Chaos Computer Club - recent events feed

A wide variety of video material distributed by the Chaos Computer Club. This feed contains events from the last two years

//media.ccc.de/

subscribe
share






On the Security and Privacy of Modern Single Sign-On in the Web (33c3)


Many web sites allow users to log in with their Facebook or Google account. This so-called Web single sign-on (SSO) often uses the standard protocols OAuth and OpenID Connect. How secure are these protocols? What can go wrong?

OAuth and OpenID Connect do not protect your privacy at all, i.e., your identity provider (e.g., Facebook or Google) can always track, where you log in. Mozilla tried to create an authentication protocol that aimed to prevent tracking: BrowserID (a.k.a. Persona). Did their proposition really solve the privacy issue? What are the lessons learned and can we do better?

about this event: https://fahrplan.events.ccc.de/congress/2016/Fahrplan/events/7827.html


fyyd: Podcast Search Engine
share








 December 28, 2016  1h4m