An update on the OAuth session fixation vulnerability

While the merits of several solutions to the OAuth session fixation vulnerability are still being hashed out on the wiki, I wanted to share the latest episode of theSocialWeb.tv, captured yesterday on location at Google’s headquarters in Mountain View, providing some background and technical details about the problem, as told by Eran Hammer-Lahav, who has been coordinating the community’s response.

Marshall Kirkpatrick of ReadWriteWeb also has a great write-up of the timeline of events that lead to the discovery of the issue, shedding more light on how quickly the community mobilized to confront this threat.


About this entry