity

Using plain OAuth 2.0 for authentication would create a security hole big enough to drive a car through.

A great article by John Bradley[1], stating that using OAuth 2.0's implicit grant flow for authentication creates a security hole big enough for a car to drive through. The comments are also worth reading. From what I've seen, it's completely broken. They'll have to fix the RP side, so they should probably just make a public announcement as soon as possible. I can't be bothered to contact everyone individually...