Skip to content

draft-ietf-oauth-cross-device-security-03

Compare
Choose a tag to compare
@PieterKas PieterKas released this 22 Oct 19:26
· 110 commits to main since this release
69dcdec
  • Introduced normative SHOULD, RECOMMENDED and MAY when applied to actions the Authorization Server, Resource Server or Client may implement.
  • Added User Education as a standalone mitigation.
  • Added Maryam Mehrnezhad, Marco Pernpruner and Giada Sciarretta to the contributors list.
  • Added Request Binding with Out-of-Band Data as an additional mitigation (feedback received at OSW 2023)
  • Adopted the OpenID Foundation terminology from [CIBA] and changed Initiating Device to Consumption Device
  • Added Fake Helpdesk and Consent Request Overload examples (new variations of attacks observed in the wild)
  • Replaced "Authenticated Flow" mitigation name with "Authenticate-then-Intitiate"
  • Added Cross-Device Session Transfer pattern (feedback received at OSW 2023)

What's Changed

New Contributors

Full Changelog: draft-ietf-oauth-cross-device-security-02...draft-ietf-oauth-cross-device-security-03