• Home
  • Videos
  • Contact
  • Subscribe to Newsletter
  • Subscribe to Re:ID Magazine
  • Twitter
  • RSS
SecureIDNews
  • Markets »
  • Corporate
  • Education
  • Financial
  • Government
  • Health
  • Transit
  • Technologies »
  • Biometrics
  • Contactless
  • Digital ID
  • NFC
  • RFID
  • Smart Cards

Time: 0 :0

You are here:

  • Home
  • Do OAuth tokens sustain hacking attacks?

Do OAuth tokens sustain hacking attacks?

20 February, 2013

By: Jill Jaracz

category: Corporate, Digital ID

0

In the recent attack on Twitter in which information for about 250,000 users was compromised, Twitter’s forced password reset may not have been enough to fix the problem, writes the blog Talking Identity. The problems may continue through the use of OAuth tokens.

The blog notes that use of OAuth tokens enables third-party apps to access Twitter, even when the passwords were reset. Twitter’s forced password reset didn’t fully shut down the apps’ access to the site. This means that hackers could get into the system and enable an OAuth token that would still allow them access after the attack had been shut down.

This scenario has implications for businesses that use BYOD policies and have employees who consistently authorize apps without monitoring them on a regular basis.

Lax oversight over these apps and the OAuth tokens employed by them could mean that an unwanted third party app could have access to a company’s cloud-based services, which could lead to further incidences of compromised data.

Read more here.


Tags: Handsets, Internet Security

recommend to friends

Related News

Entrust updates mobile credential software

10 April, 2013

DHS Science and Technology Directorate developing app for first responder verification

08 April, 2013

Report discusses dynamics of authentication in BYOD environment

26 March, 2013

Metro looks into open payment system to replace SmarTrip

19 March, 2013

SecureIDNews
BACK TO TOP

re:ID Magazine



Read current issue online

CR80News Magazine



Read current issue online

Questions, Tips, & Comments

Name:

Email:

Message:

Twitter feed

Follow on Twitter
  • About
  • Advertise
  • Store
  • re:ID
  • Subscribe
  • Twitter
  • RSS

© 2013-2014 AVISIAN Publishing. All rights reserved. info@avisian.com

Close

Enter the site

Login

Password

Remember me

Forgot password?

Login
Skip to toolbar
    • WordPress.org
    • Documentation
    • Support Forums
    • Feedback
Log Out