Skip to content

Releases: oauth-wg/oauth-cross-device-security

draft-ietf-oauth-cross-device-security-08

08 Jul 09:26
d25da44
Compare
Choose a tag to compare

draft-ietf-oauth-cross-device-security-07

13 May 19:49
b37f62d
Compare
Choose a tag to compare

Includes feedback from Working Group Last Call. Changes include:

  1. Clarification of FIDO\WebAuthn section.
  2. Updated langugage in section on FIDO to allow for use of FIDO keys on consumption devices.
  3. Clarified origin of QR Code.
  4. Editorial updates
  5. Updated examples to be consistent.
  6. Made diagram description clearer.
  7. Added CTAP 2.2 Draft.
  8. Added additional guidance on geolocation inaccuracies.
  9. Added Roy Williams to acknowledgements
  10. Clarified that authorization servers can detect
  11. Consistent use of "smart TV"
  12. Fixed references

draft-ietf-oauth-cross-device-security-06

04 Apr 16:11
a7f4f8c
Compare
Choose a tag to compare

draft-ietf-oauth-cross-device-security-05

01 Mar 09:45
f413141
Compare
Choose a tag to compare
  • Added section to provide actionable guidance to implementers on how to use this document.
  • Expanded section on formal analysis to include completed research projects.
  • Added reference to OpenID for Verifiable Presentations.

draft-ietf-oauth-cross-device-security-04

22 Oct 19:58
ed6e170
Compare
Choose a tag to compare

Corrected formatting issue that prevented the document history from displaying correctly.

draft-ietf-oauth-cross-device-security-03

22 Oct 19:26
69dcdec
Compare
Choose a tag to compare
  • Introduced normative SHOULD, RECOMMENDED and MAY when applied to actions the Authorization Server, Resource Server or Client may implement.
  • Added User Education as a standalone mitigation.
  • Added Maryam Mehrnezhad, Marco Pernpruner and Giada Sciarretta to the contributors list.
  • Added Request Binding with Out-of-Band Data as an additional mitigation (feedback received at OSW 2023)
  • Adopted the OpenID Foundation terminology from [CIBA] and changed Initiating Device to Consumption Device
  • Added Fake Helpdesk and Consent Request Overload examples (new variations of attacks observed in the wild)
  • Replaced "Authenticated Flow" mitigation name with "Authenticate-then-Intitiate"
  • Added Cross-Device Session Transfer pattern (feedback received at OSW 2023)

What's Changed

New Contributors

Full Changelog: draft-ietf-oauth-cross-device-security-02...draft-ietf-oauth-cross-device-security-03

draft-ietf-oauth-cross-device-security-02

10 Jul 09:17
3efb187
Compare
Choose a tag to compare
  • Introduced Cross-Device Consent Phishing as a label for the types of attacks described in this document.
  • Updated labels for different types of flows (User-Transferred Session Data Pattern, Backchannel-Transferred Session Pattern, User-Transferred Authorization Data Pattern)
  • Adopted consistent use of hyphenation in using "cross-device"
  • Consistent use of "Authorization Device"
  • Update Reference to Secure Signals Framework to reflect name change from Secure Signals and Events
  • Described difference between proximity enforced and proximity-less cross-device flows
  • Fixed typos and grammar edits
  • Capitalised Initiating Device and Authorization Device
  • General editorial pass

draft-ietf-oauth-cross-device-security-01

07 Dec 22:26
4a8eb01
Compare
Choose a tag to compare

Added additional diagrams and descriptions to distinguish between different cross-device flow patterns.
Added short description on limitations of each mitiagtion.
Added acknowledgement of additional contributors.
Fixed document history format.

draft-ietf-oauth-cross-device-security-00: fix build process

13 Mar 17:36
Compare
Choose a tag to compare
https://github.com/martinthomson/i-d-template/issues/356