Faruk At.eş


OAuth Redeux

J. Adam Moore with a smart solution to the problem of session fixation attacks in the OAuth flow.

Most importantly, this solution does not add additional steps for the User or unduly burden either the Provider or Consumer. By placing the generation of a request token between two automatic redirects to secure pages on both sites we eliminate poisoning the stream while still allowing optional secure dynamic callbacks with the final authorization token.


About me

Faruk Ateş

Faruk Ateş does creative things on the Web, like Modernizr. He lives in San Francisco and writes and speaks about technology, design and business.

Read more about Faruk, or .

Upcoming talks

Here on My own website

Subscribe to this site

There

Elsewhere