Feeds

Microsoft integrates OAuth 2.0 in play for Facebook goodness

Single sign-on trend hooks up Windows Live dev platform

Security for virtualized datacentres

Will short term gain lead to future pain?

However, one of the editors of the original OAuth protocol has previously expressed security concerns about version 2.0 of the open authorisation standard.

"As long as a site offers both an OAuth API and a human web interface (i.e. a website), the overall service will only be as secure as its weakest part - the cookie-based authentication system," wrote Hammer-Lahav on his blog last September.

Fujitsu's social robot teddy bears

Cuddle time

"The problem with this argument is not today, but five years from now. When trying to propose a new cookie protocol, developers will make the same argument, only this time pointing the finger at OAuth 2.0 as the weakest link.

"Removing signatures and relying solely on a secure channel solves the immediate problem, and maintain the same existing level of security. But it lacks any kind of forward looking responsibility, and the drive to make the web more secure. It’s a copout."

Meanwhile, Cameron - who left Microsoft's cryptography team last month - has similarly aired concerns about current industry trends on ID.

He has called for an advocate to champion his "user-centric identity" approach, which is about keeping various bits of an individual's online life totally separated.

"[That model] can be much more effective than shotgun splattering of ads or profiling that alienates us and makes us feel like robots are ruling our lives. Lots of people are upset about this," said Cameron in May. He used Microsoft, Google and Facebook as examples of companies pursuing those strategies.

Perhaps worryingly for some privacy activists, that trend doesn't appear to lie simply within the corporate sphere.

As we revealed last week, the UK government's Cabinet Office has been in talks with various social networks about the possibility of allowing British citizens to sign into public services online in an effort to simplify the process, by farming out the logon authentication process to a third party partner such as a bank or, more surprisingly, Facebook. ®

Internet Security Threat Report 2014

More from The Register

next story
ONE MILLION people already running Windows 10
A third of them are doing it in VMs, but early feedback focuses on frippery
Netscape Navigator - the browser that started it all - turns 20
It was 20 years ago today, Marc Andreeesen taught the band to play
Sway: Microsoft's new Office app doesn't have an Undo function
Content aggregation, meet the workplace ... oh
Sign off my IT project or I’ll PHONE your MUM
Honestly, it’s a piece of piss
Do Moan! MONSTER 6-day EMAIL OUTAGE hits Domain Monster
Customers freaked out by frightful service
Return of the Jedi – Apache reclaims web server crown
.london, .hamburg and .公司 - that's .com in Chinese - storm the web server charts
NetWare sales revive in China thanks to that man Snowden
If it ain't Microsoft, it's in fashion behind the Great Firewall
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.