Risks With OpenID

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

1 comments

Comments 1 - 1 of 1 previous next Post a comment

Post a comment
Embed Video
Edit your comment Cancel

2 Favorites

Risks With OpenID - Presentation Transcript

  1. Risks with OpenID Remember, with great comfort . comes great security risk . – Spiderman style ;)
  2. What is OpenID (wikipedia)
    • OpenID is a shared identity service, which allows Internet users to log on to many different web sites using a single digital identity. Eliminating the need for a different user name and password for each site.
    • OpenID is a decentralized, free and open standard that lets users control the amount of personal information they provide.
    • Easy for user
    • Complex to implement
    • Not so difficult to do phishing
    • You loose one ID and you loose complete web.
    • Remember single username and password for many sites
    • Need not create a new account on a new site, use the same everywhere (mostly)
    • Allow timed access
      • Allow site X to use this authentication from date ‘a’ till date ‘b’
    Benefits
  3. Popular OpenID providers
    • Flickr : http://www.flickr.com/photos/ username
    • Verisign : http:// username .pip.verisignlabs.com/
    • Technorati : http://technorati.com/people/technorati/ username
    • Blogger : http:// blogname .blogspot.com
    • Wordpress : http:// username .wordpress.com
    • & now
    • Google : https://www.google.com/accounts/o8/id?id= username
    • its actually not an OpenID  read here
  4. Risks with OpenID
    • Phishing Attacks
    • Probably the biggest concern with OpenID. Users may be tricked into providing their credentials to phished OpenID provider website.
    • This site might look like your original OpenID provider and you might loose your password for all the services affiliated to OpenID
  5. Risks with OpenID… (contd)
    • Man-in-the-middle Attacks
    • If the connection is negotiated over weak encryption then it is subjected to interception attacks.
    • Ensure that you are using HTTPS and you know how to use HTTPS safely 
  6. Risks with OpenID… (contd)
    • Replay Attacks
    • The URL from the relaying party can be sniffed, unless over HTTPS, and as such being replayed.
    • Solution again is HTTPS
  7. Risks with OpenID… (contd)
    • CSRF (Cross-site request forgery) Attacks
    • Once the victim is logged in malicious user might be able to execute CSRF attacks against other sites.
    • Oops… ;(
    • <iframe id=&quot;login&quot; src=&quot; http://bank.com/login?openid_url = user.openid.net &quot; width=&quot;0&quot; height=&quot;0&quot;></iframe>
  8. Risks with OpenID… (contd)
    • XSS Attacks
    • Once the user is logged in attackers might be able to execute a series of XSS (Cross-site scripting) attacks against the identity provider, in which case they will be able to hijack the entire on-line use presence.
    • If attacker can do it through OpenID then why not?
  9. Not against OpenID
    • No I’m not at all against OpenID.
    • It’s a great idea and will make online life lot more easier.
    • User must be aware of safe usage.
    • Implementers should take care of most of the security risk.
  10. Recommendation
    • NEVER EVER use OpenID or Single-Sign-On for banks or credit cards
    • Always use HTTPS and know how to use it safely
    • Better be paranoid than sorry  like the condom ad “better safe than worry”
  11. Further reading
    • OpenID security issues
      • http://www.thespanner.co.uk/2007/06/29/openid-security-issues/
    • OpenID: Phishing Heaven
      • http://www.links.org/?p=187
    • OpenID: Phishing Heaven II
      • http://www.links.org/?p=188
    • Problems with OpenID
      • http://idcorner.org/2007/08/22/the-problems-with-openid/
    • Phishing risk
      • http://stii.za.net/semanticweb/openid-phishing-risks-be-careful/
    • Solving phishing problem
      • http://simonwillison.net/2007/Jan/19/phishing/
  12. Confused???
    • Drop me a mail
    • rohit@ club hack .com
    • I MIGHT be able to help you 

+ Rohit SrivastwaRohit Srivastwa, 2 years ago

custom

1804 views, 2 favs, 6 embeds more stats

clubhack advisory on OpenID

More info about this document

© All Rights Reserved

Go to text version

  • Total Views 1804
    • 1705 on SlideShare
    • 99 from embeds
  • Comments 1
  • Favorites 2
  • Downloads 30
Most viewed embeds
  • 45 views on http://rohit11.blogspot.com
  • 38 views on http://punetech.com
  • 11 views on http://blog.rohit11.com
  • 3 views on http://blogs.siliconindia.com
  • 1 views on http://www.blogger.com

more

All embeds
  • 45 views on http://rohit11.blogspot.com
  • 38 views on http://punetech.com
  • 11 views on http://blog.rohit11.com
  • 3 views on http://blogs.siliconindia.com
  • 1 views on http://www.blogger.com
  • 1 views on http://www.siliconindia.com

less

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel
File a copyright complaint
Having problems? Go to our helpdesk?

Categories