<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Owasp on Bruno Pedro</title><link>https://brunopedro.com/tags/owasp/</link><description>Recent content in Owasp on Bruno Pedro</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 08 May 2018 10:00:15 -0700</lastBuildDate><atom:link href="https://brunopedro.com/tags/owasp/index.xml" rel="self" type="application/rss+xml"/><item><title>Is OAuth Really Secure?</title><link>https://brunopedro.com/2011/01/05/is-oauth-really-secure/</link><pubDate>Wed, 05 Jan 2011 01:01:27 +0000</pubDate><guid>https://brunopedro.com/2011/01/05/is-oauth-really-secure/</guid><description>&lt;p>&amp;ldquo;Is OAuth Really Secure?&amp;rdquo; is the title of a &lt;a href="http://www.slideshare.net/bpedro/is-oauth-really-secure">talk&lt;/a> I gave at the &lt;a href="http://www.owasp.org/index.php/IBWAS10" title="IBWAS'10">IBWAS'10 conference&lt;/a>, last December.&lt;/p>
&lt;p>Is the &lt;a href="http://oauth.net" title="OAuth">OAuth&lt;/a> protocol really secure? Even though the OAuth authorization protocol has been published as the &lt;a href="http://tools.ietf.org/html/rfc5849">RFC 5849&lt;/a> and is being widely adopted by large Internet companies, it&amp;rsquo;s important to stress out its possible security vulnerabilities.&lt;/p>
&lt;p>This talk focuses on the &lt;a href="http://owasp.org" title="OWASP">OWASP&lt;/a> &lt;a href="http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project">Top 10 Application Security Risks&lt;/a> and how OAuth is affected by them. While some of the security risks are mitigated by OAuth, developers need to take some action to prevent other risks from affecting their implementations.&lt;/p></description></item></channel></rss>