Federated Identity

Google Whistles While OAuth Burns — ‘MultiLogin’ 0-Day is 70+ Days Old
Richi Jennings | | access-token-manipulation, authentication token, Business Associate Agreements, Chrome, chrome 0-day, chrome phishing, Chrome Security, Chromium, Chromium-Based Browsers, Federated Identity, federated sso, google, Google Account, google account security, Google Advanced Protection, infostealer, infostealers, OAuth, oauth 2.0, oauth abuse, Oauth Application Abuse, oauth refresh token, OAuth Token Vunerability, Prisma, Protecting OAuth Tokens, SB Blogwatch, securing oauth
What a Mickey Mouse operation: Infostealer scrotes having a field day with unpatched vulnerability ...
Security Boulevard

Legal Hazards of Federated Identity
Michael Mongold | | Federated Identity, Federation, Identification Process, identity, liability, Michael Mongold, personal information, Scope of Assertion, Use of Assertion
Beyond the technical complexities of Identity Federation, Thomas Smedinghoff explains what is truly holding back wider-spread adoption of federated identification models. “’Who are you?’ is a fundamental question for all online business ...