Markdown Version | Recording 1 | Recording 2

Session Date/Time: 21 Mar 2022 13:30

oauth

Summary

The OAuth working group meeting covered updates on current drafts and RFCs, followed by presentations and discussions on three key areas: D-Pop (Demonstrating Proof-of-Possession), redirection attacks in OAuth, and the ongoing development of OAuth 2.1. Key discussions revolved around the readiness of D-Pop for Working Group Last Call, how to address known redirection vulnerabilities, and several outstanding issues in OAuth 2.1, including the iss response parameter, access token lifetimes, and redirect URI methods for native apps, as well as the definitions of client types.

Key Discussion Points

Decisions and Action Items

Next Steps


Session Date/Time: 24 Mar 2022 13:30

oauth

Summary

The oauth working group session covered three main topics: security vulnerabilities in the OAuth Device Code Flow, a proposed standard for Step-Up Authentication, and the current state and future needs for OAuth client libraries. A significant portion of the session was dedicated to understanding and addressing social engineering attacks against the Device Code Flow, including a live demonstration. Discussions also highlighted the challenges developers face when implementing OAuth and the need for better guidance and tooling. Finally, a recap of a side meeting on the OAuth 2.0 Security BCP re-affirmed the importance of PKCE, particularly for public clients.

Key Discussion Points

Device Code Flow Exploits and Mitigations

Peter Castlemann, Philip Schippers, and Daniel Fett presented on social engineering exploits affecting the OAuth Device Code Flow (RFC 8628).

Step-Up Authentication

Vittorio Bertocci and Brian presented a proposal for a standard mechanism for Step-Up Authentication.

OAuth Client Libraries

Daniel Fett discussed the current state of OAuth client libraries and proposed solutions for improvement.

PKCE Security BCP Recap

Daniel Fett provided a recap of a side meeting discussion regarding the role of PKCE in the OAuth 2.0 Security BCP.

Decisions and Action Items

Next Steps