[saag] Re: Covert Web-to-App Tracking via Localhost

Tim Bray <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CAHBU6isr2eq1dGOLbt9D29jfJPrwC_ZusqZUfmcB5rkgqZTXkA@mail.gmail.com>
>
>
> Nico Williams <[email protected]> wrote:
>    > 1) as you say SAML/Oauth2/Webauthn/etc. are a mess, and they're not
>    > universally supported,
>

I missed this and want to disagree for the record: OIDC, which is
OAuth2-based, is I think generally regarded as a success story, is widely
deployed, is acceptably secure, and is reasonably implementer-friendly.
(For those who don’t know, OAuth2 isn’t actually an auth protocol, it’s a
framework you can build actual protocols like OIDC on top of.)

A lot of security/cryptography experts hate OAuth2 because the specs
(especially JWT’s) can be read as saying you have to support really bad
practices (e.g. a NULL algorithm) to be fully conformant. Fortunately the
industry has decent consensus on what the bad practices are and generally
just avoids them.

-T

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.