4 ms·
Twitter's OAuth has a gaping security hole
- madmotive 17y agoWhat approaches do other OAuth providers take to this problem? Revoking all OAuth tokens on a password change/reset takes away a good chunk of the value that many people get from using OAuth.
- tomjen2 17y agoAgreed, but would it be difficult to have a checkbox marked "revoke all permissions to use my account from all applications" to the reset password menu?
- neilk 17y agoThat's overkill. Perhaps, one day, there will be a need to suspend all oAuth authorizations while a rogue app is identified.
- orblivion 17y agoEvery OAuth site has a "log in with Twitter" feature, correct? Maybe Twitter could organize things such that, when you change your password, you're automatically logged out of every OAuth site?
- oscardelben 17y agoThat's a feature, not a bug. In twitter as far as I remember you have the opportunity to revoke tokens yourself. It's definitely not a security hole.
- mooism2 17y agoIt's at the intersection of security and user experience. Changing your password because you think it's been compromised is a different use case from changing your password because you've been using it for years or forgotten it.
- cgranade 17y agoAt the risk of encouraging Yet Another Warning, would displaying a notice after changing passwords that sites are still authorized be a solution? I'd say that it should have links to more info and to the Connections page, but I despair of users giving up at any sign of warnings. As looking at the issues with that infamous little "lock" icon to indicate HTTPS shows, security and UX intersections are always difficult.
- mooism2 17y agoPossibly display a list of recently authorised sites (and when they were authorised), and make it easy to revoke them without going to another page. It's difficult because people don't expect another step after they've changed their password, and (I'd guess) wouldn't immediately understand the need for it. Perhaps the answer is Yet Another Configuration Setting: the default option revokes all site authorisations when you change your password; the alternate option allows (but forces) you to think about it.
- kwamenum86 17y agoMany people cannot understand the difference between a browser and an OS or the difference between Firefox and IE. How can we expect them to manage their OAuth tokens? When OAuth was first writtes many SITES did not even have it implemented correctly (Myspace is a notable example.) In general, having the average naive user administer any aspect of security beyond choosing a "secure" password is a naive expectation. You can't afford to have both parties acting naively when it comes to Internet security. For this (non-naive) audience, managing OAuth tokens makes sense and Twitter can afford to be naive. For the rest of the Internet audience this approach is probably more dangerous than convenient.
- genieyclo 17y agoSeriously though, why do all the security examples and scenarios always involve an Alice and a Bob? And why is Alice always the bad guy (or chick)?
- Nogwater 17y agohttp://en.wikipedia.org/wiki/Alice_and_Bob http://en.wikipedia.org/wiki/Alice_and_Bob
- deleted 17y ago[deleted]
- munctional 17y agoYou need to read Applied Cryptography.
- orblivion 17y agoJust like every programming example has a foo and a bar.
- cgranade 17y agoGood question. Where did Carol the cheater and Eve the eavesdropper get to?
- djb_hackernews 17y agoAlong the same lines, if you build a twitter app that uses Oauth and change the access from read to read/write the oauth tokens never change and won't work if you try to do a write operation. Even if you log out and log back in manually. More problematic the error is '401 - Unauthorized', blah. The work around recommended by Twitter? Register a new twitter app that is read/write from the get go. :(
- rabble 17y agoArgh, why do we vote up this crude sensationalist crap?
- digamber_kamat 17y agoI think it is possible to criticize in a more civilized and conversant manner. Moreover it is expected from users at HN.
- tptacek 17y agoCalling a person "crap" is uncivilized. Calling a story "crap" is just blunt.
- deleted 17y ago[deleted]
- tptacek 17y agoSummary: No it doesn't.
- orblivion 17y agoI guess I don't quite follow the logic here, though I'm not advanced in the ways of the web yet. When you connect to a site with OAth, doesn't it require that you a) sign in using Twitter or b) are already signed in using Twitter? I would think this is necessary, otherwise people with multiple Twitter accounts, each of which use the same OAuth site, would end up with a lot of confusion. So given this, Eva would have to a) sign in to Alice's Twitter account, which she can't do because Alice changed her password, or b) continue to be signed into Alice's Twitter account, while Alice changes her password, which would also be a security compromise of Twitter in general, no need to get into OAuth at that point. Did I crack this thing or did I miss something?