The Register® — Biting the hand that feeds IT

Feeds

Twitter fanatic glimpses dark side of OAuth

'Secure' authentication can be anything but

  • print
  • alert

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

A mobile enthusiast and professional internet strategist got a glimpse of OAuth's dark side recently when he received an urgent advisory from Twitter.

The dispatch, generated when Terence Eden tried to log in, said his Twitter account may have been compromised and advised he change his password. After making sure the alert was legitimate, he complied.

That should have been the end of it, but it wasn't. It turns out Eden used OAuth to seamlessly pass content between third-party websites and Twitter, and even after he had changed his Twitter password, OAuth continued to allow those websites access to his account.

"Unless you revoke these tokens when you change your password, a malicious user will still have access to your twitter account," said Eden, who tackles customer usability issues for a large telecommunications company. "Twitter doesn't make that wonderfully clear."

In theory, OAuth is supposed to enhance security by eliminating the need to share Twitter login credentials with other sites. The problem is that the tokens the service uses to authenticate users have to be manually reset. Attackers who get their hands on the tokens of a compromised account will continue to have access to the account long after the user has changed his password.

Eden alternately describes this as a "gaping security hole" and a "usability issue which has strong security implications." Whatever the case, the responsibility seems to lie with Twitter.

If the service is concerned enough to advise a user to change his password, you'd think it would take the added trouble of suggesting he also reset his OAuth credentials, as Google, which on Wednesday said it was opening its own services to work with OAuth, notes here. ®

Agentless Backup is Not a Myth

Latest Comments

Complaints against convenience

So, once again we have convenience weighted against security, and a person from one side finds it lacking. How is this different from (other) centralized authentication schemes?

If you are upset that changing your password means that you DON'T have to go around to each and every other site you visited and update the credentials there, why use a centralized scheme to begin with?

0
0
Anonymous Coward

Token trouble

Good to see people reinventing the wheel. There was this thing called kerberos once (ok, there still is), and there too people had to manage the "ticket granting ticket". Don't think they ever got around to automating that in a meaningful way, except automatically destroying it when done. Oh, and understanding that it had to reside on a trusted machine (your workstation), not some third party website. Here, well, I think they looked at it and perhaps gotten it ever so slightly wrong. Or they didn't look at it at all and gotten it ever so slightly wrong. Much like openid, really. Privacy? Hah.

0
0
Anonymous Coward

No shit, Sherlock

"Unless you revoke these tokens when you change your password, a malicious user will still have access to your twitter account,"

Well, yes. That's what it's for.

0
0

More from The Register

 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving
Panda-peddlers cuffed for chess gambling gambit
More porridge on the menu for Chinese coders after second offence
 breaking news
Yes, maybe we should keep hackers in the clink for YEARS, mulls EU
Watch out black hats, they just might throw away the key
Microsoft borks botnet takedown in Citadel snafu
Stupid Redmond kicked over our honeypots, wail white hats