Acknowledgement of the OAuth security issue
I wanted to acknowledge that we are aware of a security threat first reported on by CNET that affects the OAuth protocol.
There have been no known exploits so far and for the past several days the OAuth community has been coordinating a response with as many known providers as possible to help them understand the threat and deploy whatever mitigating factors they can.
We’d like to publicly show our appreciation for Twitter’s role in helping to minimize premature publicity of this threat, even at its own expense, taking the heat as if it was their own issue in order to allow other companies to address this threat.
We ask that people refrain from speculating about or publicly discussing the actual details of this or other threats before we have released an official statement this evening at midnight, PST on the OAuth website.
If you have any immediate concerns, please contact the vendors or Eran Hammer-Lahav directly at 408 596 1974 or eran@hueniverse.com (he is the community coordinator for this threat).
About this entry
You’re currently reading “Acknowledgement of the OAuth security issue,” an entry on OAuth
- Published:
- April 22, 2009 / 3:20 pm
- Category:
- security
- Tags:
14 Comments
Jump to comment form | comment rss [?] | trackback uri [?]