SlideShare a Scribd company logo
Risks with OpenID Remember,  with great comfort . comes  great security risk . – Spiderman style ;)
What is OpenID  (wikipedia) OpenID is a shared identity service, which allows Internet users to log on to many different web sites using a single digital identity. Eliminating the need for a different user name and password for each site.  OpenID is a decentralized, free and open standard that lets users control the amount of personal information they provide.
Easy for user Complex to implement Not so difficult to do  phishing You loose one ID and you loose complete web.
Remember single username and password for many sites Need not create a new account on a new site, use the same everywhere (mostly) Allow timed access Allow site X to use this authentication from date ‘a’ till date ‘b’ Benefits
Popular OpenID providers Flickr :  http://www.flickr.com/photos/ username  Verisign :  http:// username .pip.verisignlabs.com/ Technorati :  http://technorati.com/people/technorati/ username   Blogger :  http:// blogname .blogspot.com   Wordpress :  http:// username .wordpress.com  & now Google :  https://www.google.com/accounts/o8/id?id= username its actually not an OpenID    read  here
Risks with OpenID Phishing Attacks   Probably the biggest concern with OpenID. Users may be tricked into providing their credentials to phished OpenID provider website.  This site might look like your original OpenID provider and you might loose your password for all the services affiliated to OpenID
Risks with OpenID… (contd) Man-in-the-middle Attacks   If the connection is negotiated over weak encryption then it is subjected to interception attacks.  Ensure that you are using HTTPS and you know how to use HTTPS safely  
Risks with OpenID… (contd) Replay Attacks The URL from the relaying party can be sniffed, unless over HTTPS, and as such being replayed.  Solution again is HTTPS
Risks with OpenID… (contd) CSRF  (Cross-site request forgery)  Attacks Once the victim is logged in malicious user might be able to execute CSRF attacks against other sites. Oops… ;( <iframe id=&quot;login&quot; src=&quot; http://bank.com/login?openid_url = user.openid.net &quot; width=&quot;0&quot; height=&quot;0&quot;></iframe>
Risks with OpenID… (contd) XSS Attacks   Once the user is logged in attackers might be able to execute a series of XSS (Cross-site scripting) attacks against the identity provider, in which case they will be able to hijack the entire on-line use presence. If attacker can do it through OpenID then why not?
Not against OpenID No I’m not at all against OpenID. It’s a great idea  and will make online life lot more easier. User must be aware of safe usage. Implementers should take care of most of the security risk.
Recommendation NEVER EVER  use OpenID or Single-Sign-On for  banks  or  credit cards Always use  HTTPS  and know how to use it safely Better be paranoid than sorry   like the condom ad “better safe than worry”
Further reading OpenID security issues http://www.thespanner.co.uk/2007/06/29/openid-security-issues/ OpenID: Phishing Heaven  http://www.links.org/?p=187   OpenID: Phishing Heaven II  http://www.links.org/?p=188   Problems with OpenID  http://idcorner.org/2007/08/22/the-problems-with-openid/   Phishing risk  http://stii.za.net/semanticweb/openid-phishing-risks-be-careful/   Solving phishing problem http://simonwillison.net/2007/Jan/19/phishing/
Confused??? Drop me a mail  rohit@ club hack .com  I   MIGHT  be able to help you  

More Related Content

PPTX
Cm7 secure code_training_1day_xss
PDF
XSS-Alert-Pentration testing tool
PDF
The Cross Site Scripting Guide
PPTX
Cross site scripting
PDF
Cross site scripting
PPTX
Cross Site Scripting
PPTX
Xss (cross site scripting)
PPTX
Cross site scripting (xss)
Cm7 secure code_training_1day_xss
XSS-Alert-Pentration testing tool
The Cross Site Scripting Guide
Cross site scripting
Cross site scripting
Cross Site Scripting
Xss (cross site scripting)
Cross site scripting (xss)

What's hot (20)

PPTX
Cross-Site Scripting (XSS)
PPT
4.Xss
PPTX
Cross site scripting
PPTX
Reflective and Stored XSS- Cross Site Scripting
PDF
Attacking Web Proxies
PPTX
Cross Site Scripting(XSS)
PPTX
XSS- an application security vulnerability
PDF
XSS Injection Vulnerabilities
PPT
Cross site scripting (xss)
PDF
Cross site scripting attacks and defenses
PPT
PDF
Cross site scripting (xss) attacks issues and defense - by sandeep kumbhar
PPT
Identifying Cross Site Scripting Vulnerabilities in Web Applications
PPT
Front end-security
PPTX
Identifying XSS Vulnerabilities
PPTX
Cross Site Scripting Defense Presentation
PPT
Xss talk, attack and defense
PPTX
Deep understanding on Cross-Site Scripting and SQL Injection
Cross-Site Scripting (XSS)
4.Xss
Cross site scripting
Reflective and Stored XSS- Cross Site Scripting
Attacking Web Proxies
Cross Site Scripting(XSS)
XSS- an application security vulnerability
XSS Injection Vulnerabilities
Cross site scripting (xss)
Cross site scripting attacks and defenses
Cross site scripting (xss) attacks issues and defense - by sandeep kumbhar
Identifying Cross Site Scripting Vulnerabilities in Web Applications
Front end-security
Identifying XSS Vulnerabilities
Cross Site Scripting Defense Presentation
Xss talk, attack and defense
Deep understanding on Cross-Site Scripting and SQL Injection
Ad

Similar to Risks With OpenID (20)

PPT
PPT
Securing your digital identity with drupal
PPTX
Hacking and Cyber Security.
PDF
The Implications of OpenID
PPT
Implementing OpenID for Your Social Networking Site
PDF
Building the Social Web with OpenID
PPTX
You think you are safe online. Are You?
PPTX
Cyber Security Awareness Program.pptx
PDF
Owasp top 10 2013
PDF
OpenID Tutorials
PDF
How to 2FA-enable Open Source Applications
PDF
Implications Of OpenID (Google Tech Talk)
PDF
Openid+Opensocial
PDF
OpenID and decentralised social networks
PPT
Andrews whitakrer lecture18-security.ppt
PPT
Anonymous internet
PPT
Anonymous internet
PPTX
Defcamp 2013 - Does it pay to be a blackhat hacker
PPTX
Dan Catalin Vasile - Defcamp2013 - Does it pay to be a blackhat hacker
PPTX
Cyber attacks Dark Web Session - I4Cv1.pptx
Securing your digital identity with drupal
Hacking and Cyber Security.
The Implications of OpenID
Implementing OpenID for Your Social Networking Site
Building the Social Web with OpenID
You think you are safe online. Are You?
Cyber Security Awareness Program.pptx
Owasp top 10 2013
OpenID Tutorials
How to 2FA-enable Open Source Applications
Implications Of OpenID (Google Tech Talk)
Openid+Opensocial
OpenID and decentralised social networks
Andrews whitakrer lecture18-security.ppt
Anonymous internet
Anonymous internet
Defcamp 2013 - Does it pay to be a blackhat hacker
Dan Catalin Vasile - Defcamp2013 - Does it pay to be a blackhat hacker
Cyber attacks Dark Web Session - I4Cv1.pptx
Ad

Recently uploaded (20)

PPT
Teaching material agriculture food technology
PDF
Machine learning based COVID-19 study performance prediction
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Encapsulation_ Review paper, used for researhc scholars
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Empathic Computing: Creating Shared Understanding
PDF
KodekX | Application Modernization Development
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PPTX
sap open course for s4hana steps from ECC to s4
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Electronic commerce courselecture one. Pdf
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
Spectroscopy.pptx food analysis technology
Teaching material agriculture food technology
Machine learning based COVID-19 study performance prediction
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Per capita expenditure prediction using model stacking based on satellite ima...
The Rise and Fall of 3GPP – Time for a Sabbatical?
Encapsulation_ Review paper, used for researhc scholars
“AI and Expert System Decision Support & Business Intelligence Systems”
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Building Integrated photovoltaic BIPV_UPV.pdf
Empathic Computing: Creating Shared Understanding
KodekX | Application Modernization Development
20250228 LYD VKU AI Blended-Learning.pptx
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
sap open course for s4hana steps from ECC to s4
Review of recent advances in non-invasive hemoglobin estimation
Electronic commerce courselecture one. Pdf
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Unlocking AI with Model Context Protocol (MCP)
Spectroscopy.pptx food analysis technology

Risks With OpenID

  • 1. Risks with OpenID Remember, with great comfort . comes great security risk . – Spiderman style ;)
  • 2. What is OpenID (wikipedia) OpenID is a shared identity service, which allows Internet users to log on to many different web sites using a single digital identity. Eliminating the need for a different user name and password for each site. OpenID is a decentralized, free and open standard that lets users control the amount of personal information they provide.
  • 3. Easy for user Complex to implement Not so difficult to do phishing You loose one ID and you loose complete web.
  • 4. Remember single username and password for many sites Need not create a new account on a new site, use the same everywhere (mostly) Allow timed access Allow site X to use this authentication from date ‘a’ till date ‘b’ Benefits
  • 5. Popular OpenID providers Flickr : http://www.flickr.com/photos/ username Verisign : http:// username .pip.verisignlabs.com/ Technorati : http://technorati.com/people/technorati/ username Blogger : http:// blogname .blogspot.com Wordpress : http:// username .wordpress.com & now Google : https://www.google.com/accounts/o8/id?id= username its actually not an OpenID  read here
  • 6. Risks with OpenID Phishing Attacks Probably the biggest concern with OpenID. Users may be tricked into providing their credentials to phished OpenID provider website. This site might look like your original OpenID provider and you might loose your password for all the services affiliated to OpenID
  • 7. Risks with OpenID… (contd) Man-in-the-middle Attacks If the connection is negotiated over weak encryption then it is subjected to interception attacks. Ensure that you are using HTTPS and you know how to use HTTPS safely 
  • 8. Risks with OpenID… (contd) Replay Attacks The URL from the relaying party can be sniffed, unless over HTTPS, and as such being replayed. Solution again is HTTPS
  • 9. Risks with OpenID… (contd) CSRF (Cross-site request forgery) Attacks Once the victim is logged in malicious user might be able to execute CSRF attacks against other sites. Oops… ;( <iframe id=&quot;login&quot; src=&quot; http://bank.com/login?openid_url = user.openid.net &quot; width=&quot;0&quot; height=&quot;0&quot;></iframe>
  • 10. Risks with OpenID… (contd) XSS Attacks Once the user is logged in attackers might be able to execute a series of XSS (Cross-site scripting) attacks against the identity provider, in which case they will be able to hijack the entire on-line use presence. If attacker can do it through OpenID then why not?
  • 11. Not against OpenID No I’m not at all against OpenID. It’s a great idea and will make online life lot more easier. User must be aware of safe usage. Implementers should take care of most of the security risk.
  • 12. Recommendation NEVER EVER use OpenID or Single-Sign-On for banks or credit cards Always use HTTPS and know how to use it safely Better be paranoid than sorry  like the condom ad “better safe than worry”
  • 13. Further reading OpenID security issues http://www.thespanner.co.uk/2007/06/29/openid-security-issues/ OpenID: Phishing Heaven http://www.links.org/?p=187 OpenID: Phishing Heaven II http://www.links.org/?p=188 Problems with OpenID http://idcorner.org/2007/08/22/the-problems-with-openid/ Phishing risk http://stii.za.net/semanticweb/openid-phishing-risks-be-careful/ Solving phishing problem http://simonwillison.net/2007/Jan/19/phishing/
  • 14. Confused??? Drop me a mail rohit@ club hack .com I MIGHT be able to help you 