[CNET New]Serious security flaw in OAuth, OpenID discovered

Maniaplanet public API, ManiaConnect system and the open source PHP SDK.

Moderator: NADEO

Post Reply
User avatar
niarfman
Posts: 287
Joined: 07 Dec 2012, 10:46

[CNET New]Serious security flaw in OAuth, OpenID discovered

Post by niarfman »

Hi Nadeo Team,

Are you aware about the security issue concerning oAuth ? Is ManiaConnect concerned ?

Source : http://www.cnet.com/news/serious-securi ... discovered

I have configured ManiaConnect with phpBB and I will soon share the source code of my work to the community. I hope there is no risk before ^^
Image
Ľѷҳ Choupa Oups! ツ
User avatar
Jojo_44
Posts: 485
Joined: 12 Jul 2010, 15:58
Location: Germany->Bavaria
Contact:

Re: [CNET New]Serious security flaw in OAuth, OpenID discove

Post by Jojo_44 »

There´s no problem with the Maniaplanet Web Service I think because they implemented the OAuth 2.0 standard which means you have to specify the domain of the redirect. And it´s not a security problem of OAuth or OpenId it´s because of wrong implementations of Facebook and co to make it easier for developers.

Jojo
Image
my english sounds very unfriendly but it isn´t ;)
User avatar
niarfman
Posts: 287
Joined: 07 Dec 2012, 10:46

Re: [CNET New]Serious security flaw in OAuth, OpenID discove

Post by niarfman »

I have understood the same, and I hope we are both right :D

But maybe others were wondering about that and the point of vue from Nadeo is interesting. 8-)
Image
Ľѷҳ Choupa Oups! ツ
User avatar
gouxim
Nadeo
Nadeo
Posts: 1186
Joined: 14 Jun 2010, 17:20

Re: [CNET New]Serious security flaw in OAuth, OpenID discove

Post by gouxim »

Jojo_44 wrote:There´s no problem [...] you have to specify the domain of the redirect.
True
Jojo_44 wrote:wrong implementations of Facebook and co to make it easier for developers
They aren't actually wrong implementations. Oauth2 rfc went through lots of drafts, and was pretty much abandonned in the end ; each provider implement a different version of the draft.

Edit: there is actually a final version (http://tools.ietf.org/html/rfc6749), so one might say they have wrong implemenations.
Please do not PM for support. Instead, create a thread so that everyone can contribute or benefit from the answer! 8-)
User avatar
niarfman
Posts: 287
Joined: 07 Dec 2012, 10:46

Re: [CNET New]Serious security flaw in OAuth, OpenID discove

Post by niarfman »

Great work from your end :1010

Thanks for your answer
Image
Ľѷҳ Choupa Oups! ツ
Post Reply

Return to “Maniaplanet Web Services”

Who is online

Users browsing this forum: No registered users and 2 guests