[saag] Re: Covert Web-to-App Tracking via Localhost
Tim Bray <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <CAHBU6isr2eq1dGOLbt9D29jfJPrwC_ZusqZUfmcB5rkgqZTXkA@mail.gmail.com> |
> > > Nico Williams <[email protected]> wrote: > > 1) as you say SAML/Oauth2/Webauthn/etc. are a mess, and they're not > > universally supported, > I missed this and want to disagree for the record: OIDC, which is OAuth2-based, is I think generally regarded as a success story, is widely deployed, is acceptably secure, and is reasonably implementer-friendly. (For those who don’t know, OAuth2 isn’t actually an auth protocol, it’s a framework you can build actual protocols like OIDC on top of.) A lot of security/cryptography experts hate OAuth2 because the specs (especially JWT’s) can be read as saying you have to support really bad practices (e.g. a NULL algorithm) to be fully conformant. Fortunately the industry has decent consensus on what the bad practices are and generally just avoids them. -T _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]