<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-6894552.post7656771900751107983..comments</id><updated>2011-09-04T08:58:54.518-07:00</updated><category term='Reviews'/><category term='Immutability'/><category term='Far sighted'/><category term='OAuth'/><category term='WCF'/><category term='Ruby'/><category term='Javascript'/><category term='Linux'/><category term='Async'/><category term='NHibernate'/><category term='Smart devices'/><category term='Hardware'/><category term='Mono'/><category term='Windows'/><category term='MSBuild'/><category term='WPF'/><category term='DotNetOpenAuth'/><category term='InfoCard'/><category term='Silverlight'/><category term='.NET'/><category term='OpenID'/><category term='ASP.NET'/><category term='Windows.Forms'/><title type='text'>Comments on JMPInline: OpenID association poisoning</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.nerdbank.net/feeds/7656771900751107983/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6894552/7656771900751107983/comments/default'/><link rel='alternate' type='text/html' href='http://blog.nerdbank.net/2009/03/openid-association-poisoning.html'/><author><name>Andrew Arnott</name><uri>https://profiles.google.com/114635397638720587251</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-dETLr6cO5U0/AAAAAAAAAAI/AAAAAAAAAAA/A9rnrw9kYqs/s512-c/photo.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6894552.post-8125790142187838674</id><published>2011-09-04T08:58:54.518-07:00</published><updated>2011-09-04T08:58:54.518-07:00</updated><title type='text'>Step 7 mentions that the RP must be vulnerable to ...</title><summary type='text'>Step 7 mentions that the RP must be vulnerable to this attack.  As you say, the RP shouldn&amp;#39;t be vulnerable, but it *may* be.&lt;br /&gt;&lt;br /&gt;Step 3 is always possible, as the browser (and thus the attacker) can see the association handle after the RP and OP establish it by their privat echannel, because during the checkid_setup redirect one of the user-visible parameters is the association handle.</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6894552/7656771900751107983/comments/default/8125790142187838674'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6894552/7656771900751107983/comments/default/8125790142187838674'/><link rel='alternate' type='text/html' href='http://blog.nerdbank.net/2009/03/openid-association-poisoning.html?showComment=1315151934518#c8125790142187838674' title=''/><author><name>Andrew</name><uri>http://www.blogger.com/profile/13632400519774640095</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://2.bp.blogspot.com/_hfiLRSZPvmE/TDJhBngv6qI/AAAAAAAAEdg/a7NOd27j_Lc/S220/closeup.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.nerdbank.net/2009/03/openid-association-poisoning.html' ref='tag:blogger.com,1999:blog-6894552.post-7656771900751107983' source='http://www.blogger.com/feeds/6894552/posts/default/7656771900751107983' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1687004514'/></entry><entry><id>tag:blogger.com,1999:blog-6894552.post-1108653170231210765</id><published>2011-09-04T01:24:43.632-07:00</published><updated>2011-09-04T01:24:43.632-07:00</updated><title type='text'>Step 7 is not possible? I&amp;#39;d guess the RP store...</title><summary type='text'>Step 7 is not possible? I&amp;#39;d guess the RP stores associations per OP, so an OP cannot overwrite any other OP&amp;#39;s associations&lt;br /&gt;&lt;br /&gt;I don&amp;#39;t know how step 3 would be possible. The Web browser will never be able to read the handle established between RP and GoodOP, isn&amp;#39;t the association created in a HTTP connection directly between the RP and GoodOP.&lt;br /&gt;&lt;br /&gt;Even if the Hacker </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6894552/7656771900751107983/comments/default/1108653170231210765'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6894552/7656771900751107983/comments/default/1108653170231210765'/><link rel='alternate' type='text/html' href='http://blog.nerdbank.net/2009/03/openid-association-poisoning.html?showComment=1315124683632#c1108653170231210765' title=''/><author><name>Kaj Magnus</name><uri>http://www.blogger.com/profile/18054221902017877054</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.nerdbank.net/2009/03/openid-association-poisoning.html' ref='tag:blogger.com,1999:blog-6894552.post-7656771900751107983' source='http://www.blogger.com/feeds/6894552/posts/default/7656771900751107983' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1649815908'/></entry></feed>
