<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: OpenSocial insecurity &#8211; no user to app authentication</title>
	<atom:link href="http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/feed/" rel="self" type="application/rss+xml" />
	<link>http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/</link>
	<description>Fast Forward</description>
	<lastBuildDate>Sun, 18 Jul 2010 17:47:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Some OpenSocial thoughts &#124; From the Land of Meh...</title>
		<link>http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/comment-page-1/#comment-9574</link>
		<dc:creator>Some OpenSocial thoughts &#124; From the Land of Meh...</dc:creator>
		<pubDate>Mon, 22 Jun 2009 22:51:25 +0000</pubDate>
		<guid isPermaLink="false">http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/#comment-9574</guid>
		<description>[...] User data security is an issue: http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/ [...]</description>
		<content:encoded><![CDATA[<p>[...] User data security is an issue: <a href="http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/" rel="nofollow">http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Some OpenSocial thoughts &#124; You see a 20'x20' room, nothing else interesting...</title>
		<link>http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/comment-page-1/#comment-9351</link>
		<dc:creator>Some OpenSocial thoughts &#124; You see a 20'x20' room, nothing else interesting...</dc:creator>
		<pubDate>Mon, 26 Nov 2007 05:37:30 +0000</pubDate>
		<guid isPermaLink="false">http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/#comment-9351</guid>
		<description>[...] User data security is an issue: http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/ [...]</description>
		<content:encoded><![CDATA[<p>[...] User data security is an issue: <a href="http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/" rel="nofollow">http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Open Social: la garantia soy yo!</title>
		<link>http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/comment-page-1/#comment-9319</link>
		<dc:creator>Open Social: la garantia soy yo!</dc:creator>
		<pubDate>Wed, 07 Nov 2007 20:07:06 +0000</pubDate>
		<guid isPermaLink="false">http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/#comment-9319</guid>
		<description>[...] de que site vem as requests Ajax e qual o ID do usuário. Como gente com experiência no assunto explica, isso não chega nem perto de ser robusto o bastante para mais do que joguinhos e [...]</description>
		<content:encoded><![CDATA[<p>[...] de que site vem as requests Ajax e qual o ID do usuário. Como gente com experiência no assunto explica, isso não chega nem perto de ser robusto o bastante para mais do que joguinhos e [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: miron</title>
		<link>http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/comment-page-1/#comment-9317</link>
		<dc:creator>miron</dc:creator>
		<pubDate>Tue, 06 Nov 2007 23:18:56 +0000</pubDate>
		<guid isPermaLink="false">http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/#comment-9317</guid>
		<description>Google admits to the hole and gives no timeline, &lt;a href=&quot;http://groups.google.com/group/opensocial-api/browse_thread/thread/776cd89a27fe0518/829dc76edcebb830?hl=en#829dc76edcebb830&quot; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt; and &lt;a href=&quot;http://groups.google.com/group/opensocial-api/web/opensocial-issues-list?hl=en&quot; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt; (third item down).</description>
		<content:encoded><![CDATA[<p>Google admits to the hole and gives no timeline, <a href="http://groups.google.com/group/opensocial-api/browse_thread/thread/776cd89a27fe0518/829dc76edcebb830?hl=en#829dc76edcebb830" rel="nofollow">here</a> and <a href="http://groups.google.com/group/opensocial-api/web/opensocial-issues-list?hl=en" rel="nofollow">here</a> (third item down).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tony Stubblebine</title>
		<link>http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/comment-page-1/#comment-9316</link>
		<dc:creator>Tony Stubblebine</dc:creator>
		<pubDate>Tue, 06 Nov 2007 22:47:39 +0000</pubDate>
		<guid isPermaLink="false">http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/#comment-9316</guid>
		<description>I&#039;d be curious to know how the widget hacks that keep getting reported on TechCrunch are getting closed. It seems like the original Google partners should be sharing their newly learned security best practices.

Hopefully, I&#039;d feel better about the security holes if someone on the Google side acknowledged that they rushed everything  in order to get there press releases out and that they were in fact committed to working through these issues publicly.</description>
		<content:encoded><![CDATA[<p>I&#8217;d be curious to know how the widget hacks that keep getting reported on TechCrunch are getting closed. It seems like the original Google partners should be sharing their newly learned security best practices.</p>
<p>Hopefully, I&#8217;d feel better about the security holes if someone on the Google side acknowledged that they rushed everything  in order to get there press releases out and that they were in fact committed to working through these issues publicly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: miron</title>
		<link>http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/comment-page-1/#comment-9315</link>
		<dc:creator>miron</dc:creator>
		<pubDate>Tue, 06 Nov 2007 18:50:13 +0000</pubDate>
		<guid isPermaLink="false">http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/#comment-9315</guid>
		<description>Ramon,

You&#039;ll have to provide more details, your comment is not clear to me.

What do you mean by &quot;you can verify the ID ...&quot;?  There is no functionality in the API to verify IDs.

The second item needs clarification.  What kind of application doesn&#039;t care about ID spoofing?

The third item doesn&#039;t make sense, because Ajax is just another way to connect to the back end.  It does not provide any additional authentication means.

Thanks.</description>
		<content:encoded><![CDATA[<p>Ramon,</p>
<p>You&#8217;ll have to provide more details, your comment is not clear to me.</p>
<p>What do you mean by &#8220;you can verify the ID &#8230;&#8221;?  There is no functionality in the API to verify IDs.</p>
<p>The second item needs clarification.  What kind of application doesn&#8217;t care about ID spoofing?</p>
<p>The third item doesn&#8217;t make sense, because Ajax is just another way to connect to the back end.  It does not provide any additional authentication means.</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ramon</title>
		<link>http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/comment-page-1/#comment-9314</link>
		<dc:creator>Ramon</dc:creator>
		<pubDate>Tue, 06 Nov 2007 14:17:58 +0000</pubDate>
		<guid isPermaLink="false">http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/#comment-9314</guid>
		<description>Hi Miron and Mat,

Well you can verify if the ID provided is the actual owner of the ID, that&#039;s the first security &#039;breach&#039; solution.
Second: Don&#039;t make your application authentication focused, make it owner to friends focused.
Third: Implement Ajax calls to verify and/or block any feature you think can be hacked (hijacking, etc.).

Sorry, but I cannot give a url right now due to still on going development but once I get into a beta version I will send you the link.
Best,
Ramon</description>
		<content:encoded><![CDATA[<p>Hi Miron and Mat,</p>
<p>Well you can verify if the ID provided is the actual owner of the ID, that&#8217;s the first security &#8216;breach&#8217; solution.<br />
Second: Don&#8217;t make your application authentication focused, make it owner to friends focused.<br />
Third: Implement Ajax calls to verify and/or block any feature you think can be hacked (hijacking, etc.).</p>
<p>Sorry, but I cannot give a url right now due to still on going development but once I get into a beta version I will send you the link.<br />
Best,<br />
Ramon</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ippimail.com &#187; Blog Archive &#187; OpenSocial: After the hype, the holes</title>
		<link>http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/comment-page-1/#comment-9311</link>
		<dc:creator>ippimail.com &#187; Blog Archive &#187; OpenSocial: After the hype, the holes</dc:creator>
		<pubDate>Tue, 06 Nov 2007 02:05:03 +0000</pubDate>
		<guid isPermaLink="false">http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/#comment-9311</guid>
		<description>[...] based on the standard hacked within minutes, it quickly became evident that OpenSocial is vulnerable and offers an open door to anyone who wants to put a little effort into pushing it [...]</description>
		<content:encoded><![CDATA[<p>[...] based on the standard hacked within minutes, it quickly became evident that OpenSocial is vulnerable and offers an open door to anyone who wants to put a little effort into pushing it [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aehso&#8217;s Output &#187; OpenSocial Doc Review Part 2 : Authentication, Hosting and Applications</title>
		<link>http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/comment-page-1/#comment-9310</link>
		<dc:creator>Aehso&#8217;s Output &#187; OpenSocial Doc Review Part 2 : Authentication, Hosting and Applications</dc:creator>
		<pubDate>Mon, 05 Nov 2007 19:48:06 +0000</pubDate>
		<guid isPermaLink="false">http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/#comment-9310</guid>
		<description>[...] Miron highlights another potentially critical problem - track it [...]</description>
		<content:encoded><![CDATA[<p>[...] Miron highlights another potentially critical problem &#8211; track it [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mat</title>
		<link>http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/comment-page-1/#comment-9309</link>
		<dc:creator>Mat</dc:creator>
		<pubDate>Mon, 05 Nov 2007 17:54:53 +0000</pubDate>
		<guid isPermaLink="false">http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/#comment-9309</guid>
		<description>Have to say, I agree with miron. I currently cant see how you can prevent again spoofing attacks with a javascript only API, Due to the nature of the app we are creating we need to store a substantial amount of data off on our own servers, and we cant store this in any secure maner (e.g. associating it to a certain user), as we cant trust any info coming from the browser. At the moment I cant see a solution to this, but feel free to enlighten me.

Ramon if you could give me the url of your app, maybe a demo could be in order.

Mat</description>
		<content:encoded><![CDATA[<p>Have to say, I agree with miron. I currently cant see how you can prevent again spoofing attacks with a javascript only API, Due to the nature of the app we are creating we need to store a substantial amount of data off on our own servers, and we cant store this in any secure maner (e.g. associating it to a certain user), as we cant trust any info coming from the browser. At the moment I cant see a solution to this, but feel free to enlighten me.</p>
<p>Ramon if you could give me the url of your app, maybe a demo could be in order.</p>
<p>Mat</p>
]]></content:encoded>
	</item>
</channel>
</rss>
