Feeds

Microsoft integrates OAuth 2.0 in play for Facebook goodness

Single sign-on trend hooks up Windows Live dev platform

Application security programs and practises

Will short term gain lead to future pain?

However, one of the editors of the original OAuth protocol has previously expressed security concerns about version 2.0 of the open authorisation standard.

"As long as a site offers both an OAuth API and a human web interface (i.e. a website), the overall service will only be as secure as its weakest part - the cookie-based authentication system," wrote Hammer-Lahav on his blog last September.

Fujitsu's social robot teddy bears

Cuddle time

"The problem with this argument is not today, but five years from now. When trying to propose a new cookie protocol, developers will make the same argument, only this time pointing the finger at OAuth 2.0 as the weakest link.

"Removing signatures and relying solely on a secure channel solves the immediate problem, and maintain the same existing level of security. But it lacks any kind of forward looking responsibility, and the drive to make the web more secure. It’s a copout."

Meanwhile, Cameron - who left Microsoft's cryptography team last month - has similarly aired concerns about current industry trends on ID.

He has called for an advocate to champion his "user-centric identity" approach, which is about keeping various bits of an individual's online life totally separated.

"[That model] can be much more effective than shotgun splattering of ads or profiling that alienates us and makes us feel like robots are ruling our lives. Lots of people are upset about this," said Cameron in May. He used Microsoft, Google and Facebook as examples of companies pursuing those strategies.

Perhaps worryingly for some privacy activists, that trend doesn't appear to lie simply within the corporate sphere.

As we revealed last week, the UK government's Cabinet Office has been in talks with various social networks about the possibility of allowing British citizens to sign into public services online in an effort to simplify the process, by farming out the logon authentication process to a third party partner such as a bank or, more surprisingly, Facebook. ®

The smart choice: opportunity from uncertainty

More from The Register

next story
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Do YOU work at Microsoft? Um. Are you SURE about that?
Nokia and marketing types first to get the bullet, says report
Microsoft takes on Chromebook with low-cost Windows laptops
Redmond's chief salesman: We're taking 'hard' decisions
Cheer up, Nokia fans. It can start making mobes again in 18 months
The real winner of the Nokia sale is *drumroll* ... Nokia
EU dons gloves, pokes Google's deals with Android mobe makers
El Reg cops a squint at investigatory letters
Chrome browser has been DRAINING PC batteries for YEARS
Google is only now fixing ancient, energy-sapping bug
Big Blue Apple: IBM to sell iPads, iPhones to enterprises
iOS/2 gear loaded with apps for big biz ... uh oh BlackBerry
prev story

Whitepapers

Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.