<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>OAuth &#187; security</title>
	<atom:link href="http://blog.oauth.net/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.oauth.net</link>
	<description>An open protocol to allow secure API authorization in a simple and standard method from web, desktop, and mobile applications.</description>
	<lastBuildDate>Mon, 11 May 2009 23:15:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.oauth.net' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/1a4269caa96cb29bb5d69d95d75bf778?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>OAuth &#187; security</title>
		<link>http://blog.oauth.net</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.oauth.net/osd.xml" title="OAuth" />
	<atom:link rel='hub' href='http://blog.oauth.net/?pushpress=hub'/>
		<item>
		<title>An update on the OAuth session fixation vulnerability</title>
		<link>http://blog.oauth.net/2009/04/25/an-update-on-the-oauth-session-fixation-vulnerability/</link>
		<comments>http://blog.oauth.net/2009/04/25/an-update-on-the-oauth-session-fixation-vulnerability/#comments</comments>
		<pubDate>Sun, 26 Apr 2009 01:50:13 +0000</pubDate>
		<dc:creator>Chris Messina</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[eran hammer-lahav]]></category>
		<category><![CDATA[thesocialweb.tv]]></category>

		<guid isPermaLink="false">http://blog.oauth.net/?p=69</guid>
		<description><![CDATA[While the merits of several solutions to the OAuth session fixation vulnerability are still being hashed out on the wiki, I wanted to share the latest episode of theSocialWeb.tv, captured yesterday on location at Google&#8217;s headquarters in Mountain View, providing some background and technical details about the problem, as told by Eran Hammer-Lahav, who has [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.oauth.net&#038;blog=1491687&#038;post=69&#038;subd=oauth&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[	      <object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" width="437" height="288" id="viddler_437"><param name="movie" value="http://www.viddler.com/player/b345c7b5/"/><param name="allowScriptAccess" value="always"/><param name="allowNetworking" value="all"/><param name="wmode" value=""/><param name="allowFullScreen"value="true"/><param name="flashVars" value="f=1&autoplay=f&disablebranding=f&liverailTags="/><embed src="http://www.viddler.com/player/b345c7b5/" width="437" height="288" type="application/x-shockwave-flash" wmode="" allowScriptAccess="always" allowFullScreen="true" allowNetworking="all" name="viddler_437" flashVars="f=1&autoplay=f&disablebranding=f&liverailTags="></embed></object>
<p>While the merits of <a href="http://wiki.oauth.net/Signed-Callback-URLs">several</a> <a href="http://wiki.oauth.net/Signed-Approval-URLs">solutions</a> to the <a href="http://blog.oauth.net/2009/04/22/acknowledgement-of-the-oauth-security-issue/">OAuth session fixation vulnerability</a> are still being hashed <a href="http://wiki.oauth.net/OAuth-Session-Fixation-Advisory">out on the wiki</a>, I wanted to share the <a href="http://www.thesocialweb.tv/blog/2009/04/oauth.html">latest episode</a> of <a href="http://www.thesocialweb.tv">theSocialWeb.tv</a>, captured yesterday on location at Google&#8217;s headquarters in Mountain View, providing some background and technical details about the problem, as told by <a href="http://hueniverse.com">Eran Hammer-Lahav</a>, who has been coordinating the community&#8217;s response.</p>
<p><a href="http://marshallk.com/">Marshall Kirkpatrick</a> of ReadWriteWeb also has a great write-up of the <a href="http://www.readwriteweb.com/archives/how_the_oauth_security_battle_was_won_open_web_sty.php" title="How the OAuth Security Battle Was Won, Open Web Style">timeline of events that lead to the discovery of the issue</a>, shedding more light on how quickly the community mobilized to confront this threat.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/oauth.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/oauth.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/oauth.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/oauth.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/oauth.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/oauth.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/oauth.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/oauth.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/oauth.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/oauth.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/oauth.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/oauth.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/oauth.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/oauth.wordpress.com/69/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.oauth.net&#038;blog=1491687&#038;post=69&#038;subd=oauth&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.oauth.net/2009/04/25/an-update-on-the-oauth-session-fixation-vulnerability/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8403e20f058363f718144dd51faa65a7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">factoryjoe</media:title>
		</media:content>
	</item>
		<item>
		<title>Acknowledgement of the OAuth security issue</title>
		<link>http://blog.oauth.net/2009/04/22/acknowledgement-of-the-oauth-security-issue/</link>
		<comments>http://blog.oauth.net/2009/04/22/acknowledgement-of-the-oauth-security-issue/#comments</comments>
		<pubDate>Wed, 22 Apr 2009 22:20:11 +0000</pubDate>
		<dc:creator>Chris Messina</dc:creator>
				<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.oauth.net/?p=67</guid>
		<description><![CDATA[I wanted to acknowledge that we are aware of a security threat first reported on by CNET that affects the OAuth protocol. There have been no known exploits so far and for the past several days the OAuth community has been coordinating a response with as many known providers as possible to help them understand [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.oauth.net&#038;blog=1491687&#038;post=67&#038;subd=oauth&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I wanted to <a href="http://groups.google.com/group/oauth/browse_thread/thread/20e12ace524dba3">acknowledge</a> that we are aware of a security threat first <a href="http://news.cnet.com/8301-13577_3-10225103-36.html">reported on</a> by CNET that affects the OAuth protocol.</p>
<p>There have been no known exploits so far and for the past several days the OAuth community has been coordinating a response with as many known providers as possible to help them understand the threat and deploy whatever mitigating factors they can.</p>
<p>We&#8217;d like to publicly show our appreciation for Twitter&#8217;s role in helping to minimize premature publicity of this threat, even at its own expense, <a href="http://www.techcrunch.com/2009/04/22/twitter-oauth-temporarily-disabled-leaves-developers-hanging/">taking the heat</a> <a href="http://blog.twitter.com/2009/04/whats-deal-with-oauth.html">as if it was their own issue</a> in order to allow other companies to address this threat. </p>
<p>We ask that people refrain from speculating about or publicly discussing the actual details of this or other threats before we have released an official statement this evening at midnight, PST on the <a href="http://oauth.net">OAuth website</a>.</p>
<p>If you have any immediate concerns, please contact the vendors or <a href="http://hueniverse.com">Eran Hammer-Lahav</a> directly at 408 596 1974 or <a href="mailto:eran@hueniverse.com">eran@hueniverse.com</a> (he is the community coordinator for this threat). </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/oauth.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/oauth.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/oauth.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/oauth.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/oauth.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/oauth.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/oauth.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/oauth.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/oauth.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/oauth.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/oauth.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/oauth.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/oauth.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/oauth.wordpress.com/67/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.oauth.net&#038;blog=1491687&#038;post=67&#038;subd=oauth&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.oauth.net/2009/04/22/acknowledgement-of-the-oauth-security-issue/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8403e20f058363f718144dd51faa65a7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">factoryjoe</media:title>
		</media:content>
	</item>
	</channel>
</rss>
