Parent Categories/Forums: OpenID
Edit this Forum

OpenID - Security

Search:
This forum is an archive for the mailing list: security@openid.net (mailing list options). Messages posted here will be sent to this mailing list.

Discussion around security and anti-phishing tactics of OpenID.
Child Forums (0): None
To migrate this forum to the new Nabble2 system, please post a request in the Nabble Support forum — Learn more
Post to OpenID - Security Post New Message  ::  Alert me of new posts  ::  Rating Filter:

Thread (31 Threads) Rating Replies Last Message

Danger of Content-Location HTTP response header by Andrew Arnott
9
by Chris Messina

Re: Login CSRF in OpenID Authentication by Adam Barth
0
by Adam Barth

PAPE Policy for RPs to force authentication without browser cookie by Allen Tom-2
33
by Allen Tom-2

Re: [specs-pape] PAPE Policy for RPs to force authentication without browser cookie by John Bradley-8
0
by John Bradley-8

Re: [specs-pape] PAPE Policy for RPs to force authentication without browser cookie by John Bradley-8
0
by John Bradley-8

Open Redirector issue with checkid_immediate by Allen Tom-2
12
by Brandon Ramirez

OpenID Security Best Practices Doc by Allen Tom-2
18
by Martin Atkins-2

Public Comment Preparation to draft NIST SP800-63 rev.1 Dec 2008 by Nat Sakimura
0
by Nat Sakimura

Please convince me not to ban SSL (OP's) by SitG Admin
13
by SitG Admin

How secure is open id? by richardscannell
1
by SitG Admin

Unsubscribe by Jennifer Michelle
0
by Jennifer Michelle

how secure is openid? advise pls.. by Balasubramanian G
18
by SitG Admin

Security Committee by Nat Sakimura
0
by Nat Sakimura

User directly requet to OP. by 6d5930fcb2225bbca791...
3
by SitG Admin

[OpenID] Re: generation fragments by SitG Admin
4
by SitG Admin

OpenID Provider questions by Aerocell
0
by Aerocell

OpenID/Debian PRNG/DNS Cache poisoning advisory by Ben Laurie-3
23
by Ben Laurie-3

Tailoring headers to Consumers by SitG Admin
0
by SitG Admin

Net-ID 2008 in Basel by stefanie.geuhs
0
by stefanie.geuhs

Comment on the use of nonces in OpenID Authentcation 2.0/d12 by Jose Kahan-2
1
by Johnny Bufu

Phishing-Resistant Authentication definition by Dick Hardt
0
by Dick Hardt

Validating openid.identity in authentication responses by Trevor Johns
10
by Manger, James H

Re: The dangers of CSS iframe overlays by gaz_sec
0
by gaz_sec

OpenID account security by gaz_sec
0
by gaz_sec

The dangers of CSS iframe overlays by gaz_sec
0
by gaz_sec

CSRF protection by gaz_sec
0
by gaz_sec

Re: [OpenID] Trust + Security @ OpenID by Dmitry Shechtman-2
11
by Eric Norman

Re: [OpenID] Trust + Security @ OpenID by Eddy Nigg (StartCom ...
0
by Eddy Nigg (StartCom ...

document.domain by gaz_sec
0
by gaz_sec

Old MyOpenID POC released by gaz_sec
0
by gaz_sec

Browser support once again - considerations by Boris Erdmann
1
by Alaric Dailey-2
Post to OpenID - Security Post New Message  ::  Alert me of new posts  ::  Atom feed for OpenID - Security