OpenID & OAuth:
security considerations

Arjan Scherpenisse, Mediamatic Lab
arjan@mediamatic.nl

February 2009

Agenda

OpenID

Protocol flow

Security: OpenID URL sanity check

Security issues: Crypto

Security: RP to IdP redirect

Security: Identity provider trust

Security: IdP to RP redirect

Security: misc

OAuth

OAuth security considerations

Concluding remarks