6 ms·
The first vulnerability is in the title, OAuth is an Authorization framework (Open Authorization) and is explicitly NOT for authentication. It’s also a delegati
by vwpolo3 6y ago
The first vulnerability is in the title, OAuth is an Authorization framework (Open Authorization) and is explicitly NOT for authentication. It’s also a delegation protocol (I give you something to do on my behalf).
If you want a list of things that can go wrong, look here: https://tools.ietf.org/id/draft-ietf-oauth-security-topics-10.html https://tools.ietf.org/id/draft-ietf-oauth-security-topics-1...
Generally you probably do not need OAuth2: https://www.ory.sh/hydra/docs/concepts/before-oauth2/ https://www.ory.sh/hydra/docs/concepts/before-oauth2/
But if you do don’t roll your own but use proven open source like https://github.com/ory/hydra https://github.com/ory/hydra
- k__ 6y agoInteresting, I always thought it was the other way around. It would authenticate who you are, but you have authorize the people yourself later.
- babelfish 6y agoOpenID Connect is built on top of OAuth2 and is the recommended solution for authentication.
- based2 6y ago-> OAuthz (vs authn)
- iecheruo 6y agoFrom the article: > OAuth authentication > Although not originally intended for this purpose, OAuth has evolved into a means of authenticating users as well.
- UncleMeat 6y agoIn fact, there id say that the huge majority of oauth flows on the web are used for authentication at this point.
- caseysoftware 6y agoTo be more precise, the flows are used to initiate authentication. They do not actually perform it.
- tptacek 6y agoIf you mean, like, logging into things with Google, sure, but isn't that technically OIDC? If you mean to say "most OAuth is used for OIDC, and is thus authentication", that's a different and less interesting claim. If instead you're saying that vanilla OAuth is primarily used for authentication, you're saying something more interesting (and problematic). You can use vanilla OAuth to log in, but you're adding a particularly subtle class of possible flaws in your design by doing so.
- UncleMeat 6y agoI mean the former. The primary use case of oauth on the modern web is to support openid connect. So much so that I expect it'll be a "SSL vs TLS" thing in the future where we actually use "oauth" to refer to the entire openid connect flow.
- tptacek 6y agoSure, OK. But this article really thinking about OAuth authentication in terms of OAuth itself, not OIDC. The dominant use of TCP on the Internet is (I hope?) to fetch URLs, but HTTP is not TCP. :)
- ddek 6y agoThe OAuth 2.0 RFC specifies the 'password' grant type, where the user provides the username and password directly. I'd contest the claim that OAuth was not intended for authentication, because there are no authz uses for the password grant.
- tptacek 6y agoIt famously wasn't intended for authentication, which is why OIDC was developed on top of it. Trying to run a delegated authorization protocol as an authentication protocol caused vulnerabilities. There are obvious authz uses for the password grant: you use it when you want to delegate access to a client running on your desktop, which is in your custody, and there's no point in running a multi-legged authorization protocol because you can just log the client in yourself. Your first thought about that might be "that's authentication", but it's not: you don't have to give all-or-nothing access (in theory) to such a client.
- dwaite 6y agoOAuth 2.0 password grant can be (mis)used for authentication the same way that LDAP Bind is used for authentication. That doesn't make either of them an authentication protocol.
- jjeaff 6y agoI've been seeing more and more apps and websites have me login with my xyz app login info. Then, ask if it's ok to grant access to xyz app so it can access xyz app information. Makes sense only if you are a developer. You are granting the frontend access to the backend via oauth. Completely confusing for everyone else and was pretty confusing for me at first as well.
- JoBrad 6y agoCounterpoint: although SSN was not intended as a means of identification, it evolved into being used that way.
- oauea 6y agoNice, that page and your post is basically an ad. You don't need a proven open standard, you need our custom protocol instead!
- pmh 6y agoFrom a quick glance, it doesn't look like a protocol per se, but a user management system akin to Keycloak. Those solve a slightly different set of problems than OIDC or OAuth
- vwpolo3 6y agoIt explains why OAuth2 is hard to use and does not solve login, registration, sessions, profile management, mfa, and proposes another solution. It’s all open source! :)
- mooreds 6y agoIt is designed for authorization but as sibling comments have said, it is very often used for authentication. Even though good old RFC 6749 says nothing about the details of authentication and leaves the nitty gritty of that to the Authorization server. But almost every OAuth server I'm aware of has some kind of authentication functionality. 100% agree that you should not roll your own. There are lots and lots of options out there with different strengths and weaknesses. Determine what you need and then find the right solution (which may be hydra or something else).
- dwaite 6y agoRFC 6749 does not contain any to verify tokens are usable for authentication, and is insecure (and has been exploited) when used for authentication on its own. You have extensions like Facebook Connect or OpenID Connect which add on the additional technology and client steps to allow it to be used securely for authentication. The title is wrong because those involved in the standardization of OAuth 2.0 have yelled from the very beginning not to use it for authentication, but instead use something that builds authentication on top of it.
- Osiris 6y agoYour first link calls the specification "Open Authentication" which seems to contradict your statement that it's called "Open Authorization".
- vwpolo3 6y agoThat looks like a mistake in the doc: - https://oauth.net/articles/authentication/ https://oauth.net/articles/authentication/ - https://tools.ietf.org/html/rfc6749 https://tools.ietf.org/html/rfc6749 - The OAuth 2.0 Authorization Framework
- mwcampbell 6y agoI'm currently trying to decide if OAuth is overkill for something I'm working on: a first-party browser extension for a SaaS. The extension needs to authenticate the user with the SaaS on installation, then make API calls to the SaaS on the user's behalf. In theory, OAuth is a good idea because it's a standard, as opposed to some ad-hoc system that I cook up myself. But if I try to use an off-the-shelf OAuth provider implementation in the SaaS, it's obvious that I'm not using it for its intended purpose, because when a user goes through the OAuth authorization flow, they get a screen asking whether they authorize the app to access the service. But in the user's mind, the app (the browser extension) is part of the service. So, does that just mean I need to tweak the OAuth provider? Or is this a hint that I should go with a simpler solution?
- hirsin 6y agoSo called "first party apps", those that are first party to the IDP, can often be considered as pre-consented. So the consent can be skipped - it's why you don't need to consent to use Excel or Gmail.
- throwbacktictac 6y agoI think it make sense to have a oAuth service for it. Like you said, it standard and straight forward. If you will have third party consume your users API you won't have to put too much effort into coming up with a different scheme. google and TDAmeritrade authenticate their 1st party services with oAuth and it logically makes sense to me.
- TriNetra 6y agoYou can use HMAC [0]. Create a UI to collect username/password and make an API call to login endpoint, which should return sessionId/secret. going forward sign API requests using the HMAC protocol without ever revealing the secret on the wire again. 0: https://aspsecuritykit.net/guides/implementing-hmac-scheme-to-protect-api-requests/ https://aspsecuritykit.net/guides/implementing-hmac-scheme-t...
- ec109685 6y agoNest does this. When you auth with Google, it asks for consent, even though they are owned by same company. Agree below though on preconsent.
- TriNetra 6y agoIn reality, most of the applications are using it for authentication: to identify who you are using your GitHub, FaceBook or Google account. Authorization is the process of determining whether the identity can perform the specified action on the specified data [0]; such social logins provide close to no real options to users to specify this aspect. 0: https://aspsecuritykit.net/guides/designing-activity-based-data-aware-authorization/ https://aspsecuritykit.net/guides/designing-activity-based-d...