OAuth 2.0: New Attacks and Security Recommendations
by Daniel Fett
The IETF OAuth Working Group is working towards a new Security Best Current Practice (BCP) RFC that aims to weed out insecure implementation patterns for OAuth 2.0. It based on lessons learned in practice and on new attacks found through formal security analyses of OAuth and OpenID Connect.
I would like to present and discuss this work.