If you haven't seen the Microsoft OAuth vulnerability yet, you need to check it out. #nOAuth
Anyone in the world is able to access your apps AS YOU with MS OAuth if the app is configured to use email as the account identifier.
Next tweet contains a video demo:
In the disclosure blog below, @omercnet goes into the details of:
✔ How nOAuth works
✔ How we helped fix many vulnerable apps (including fellow authentication providers)
✔ How you can check if your app is vulnerable to nOAuth
https://t.co/GlPp6lZSGU
123... and just like that, we are public beta - https://t.co/FBMw9K6OyB! Amazing teamwork across the board. We would love to hear feedback from every builder out there. Call out to all the startup founders/engineers/product managers - please try the produ…https://t.co/0zPw3yDDf9
Another sprint ends
Though Friday brings big relief
New bugs lie ahead
To any #developers reading this haiku - congrats on making it through the week! Hope you’re ready to do it all over again in a few days.
pic credit: @omercnet#descopers
kill -9 pa$$w0rds
Sorry, we thought this was a terminal instead of a Twitter feed.
Anyway, hello from Descope! We’re building something in the authentication space for developers and can’t wait to share it with you.
Visit our site if you’re curious: https://t.co/wIq4zBKCjO
All @SecurityBSides organizers around the world - make sure to check out the message from BSides Global on the organizer mailing list in preparation for our next phase of growth.
Please RT for visibility...
Thanks!