{"id":2924,"date":"2012-04-23T07:00:38","date_gmt":"2012-04-23T15:00:38","guid":{"rendered":"http:\/\/www.formtek.com\/blog\/?p=2924"},"modified":"2012-04-23T07:00:38","modified_gmt":"2012-04-23T15:00:38","slug":"single-sign-ontechnology-security-flaws-prove-worrisome","status":"publish","type":"post","link":"https:\/\/formtek.com\/blog\/single-sign-ontechnology-security-flaws-prove-worrisome\/","title":{"rendered":"Single Sign On\/Technology: Security Flaws Prove Worrisome"},"content":{"rendered":"<p><a title=\"Single Sign On (SSO) defintiion\" href=\"http:\/\/en.wikipedia.org\/wiki\/Single_sign-on\" target=\"_blank\">Single sign-on (SSO)<\/a> creates a single authentication mechanism that allows a user to gain access to multiple software systems after logging in once. \u00a0It eliminates the need to separately login to each application that the user interacts with and reduced complexity for the user since only a single password is used across all applications. \u00a0SSO is often used by businesses for users to access applications running within the local internet, but it increasingly is being used by consumer web-based application.<\/p>\n<p><a title=\"OpenID web site\" href=\"http:\/\/openid.net\/\" target=\"_blank\">OpenID <\/a>is a popular web application SSO authentiction mechanism that is used by Google, PayPal, Facebook, JanRain, Freelancer, FarmVille, Sears.com, Universal Music Group, France Telecom, Novell\u00a0and quite a few other consumer web sites. \u00a0In fact, as of 2009 there were <a title=\"OpenID users and web sites\" href=\"http:\/\/openid.net\/2009\/12\/16\/openid-2009-year-in-review\/\" target=\"_blank\">over one billion OpenID enabled user accounts and more than 50,000 web sites<\/a> accepting OpenID.<\/p>\n<p>But how secure is SSO? \u00a0Surprisingly it&#8217;s an area that really hasn&#8217;t been given that much attention, despite it&#8217;s increasing use. \u00a0Because of the complexity of the technology, many developers often implement SSO without a solid understanding of how it works, resulting in implementations with security flaws. \u00a0New research finds the security of SSO to be &#8220;worrisome&#8221;.<\/p>\n<p><a title=\"OpenID SSO security problem paper\" href=\"http:\/\/research.microsoft.com\/pubs\/160659\/websso-final.pdf\" target=\"_blank\">In a paper<\/a> byIndiana University and Microsoft researchers Rui Wang,\u00a0<a title=\"Shuo Chen bio\" href=\"http:\/\/www.linkedin.com\/pub\/shuo-chen\/2\/995\/16a\" target=\"_blank\">Shuo Chen<\/a>, and XiaoFeng Wang, 8 serious security flaws were found with OpenID SSO authentication. \u00a0Rui Wang <a title=\"Rui Wang comments on SSO flaws\" href=\"http:\/\/www.computerworld.com\/s\/article\/9225589\/Study_finds_major_flaws_in_single_sign_on_systems\" target=\"_blank\">commented that<\/a> &#8220;These bugs allow an unauthorized party to log into legitimate users\u2019 accounts \u2026 thereby completely defeating their authentication protection.&#8221; \u00a0XiaoFeng Wang <a title=\"XiaoFeng Wang on SSO security\" href=\"http:\/\/www.computerworld.com\/s\/article\/9225589\/Study_finds_major_flaws_in_single_sign_on_systems\" target=\"_blank\">said <\/a>that\u00a0&#8220;The problem here is that the authentication system makes life easier but it makes security management more challenging.&#8221;<\/p>\n<p>The two biggest reasons for why these flaws exist is:<\/p>\n<ul>\n<li>poor integration of web sites with the OpenID API<\/li>\n<li>lack of end-to-end security checks<\/li>\n<\/ul>\n<p>The research paper concludes that &#8221; security-critical logic flaws pervasively exist in SSO systems, which can be discovered from browser-relayed\u00a0messages and practically exploited by a party without access\u00a0to source code or other insider knowledge of these systems. \u00a0This overall situation is serious. Clearly the scale of the problem is beyond what we can cover as a single research team, so we wish this paper can be a call for a collaborative effort of the SSO community. \u00a0In addition to those reported, we are discovering and\u00a0confirming new flaws in other web SSO systems.&#8221;<\/p>\n<p><a title=\"Steve Watts bio\" href=\"http:\/\/uk.linkedin.com\/pub\/steve-watts\/27\/215\/b24\" target=\"_blank\">Steve Watts<\/a>, co-founder of SecurEnvoy <a title=\"Steve Watts on SSO security\" href=\"http:\/\/www.bobsguide.com\/guide\/news\/2012\/Mar\/19\/us-researchers-find-flaws-in-single-sign-on-uk-experts-says-this-highlights-the-need-for-2fa.html\" target=\"_blank\">said <\/a>that &#8220;The problem with SSO-based security is that it only authenticates the user when they actually log into the system concerned. And with nasties such as man-in-the-browser and plain text cookie intercepts becoming commonplace on both wireline and \u2013 in particular &#8211; wireless Internet connections, there is clearly a need for 2FA technology&#8221;.<\/p>\n<p><a title=\"Phil Lieberman\" href=\"http:\/\/www.linkedin.com\/pub\/philip-lieberman\/4\/4ba\/69b\" target=\"_blank\">Phil Lieberman<\/a> of Lieberman Software <a title=\"Phil Lieberman comments on SSO\" href=\"http:\/\/www.darkreading.com\/authentication\/167901072\/security\/news\/232602844\/web-services-single-sign-on-contain-big-flaws.html\" target=\"_blank\">said <\/a>that\u00a0&#8220;Federation and SSO are designed to make the user&#8217;s life easier, not improve or even maintain the security of their transactions. \u00a0Logon convenience has its costs, and with free authentication services, you get what you pay for. \u00a0These systems were not initially designed and hardened for financial transactions. Further, there has been precious little to no oversight over the security of their implementation. The lesson to be learned here is that many cloud-based solutions for authentication and security should be treated as unproven and insecure in most cases.&#8221;<\/p>\n<div class=\"lightsocial_container\"><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/digg.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsingle-sign-ontechnology-security-flaws-prove-worrisome%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/digg.png\" alt=\"Digg This\" title=\"Digg This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.reddit.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsingle-sign-ontechnology-security-flaws-prove-worrisome%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/reddit.png\" alt=\"Reddit This\" title=\"Reddit This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.stumbleupon.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsingle-sign-ontechnology-security-flaws-prove-worrisome%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/stumbleupon.png\" alt=\"Stumble Now!\" title=\"Stumble Now!\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/buzz.yahoo.com\/buzz?targetUrl=https%3A%2F%2Fformtek.com%2Fblog%2Fsingle-sign-ontechnology-security-flaws-prove-worrisome%2F&amp;headline=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/yahoo_buzz.png\" alt=\"Buzz This\" title=\"Buzz This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dzone.com\/links\/add.html?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsingle-sign-ontechnology-security-flaws-prove-worrisome%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dzone.png\" alt=\"Vote on DZone\" title=\"Vote on DZone\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.facebook.com\/sharer.php?t=&amp;u=https%3A%2F%2Fformtek.com%2Fblog%2Fsingle-sign-ontechnology-security-flaws-prove-worrisome%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/facebook.png\" alt=\"Share on Facebook\" title=\"Share on Facebook\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/delicious.com\/save?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsingle-sign-ontechnology-security-flaws-prove-worrisome%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/delicious.png\" alt=\"Bookmark this on Delicious\" title=\"Bookmark this on Delicious\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dotnetkicks.com\/kick\/?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsingle-sign-ontechnology-security-flaws-prove-worrisome%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetkicks.png\" alt=\"Kick It on DotNetKicks.com\" title=\"Kick It on DotNetKicks.com\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/dotnetshoutout.com\/Submit?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsingle-sign-ontechnology-security-flaws-prove-worrisome%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetshoutout.png\" alt=\"Shout it\" title=\"Shout it\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.linkedin.com\/shareArticle?mini=true&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsingle-sign-ontechnology-security-flaws-prove-worrisome%2F&amp;title=&amp;summary=&amp;source=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/linkedin.png\" alt=\"Share on LinkedIn\" title=\"Share on LinkedIn\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.technorati.com\/faves?add=https%3A%2F%2Fformtek.com%2Fblog%2Fsingle-sign-ontechnology-security-flaws-prove-worrisome%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/technorati.png\" alt=\"Bookmark this on Technorati\" title=\"Bookmark this on Technorati\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/twitter.com\/home?status=Reading+https%3A%2F%2Fformtek.com%2Fblog%2Fsingle-sign-ontechnology-security-flaws-prove-worrisome%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/twitter.png\" alt=\"Post on Twitter\" title=\"Post on Twitter\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.google.com\/buzz\/post?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsingle-sign-ontechnology-security-flaws-prove-worrisome%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/google_buzz.png\" alt=\"Google Buzz (aka. Google Reader)\" title=\"Google Buzz (aka. Google Reader)\" \/><\/a><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>Single sign-on (SSO) creates a single authentication mechanism that allows a user to gain access to multiple software systems after logging in once. \u00a0It eliminates the need to separately login to each application that the user interacts with and reduced<span class=\"ellipsis\">&hellip;<\/span><\/p>\n<div class=\"read-more\"><a href=\"https:\/\/formtek.com\/blog\/single-sign-ontechnology-security-flaws-prove-worrisome\/\">Read more &#8250;<\/a><\/div>\n<p><!-- end of .read-more --><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31,36],"tags":[],"class_list":["post-2924","post","type-post","status-publish","format-standard","hentry","category-security","category-technology"],"_links":{"self":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/2924","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/comments?post=2924"}],"version-history":[{"count":0,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/2924\/revisions"}],"wp:attachment":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/media?parent=2924"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/categories?post=2924"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/tags?post=2924"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}