<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Acknowledgement of the OAuth security issue</title>
	<atom:link href="http://blog.oauth.net/2009/04/22/acknowledgement-of-the-oauth-security-issue/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.oauth.net/2009/04/22/acknowledgement-of-the-oauth-security-issue/</link>
	<description>An open protocol to allow secure API authorization in a simple and standard method from web, desktop, and mobile applications.</description>
	<lastBuildDate>Mon, 04 Jan 2010 06:09:31 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Peter Keane's Miscellanea &#183; Layers</title>
		<link>http://blog.oauth.net/2009/04/22/acknowledgement-of-the-oauth-security-issue/#comment-173</link>
		<dc:creator>Peter Keane's Miscellanea &#183; Layers</dc:creator>
		<pubDate>Mon, 04 Jan 2010 06:09:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.oauth.net/?p=67#comment-173</guid>
		<description>[...] that allows two separate services to interoperate. Maybe not seamlessly and perhaps not without the occassionaly glitch, but ultimately it works and the results can be astonishing (cf. THE [...]</description>
		<content:encoded><![CDATA[<p>[...] that allows two separate services to interoperate. Maybe not seamlessly and perhaps not without the occassionaly glitch, but ultimately it works and the results can be astonishing (cf. THE [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: A Fire Eagle updater for Windows Mobile &#171; dale lane</title>
		<link>http://blog.oauth.net/2009/04/22/acknowledgement-of-the-oauth-security-issue/#comment-169</link>
		<dc:creator>A Fire Eagle updater for Windows Mobile &#171; dale lane</dc:creator>
		<pubDate>Thu, 13 Aug 2009 21:53:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.oauth.net/?p=67#comment-169</guid>
		<description>[...] the security threat identified in OAuth last April, OAuth providers have got even more cautious, and the updated OAuth protocol is even more [...]</description>
		<content:encoded><![CDATA[<p>[...] the security threat identified in OAuth last April, OAuth providers have got even more cautious, and the updated OAuth protocol is even more [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: a walking city &#187; Blog Archive &#187; Java, OAuth, Signpost</title>
		<link>http://blog.oauth.net/2009/04/22/acknowledgement-of-the-oauth-security-issue/#comment-168</link>
		<dc:creator>a walking city &#187; Blog Archive &#187; Java, OAuth, Signpost</dc:creator>
		<pubDate>Sun, 28 Jun 2009 05:48:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.oauth.net/?p=67#comment-168</guid>
		<description>[...] with a number of services, including Twitter and using the new OAuth 1.0a spec that addresses the vulnerability found in the OAuth spec [...]</description>
		<content:encoded><![CDATA[<p>[...] with a number of services, including Twitter and using the new OAuth 1.0a spec that addresses the vulnerability found in the OAuth spec [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Web API a bezpečnosť</title>
		<link>http://blog.oauth.net/2009/04/22/acknowledgement-of-the-oauth-security-issue/#comment-167</link>
		<dc:creator>Web API a bezpečnosť</dc:creator>
		<pubDate>Tue, 16 Jun 2009 16:37:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.oauth.net/?p=67#comment-167</guid>
		<description>[...] užívateľa). Dnes už Twitter podporuje aj oveľa lepší OAuth, v ktorom bolo len nedávno objavená bezpečnostná zraniteľnosť, čo viedlo k dočasnému odstaveniu protokolu. Napriek tomu je tento protokol ďaleko [...]</description>
		<content:encoded><![CDATA[<p>[...] užívateľa). Dnes už Twitter podporuje aj oveľa lepší OAuth, v ktorom bolo len nedávno objavená bezpečnostná zraniteľnosť, čo viedlo k dočasnému odstaveniu protokolu. Napriek tomu je tento protokol ďaleko [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: airkart</title>
		<link>http://blog.oauth.net/2009/04/22/acknowledgement-of-the-oauth-security-issue/#comment-161</link>
		<dc:creator>airkart</dc:creator>
		<pubDate>Mon, 27 Apr 2009 04:25:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.oauth.net/?p=67#comment-161</guid>
		<description>Haha, that should be http://blog.ics.utsa.edu. Silly typos!</description>
		<content:encoded><![CDATA[<p>Haha, that should be <a href="http://blog.ics.utsa.edu" rel="nofollow">http://blog.ics.utsa.edu</a>. Silly typos!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: An update on the OAuth session fixation vulnerability &#171; OAuth</title>
		<link>http://blog.oauth.net/2009/04/22/acknowledgement-of-the-oauth-security-issue/#comment-157</link>
		<dc:creator>An update on the OAuth session fixation vulnerability &#171; OAuth</dc:creator>
		<pubDate>Sun, 26 Apr 2009 01:50:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.oauth.net/?p=67#comment-157</guid>
		<description>[...] OAuth An open protocol to allow secure API authentication in a simple and standard method from desktop and web applications.     &#171; Acknowledgement of the OAuth security&#160;issue [...]</description>
		<content:encoded><![CDATA[<p>[...] OAuth An open protocol to allow secure API authentication in a simple and standard method from desktop and web applications.     &laquo; Acknowledgement of the OAuth security&nbsp;issue [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: IT Blog</title>
		<link>http://blog.oauth.net/2009/04/22/acknowledgement-of-the-oauth-security-issue/#comment-154</link>
		<dc:creator>IT Blog</dc:creator>
		<pubDate>Sat, 25 Apr 2009 20:32:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.oauth.net/?p=67#comment-154</guid>
		<description>&lt;strong&gt;OAuth Problem...&lt;/strong&gt;

We’d like to publicly show our appreciation for Twitter’s role in helping to minimize premature publicity of this threat, even at its own expense, taking the heat as if it was their own issue in order to allow other companies to address this threat. 
...</description>
		<content:encoded><![CDATA[<p><strong>OAuth Problem&#8230;</strong></p>
<p>We’d like to publicly show our appreciation for Twitter’s role in helping to minimize premature publicity of this threat, even at its own expense, taking the heat as if it was their own issue in order to allow other companies to address this threat.<br />
&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Twitter Watch Out OAuth Has Security Problem with Exploits</title>
		<link>http://blog.oauth.net/2009/04/22/acknowledgement-of-the-oauth-security-issue/#comment-143</link>
		<dc:creator>Twitter Watch Out OAuth Has Security Problem with Exploits</dc:creator>
		<pubDate>Fri, 24 Apr 2009 21:49:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.oauth.net/?p=67#comment-143</guid>
		<description>[...] You can read more about this Security Advisory and Security Issue [...]</description>
		<content:encoded><![CDATA[<p>[...] You can read more about this Security Advisory and Security Issue [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: airkart</title>
		<link>http://blog.oauth.net/2009/04/22/acknowledgement-of-the-oauth-security-issue/#comment-142</link>
		<dc:creator>airkart</dc:creator>
		<pubDate>Fri, 24 Apr 2009 18:42:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.oauth.net/?p=67#comment-142</guid>
		<description>Chris,

Your post here and the followup on the OAuth site is a very good response explaining the session fixation attack. As a silver lining, it is worth pointing out that the fact that this attack was even detected shows OAuth is gaining traction (and the scrutiny that comes along for the ride).

For a &quot;quick fix&quot; to this issue, a post on http://blog.ics.utsa.edu/ covers how this particular attack can be mitigated.

Erhan</description>
		<content:encoded><![CDATA[<p>Chris,</p>
<p>Your post here and the followup on the OAuth site is a very good response explaining the session fixation attack. As a silver lining, it is worth pointing out that the fact that this attack was even detected shows OAuth is gaining traction (and the scrutiny that comes along for the ride).</p>
<p>For a &#8220;quick fix&#8221; to this issue, a post on <a href="http://blog.ics.utsa.edu/" rel="nofollow">http://blog.ics.utsa.edu/</a> covers how this particular attack can be mitigated.</p>
<p>Erhan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Top Posts &#171; WordPress.com</title>
		<link>http://blog.oauth.net/2009/04/22/acknowledgement-of-the-oauth-security-issue/#comment-141</link>
		<dc:creator>Top Posts &#171; WordPress.com</dc:creator>
		<pubDate>Fri, 24 Apr 2009 00:54:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.oauth.net/?p=67#comment-141</guid>
		<description>[...]  Acknowledgement of the OAuth security issue I wanted to acknowledge that we are aware of a security threat first reported on by CNET that affects the OAuth [...] [...]</description>
		<content:encoded><![CDATA[<p>[...]  Acknowledgement of the OAuth security issue I wanted to acknowledge that we are aware of a security threat first reported on by CNET that affects the OAuth [...] [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
