3 ms·
Everyone is asking themselves the same question. Parts of this attack were identified last year but the full scale was not appreciated by the people who identif
by theRazorBlade 17y ago
Everyone is asking themselves the same question. Parts of this attack were identified last year but the full scale was not appreciated by the people who identified some of the issues. Everyone assumed that good security practices will be enough. So yes, everyone just missed it, and probably would continue to miss it if it wasn't for some unique situation last week which I will share soon.
- lmea 17y agoI'm wondering if the novel usage of OAuth for single click login to twitter might have played a role in letting the vulnerability emerge, as in that case it seems a lot easier to trick someone to click on an OAuth-related link on some site different from the consumer. Looking at the protocol while thinking to the basic use case (authorizing API access to some consumer app) one tends to think that tricking a user to start the authorization step from outside the consumer could not be easy. But in this flow: http://apiwiki.twitter.com/Sign-in-with-Twitter http://apiwiki.twitter.com/Sign-in-with-Twitter the case 3 (user logged in to twitter) is really similar to the attack case, except that in attack the request would be to oauth/authorize instead of to oauth/authenticate...