<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <p>*** Sorry. I did it again. ***<br>
    </p>
    <p>Hi William,</p>
    <p>may interested parties at remote locations contribute as well?</p>
    best regards,<br>
    Torsten.<br>
    <br>
    PS: where had the OIDF workshop been announced? I don't remember a
    posting on this list.<br>
    <br>
    <div class="moz-cite-prefix">Am 27.04.2016 um 19:22 schrieb Torsten
      Lodderstedt:<br>
    </div>
    <blockquote
      cite="mid:22adf439-b342-dc7b-6b61-228b2a7eedf4@lodderstedt.net"
      type="cite">
      <meta content="text/html; charset=windows-1252"
        http-equiv="Content-Type">
      <p>Hi Denniss,</p>
      <p>may interested parties at remote locations contribute as well?</p>
      best regards,<br>
      Torsten.<br>
      <br>
      PS: where had the OIDF workshop been announced? I don't remember a
      posting on this list.<br>
      <br>
      <div class="moz-cite-prefix">Am 25.04.2016 um 23:53 schrieb
        William Denniss:<br>
      </div>
      <blockquote
cite="mid:CAAP42hDzJGYBOoR5O+6fqnyxQh0_Hz+P5VFCzpCSO6Lvi0VA1A@mail.gmail.com"
        type="cite">
        <div dir="ltr">We discussed this topic at the OIDF workshop
          today. The consensus was that we should publish a formal-ish
          (board reviewed) blog post / bulletin with implementation
          advice on how to mitigate Mix-up and Cut-and-Paste in Connect.
          <div><br>
          </div>
          <div>Interested parties can meet tomorrow at IIW to draft this
            text.</div>
        </div>
        <div class="gmail_extra"><br>
          <div class="gmail_quote">On Sat, Apr 23, 2016 at 7:57 AM, John
            Bradley <span dir="ltr"><<a moz-do-not-send="true"
                href="mailto:ve7jtb@ve7jtb.com" target="_blank">ve7jtb@ve7jtb.com</a>></span>
            wrote:<br>
            <blockquote class="gmail_quote" style="margin:0 0 0
              .8ex;border-left:1px #ccc solid;padding-left:1ex">
              <p dir="ltr">I think there are two discussions.  </p>
              <p dir="ltr">One is what the OAuth WG should do and that
                should be on the OAuth list.</p>
              <p dir="ltr">There is a separate discussion about what
                Connect should recommend untill OAuth addresses the
                issue.  </p>
              <p dir="ltr">I think the latter was how this thread
                started.  </p>
              <p dir="ltr">We not be should not wait for OAuth to
                recommend something before we explain the existing
                mitigations in Connect.</p>
              <p dir="ltr">The touchier topic is should we add anything
                new before OAuth decides.  <br>
                <br>
                To Brian's point about the AS not identifying itself in
                the response,  that was the recommended change from the
                Darmstadt meeting.   I am however hesitant to take that
                up as a Connect only fix even though it would work just
                fine for Connect. <br>
                <br>
                John B. </p>
              <div class="gmail_quote">On Apr 23, 2016 9:04 AM, "Brian
                Campbell" <<a moz-do-not-send="true"
                  href="mailto:bcampbell@pingidentity.com"
                  target="_blank">bcampbell@pingidentity.com</a>>
                wrote:<br type="attribution">
                <blockquote class="gmail_quote" style="margin:0 0 0
                  .8ex;border-left:1px #ccc solid;padding-left:1ex">
                  <div dir="ltr">Just noticed a typo in my previous
                    message. I meant to write "omission" rather than
                    "commission" there. Should have said:<br>
                    <br>
                    <span>My view is still that the attack is enabled by
                      an </span><span><b>omission</b> in OAuth of the
                      AS identifying itself in the authorization
                      response. I think the fix should be at that layer
                      too. Progress in the OAuth WG isn't exactly
                      promising though... </span><br>
                    <span class="">
                      <div class="gmail_extra"><br>
                        <div class="gmail_quote">On Sat, Apr 23, 2016 at
                          5:36 AM, Torsten Lodderstedt <span dir="ltr"><<a
                              moz-do-not-send="true"
                              class="moz-txt-link-abbreviated"
                              href="mailto:torsten@lodderstedt.net"><a class="moz-txt-link-abbreviated" href="mailto:torsten@lodderstedt.net">torsten@lodderstedt.net</a></a>></span>
                          wrote:<br>
                          <blockquote class="gmail_quote"
                            style="margin:0 0 0 .8ex;border-left:1px
                            #ccc solid;padding-left:1ex"><span>Am
                              15.04.2016 um 19:05 schrieb Brian
                              Campbell:<br>
                              <blockquote class="gmail_quote"
                                style="margin:0 0 0 .8ex;border-left:1px
                                #ccc solid;padding-left:1ex"> My view is
                                still that the attack is enabled by an
                                commission in OAuth of the AS
                                identifying itself in the authorization
                                response. I think the fix should be at
                                that layer too. Progress in the OAuth WG
                                isn't exactly promising though... <br>
                              </blockquote>
                            </span> Why don`t we bring this discussion
                            to the OAuth WG? It`s nearly the same group
                            of people as on this list.<br>
                          </blockquote>
                        </div>
                        <br>
                      </div>
                    </span></div>
                </blockquote>
              </div>
              <br>
              _______________________________________________<br>
              Openid-specs-ab mailing list<br>
              <a moz-do-not-send="true"
                href="mailto:Openid-specs-ab@lists.openid.net">Openid-specs-ab@lists.openid.net</a><br>
              <a moz-do-not-send="true"
                href="http://lists.openid.net/mailman/listinfo/openid-specs-ab"
                rel="noreferrer" target="_blank">http://lists.openid.net/mailman/listinfo/openid-specs-ab</a><br>
              <br>
            </blockquote>
          </div>
          <br>
        </div>
        <br>
        <fieldset class="mimeAttachmentHeader"></fieldset>
        <br>
        <pre wrap="">_______________________________________________
Openid-specs-ab mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:Openid-specs-ab@lists.openid.net">Openid-specs-ab@lists.openid.net</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="http://lists.openid.net/mailman/listinfo/openid-specs-ab">http://lists.openid.net/mailman/listinfo/openid-specs-ab</a>
</pre>
      </blockquote>
      <br>
    </blockquote>
    <br>
  </body>
</html>