Security News > 2011 > May > OpenID warns of 'psychic paper' authentication attack

OpenID warns of 'psychic paper' authentication attack
2011-05-10 07:32

http://www.theregister.co.uk/2011/05/09/openid_security_bug/ By John Leyden The Register 9th May 2011 OpenID has warned of bugs in its authentication technology that create a possible means for hackers to modify data sent between sites. The flaw is noteworthy because many high-profile sites -- including Google, Yahoo! and Flickr -- use the technology so that once users have logged into one site, they aren't constantly prompted for passwords. Thousands of smaller sites also use the technology. The security weakness stems from an implementation flaw in authentication exchange, an extension to the OpenID system that gives sites the ability to exchange identity information between endpoints. The bug meant that proper checks on whether authentication information had been correctly signed were not carried out in some cases, thus creating a mechanism for hackers to offer false information that is accepted as genuine. The security bug has been confirmed in OpenID4Java and Kay Framework, but is not necessarily limited to them. Both libraries have been updated. Janrain, Ping Identity and DotNetOpenAuth are immune from the bug. [...] ___________________________________________________________ Tegatai Managed Colocation: Four Provider Blended Tier-1 Bandwidth, Fortinet Universal Threat Management, Natural Disaster Avoidance, Always-On Power Delivery Network, Cisco Switches, SAS 70 Type II Datacenter. Find peace of mind, Defend your Critical Infrastructure. http://www.tegataiphoenix.com/


News URL

http://www.theregister.co.uk/2011/05/09/openid_security_bug/