{"id":1532,"date":"2017-01-23T17:28:36","date_gmt":"2017-01-23T21:28:36","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=1532"},"modified":"2017-01-23T17:34:56","modified_gmt":"2017-01-23T21:34:56","slug":"1532-2","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/1532-2\/","title":{"rendered":"On the Security and Privacy of Modern Web SSO, Presentation from 33c3"},"content":{"rendered":"<p>https:\/\/youtu.be\/slxiQQC1SpY<\/p>\n<p style=\"text-align: justify\">Many websites allow users to log in with their Facebook or Google account. This web-based single sign-on (SSO), as it&#8217;s called, mostly uses the standard protocols such as OAuth and OpenID Connect, but how secure are these protocols? And what can go wrong?<\/p>\n<p style=\"text-align: justify\">In this 64-minute presentation from the 33rd Chaos Communication Congress (33c3), \u00a0an annual conference organized by the Chaos Computer Club in Hamburg, DE, speaker Guido Schmitz breaks down the\u00a0disadvantages of OAuth and OpenID Connect\u00a0and demonstrates what can go wrong with them.<\/p>\n<p style=\"text-align: justify\">Schmitz will also examine Mozilla&#8217;s proposed authentication protocol, BrowserID (a.k.a. Persona), and discuss whether their proposition really solved the privacy issue, the lessons learned and what we can do better.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>https:\/\/youtu.be\/slxiQQC1SpY Many websites allow users to log in with their Facebook or Google account. This web-based single sign-on (SSO), as it&#8217;s called, mostly uses the standard protocols such as OAuth and OpenID Connect, but how secure are these protocols? And what can go wrong? In this 64-minute presentation from the 33rd Chaos Communication Congress (33c3), [&hellip;]<\/p>\n","protected":false},"author":24,"featured_media":1533,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[7],"tags":[463,464,223,462,147,461,205],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>On the Security and Privacy of Modern Web SSO, Presentation from 33c3 - Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services<\/title>\n<meta name=\"description\" content=\"In this 64-minute presentation from the 33rd Chaos Communication Congress (33c3), \u00a0an annual conference organized by the Chaos Computer Club in Hamburg, DE, speaker Guido Schmitz breaks down the\u00a0disadvantages of OAuth and OpenID Connect\u00a0and demonstrates what can go wrong with them.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/1532-2\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jeff Edwards\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/1532-2\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/1532-2\/\",\"name\":\"On the Security and Privacy of Modern Web SSO, Presentation from 33c3 - Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/1532-2\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/1532-2\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2017\/01\/single-sign-on-presentation-17.png\",\"datePublished\":\"2017-01-23T21:28:36+00:00\",\"dateModified\":\"2017-01-23T21:34:56+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6\"},\"description\":\"In this 64-minute presentation from the 33rd Chaos Communication Congress (33c3), \u00a0an annual conference organized by the Chaos Computer Club in Hamburg, DE, speaker Guido Schmitz breaks down the\u00a0disadvantages of OAuth and OpenID Connect\u00a0and demonstrates what can go wrong with them.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/1532-2\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/1532-2\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/1532-2\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2017\/01\/single-sign-on-presentation-17.png\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2017\/01\/single-sign-on-presentation-17.png\",\"width\":850,\"height\":430},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/1532-2\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"On the Security and Privacy of Modern Web SSO, Presentation from 33c3\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services\",\"description\":\"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6\",\"name\":\"Jeff Edwards\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g\",\"caption\":\"Jeff Edwards\"},\"description\":\"Jeff Edwards is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in Journalism from the University of Massachusetts Amherst, and previously worked as a reporter covering Boston City Hall.\",\"sameAs\":[\"https:\/\/solutionsreview.com\",\"https:\/\/x.com\/InfoSec_Review\"],\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/jedwards\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"On the Security and Privacy of Modern Web SSO, Presentation from 33c3 - Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","description":"In this 64-minute presentation from the 33rd Chaos Communication Congress (33c3), \u00a0an annual conference organized by the Chaos Computer Club in Hamburg, DE, speaker Guido Schmitz breaks down the\u00a0disadvantages of OAuth and OpenID Connect\u00a0and demonstrates what can go wrong with them.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/1532-2\/","twitter_misc":{"Written by":"Jeff Edwards","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/1532-2\/","url":"https:\/\/solutionsreview.com\/identity-management\/1532-2\/","name":"On the Security and Privacy of Modern Web SSO, Presentation from 33c3 - Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/1532-2\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/1532-2\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2017\/01\/single-sign-on-presentation-17.png","datePublished":"2017-01-23T21:28:36+00:00","dateModified":"2017-01-23T21:34:56+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6"},"description":"In this 64-minute presentation from the 33rd Chaos Communication Congress (33c3), \u00a0an annual conference organized by the Chaos Computer Club in Hamburg, DE, speaker Guido Schmitz breaks down the\u00a0disadvantages of OAuth and OpenID Connect\u00a0and demonstrates what can go wrong with them.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/1532-2\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/1532-2\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/1532-2\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2017\/01\/single-sign-on-presentation-17.png","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2017\/01\/single-sign-on-presentation-17.png","width":850,"height":430},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/1532-2\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"On the Security and Privacy of Modern Web SSO, Presentation from 33c3"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","description":"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6","name":"Jeff Edwards","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g","caption":"Jeff Edwards"},"description":"Jeff Edwards is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in Journalism from the University of Massachusetts Amherst, and previously worked as a reporter covering Boston City Hall.","sameAs":["https:\/\/solutionsreview.com","https:\/\/x.com\/InfoSec_Review"],"url":"https:\/\/solutionsreview.com\/identity-management\/author\/jedwards\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/1532"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/24"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=1532"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/1532\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media\/1533"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=1532"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=1532"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=1532"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}