<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://tcwiki.azurewebsites.net/index.php?action=history&amp;feed=atom&amp;title=Bearer_Tokens_Considered_Harmful</id>
		<title>Bearer Tokens Considered Harmful - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://tcwiki.azurewebsites.net/index.php?action=history&amp;feed=atom&amp;title=Bearer_Tokens_Considered_Harmful"/>
		<link rel="alternate" type="text/html" href="http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;action=history"/>
		<updated>2026-07-28T03:11:46Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.4</generator>

	<entry>
		<id>http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=7940&amp;oldid=prev</id>
		<title>Tom: /* Problems */</title>
		<link rel="alternate" type="text/html" href="http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=7940&amp;oldid=prev"/>
				<updated>2020-08-26T20:42:30Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Problems&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 20:42, 26 August 2020&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l23&quot; &gt;Line 23:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 23:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Now we have a large number of people using OAuth 2.0, but increasing evidence that not only can Facebook not get it right,&amp;lt;ref&amp;gt;Thomas Brewster, ''How Facebook Was Hacked And Why It's A Disaster For Internet Security.'' (2018-09-28)Forbes https://www.forbes.com/sites/thomasbrewster/2018/09/29/how-facebook-was-hacked-and-why-its-a-disaster-for-internet-security/#5a64b0b82033&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;Issie Lapowsky, ''The Facebook Hack Exposes an Internet-Wide Failure.'' (2018-10-02) Wired https://www.wired.com/story/facebook-hack-single-sign-on-data-exposed/?CNDID=45183233&amp;amp;mbid=nl_100218_daily_list1_p4&amp;lt;/ref&amp;gt; but the UK Open Banking community is not convinced that bearer tokens are acceptable for payment protocols. Note that Facebook acknowledged that they &amp;quot;cannot fix this&amp;quot; as early as 2014&amp;lt;ref&amp;gt;Wang Wei, ''Hacking Facebook User 'Access Token' with Man-in-the-Middle Attack'' (2014-03-11)The Hacker News https://thehackernews.com/2014/03/hacking-facebook-user-access-token-with.html&amp;lt;/ref&amp;gt; but they again have promised to find a solution. Does anyone still believe that it will be possible for them to do that?&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Now we have a large number of people using OAuth 2.0, but increasing evidence that not only can Facebook not get it right,&amp;lt;ref&amp;gt;Thomas Brewster, ''How Facebook Was Hacked And Why It's A Disaster For Internet Security.'' (2018-09-28)Forbes https://www.forbes.com/sites/thomasbrewster/2018/09/29/how-facebook-was-hacked-and-why-its-a-disaster-for-internet-security/#5a64b0b82033&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;Issie Lapowsky, ''The Facebook Hack Exposes an Internet-Wide Failure.'' (2018-10-02) Wired https://www.wired.com/story/facebook-hack-single-sign-on-data-exposed/?CNDID=45183233&amp;amp;mbid=nl_100218_daily_list1_p4&amp;lt;/ref&amp;gt; but the UK Open Banking community is not convinced that bearer tokens are acceptable for payment protocols. Note that Facebook acknowledged that they &amp;quot;cannot fix this&amp;quot; as early as 2014&amp;lt;ref&amp;gt;Wang Wei, ''Hacking Facebook User 'Access Token' with Man-in-the-Middle Attack'' (2014-03-11)The Hacker News https://thehackernews.com/2014/03/hacking-facebook-user-access-token-with.html&amp;lt;/ref&amp;gt; but they again have promised to find a solution. Does anyone still believe that it will be possible for them to do that?&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;To be clear, the bearer token worked as designed; it gave the holder access to a single resource. What all the binding stuff is designed to do is assure that the access is only available to the user that was given the grant. So there are two problems here: (1) the bearer token is not bound to the user and the resource site, (2) the access granted by the token is to a resource that allows additional privilege grants beyond itself. In the case of Facebook, and many other sites that I have seen, the resource even allowed the user to impersonate other users.&amp;#160; In Facebook this was benignly labeled as the &amp;quot;View-As&amp;quot; feature. In European open banking proposals a payment initiator can impersonate the user to get money from their account. I don't believe that any of the OpenID or OAuth standards allows &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;impersonation&lt;/del&gt;, but that doesn't stop developers from thinking that they need it and are smart enough to control it. But neither is true in practice.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;To be clear, the bearer token worked as designed; it gave the holder access to a single resource. What all the binding stuff is designed to do is assure that the access is only available to the user that was given the grant. So there are two problems here: (1) the bearer token is not bound to the user and the resource site, (2) the access granted by the token is to a resource that allows additional privilege grants beyond itself. In the case of Facebook, and many other sites that I have seen, the resource even allowed the user to impersonate other users.&amp;#160; In Facebook this was benignly labeled as the &amp;quot;View-As&amp;quot; feature. In European open banking proposals a payment initiator can impersonate the user to get money from their account. I don't believe that any of the OpenID or OAuth standards allows &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[[Impersonation]]&lt;/ins&gt;, but that doesn't stop developers from thinking that they need it and are smart enough to control it. But neither is true in practice.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Solution==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Solution==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Tom</name></author>	</entry>

	<entry>
		<id>http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=7939&amp;oldid=prev</id>
		<title>Tom: /* Solution */</title>
		<link rel="alternate" type="text/html" href="http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=7939&amp;oldid=prev"/>
				<updated>2020-08-26T20:41:32Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Solution&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 20:41, 26 August 2020&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l28&quot; &gt;Line 28:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 28:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The obvious solution is a different token type in OAuth 2.0, or perhaps even a different version of OAuth, I guess 3.0. The obvious objection will be that &amp;quot;everybody is using OAuth 2.0 with bearer, we have no choice.&amp;quot; The obvious answer is &amp;quot;bollocks, let's do this thing right!&amp;quot; Besides, if so few developers are able to handle the security complexity of OAuth 2.0 as it is, then we would be better off with something new that has securely bound to the user, or perhaps to the user's device. Given the ubiquitous deployment of computers with trusted execution environment, the later should be eminently practical. Of course [[FIDO U2F]] could provide this functionality as well, so perhaps the predicted wide deployment of web authentication will provide an answer. That protocol does require a binding of the web site to the user token. While that does require a trusted user agent, we know that Android, at least, is committed to validating the source of any app that validates the site binding. Apple seems to take user issues seriously, so there is a good chance they will follow suit.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The obvious solution is a different token type in OAuth 2.0, or perhaps even a different version of OAuth, I guess 3.0. The obvious objection will be that &amp;quot;everybody is using OAuth 2.0 with bearer, we have no choice.&amp;quot; The obvious answer is &amp;quot;bollocks, let's do this thing right!&amp;quot; Besides, if so few developers are able to handle the security complexity of OAuth 2.0 as it is, then we would be better off with something new that has securely bound to the user, or perhaps to the user's device. Given the ubiquitous deployment of computers with trusted execution environment, the later should be eminently practical. Of course [[FIDO U2F]] could provide this functionality as well, so perhaps the predicted wide deployment of web authentication will provide an answer. That protocol does require a binding of the web site to the user token. While that does require a trusted user agent, we know that Android, at least, is committed to validating the source of any app that validates the site binding. Apple seems to take user issues seriously, so there is a good chance they will follow suit.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In summary, OAuth 2.0 has wide adoption across a wide range of deployments. This success is fantastic and somehow it should be leveraged to lead us to the next level of security. I personally have no confidence in the complex binding protocols now being proposed and strongly recommend a new token design with binding as a part of the token itself, not in some separate process that a developer needs to get right for a deployment to be secure. I would also explicitly ban the use of &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;impersonation&lt;/del&gt;. The opposite view is that the OAuth 2.0 standards are successful precisely because they are flexible and not too hard line on security. I suspect it is obvious that I tend to be hard line on security, which is what applications like banking require.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In summary, OAuth 2.0 has wide adoption across a wide range of deployments. This success is fantastic and somehow it should be leveraged to lead us to the next level of security. I personally have no confidence in the complex binding protocols now being proposed and strongly recommend a new token design with binding as a part of the token itself, not in some separate process that a developer needs to get right for a deployment to be secure. I would also explicitly ban the use of &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[[Impersonation]]&lt;/ins&gt;. The opposite view is that the OAuth 2.0 standards are successful precisely because they are flexible and not too hard line on security. I suspect it is obvious that I tend to be hard line on security, which is what applications like banking require.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==What's in a Name==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==What's in a Name==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Tom</name></author>	</entry>

	<entry>
		<id>http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=5379&amp;oldid=prev</id>
		<title>Tom: /* Solution */</title>
		<link rel="alternate" type="text/html" href="http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=5379&amp;oldid=prev"/>
				<updated>2019-04-13T02:13:28Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Solution&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 02:13, 13 April 2019&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l26&quot; &gt;Line 26:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 26:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Solution==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Solution==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The obvious solution is a different token type in OAuth 2.0, or perhaps even a different version of OAuth, I guess 3.0. The obvious objection will be that &amp;quot;everybody is using OAuth 2.0 with bearer, we have no choice.&amp;quot; The obvious answer is &amp;quot;bollocks, let's do this thing right!&amp;quot; Besides, if so few developers are able to handle the security complexity of OAuth 2.0 as it is, then we would be better off with something new that has securely bound to the user, or perhaps to the user's device. Given the ubiquitous deployment of computers with trusted execution environment, the later should be eminently practical. Of course FIDO U2F could provide this functionality as well, so perhaps the predicted wide deployment of web authentication will provide an answer. That protocol does require a binding of the web site to the user token. While that does require a trusted user agent, we know that Android, at least, is committed to validating the source of any app that validates the site binding. Apple seems to take user issues seriously, so there is a good chance they will follow suit.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The obvious solution is a different token type in OAuth 2.0, or perhaps even a different version of OAuth, I guess 3.0. The obvious objection will be that &amp;quot;everybody is using OAuth 2.0 with bearer, we have no choice.&amp;quot; The obvious answer is &amp;quot;bollocks, let's do this thing right!&amp;quot; Besides, if so few developers are able to handle the security complexity of OAuth 2.0 as it is, then we would be better off with something new that has securely bound to the user, or perhaps to the user's device. Given the ubiquitous deployment of computers with trusted execution environment, the later should be eminently practical. Of course &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[[&lt;/ins&gt;FIDO U2F&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;]] &lt;/ins&gt;could provide this functionality as well, so perhaps the predicted wide deployment of web authentication will provide an answer. That protocol does require a binding of the web site to the user token. While that does require a trusted user agent, we know that Android, at least, is committed to validating the source of any app that validates the site binding. Apple seems to take user issues seriously, so there is a good chance they will follow suit.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In summary, OAuth 2.0 has wide adoption across a wide range of deployments. This success is fantastic and somehow it should be leveraged to lead us to the next level of security. I personally have no confidence in the complex binding protocols now being proposed and strongly recommend a new token design with binding as a part of the token itself, not in some separate process that a developer needs to get right for a deployment to be secure. I would also explicitly ban the use of impersonation. The opposite view is that the OAuth 2.0 standards are successful precisely because they are flexible and not too hard line on security. I suspect it is obvious that I tend to be hard line on security, which is what applications like banking require.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In summary, OAuth 2.0 has wide adoption across a wide range of deployments. This success is fantastic and somehow it should be leveraged to lead us to the next level of security. I personally have no confidence in the complex binding protocols now being proposed and strongly recommend a new token design with binding as a part of the token itself, not in some separate process that a developer needs to get right for a deployment to be secure. I would also explicitly ban the use of impersonation. The opposite view is that the OAuth 2.0 standards are successful precisely because they are flexible and not too hard line on security. I suspect it is obvious that I tend to be hard line on security, which is what applications like banking require.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Tom</name></author>	</entry>

	<entry>
		<id>http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=4149&amp;oldid=prev</id>
		<title>Tom: /* Introduction */</title>
		<link rel="alternate" type="text/html" href="http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=4149&amp;oldid=prev"/>
				<updated>2018-11-14T00:28:09Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 00:28, 14 November 2018&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l6&quot; &gt;Line 6:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 6:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This paper discusses the limitations of Channel Binding or other half-way measures to fix a broken security feature introduced with OAuth 2.0,&amp;lt;ref&amp;gt;D. Hardt, ''The OAuth 2.0 Authorization Framework.'' RFC 6749&amp;lt;/ref&amp;gt; Bearer Tokens.&amp;lt;ref&amp;gt;M. Jones, D. Hardt, ''The OAuth 2.0 Authorization Framework: Bearer Token Usage.'' RFC 6750&amp;lt;/ref&amp;gt; The conclusion is that Bearer Tokens themselves are the problem and we need to be working on finding better ways to authorize the release of resources on the web.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This paper discusses the limitations of Channel Binding or other half-way measures to fix a broken security feature introduced with OAuth 2.0,&amp;lt;ref&amp;gt;D. Hardt, ''The OAuth 2.0 Authorization Framework.'' RFC 6749&amp;lt;/ref&amp;gt; Bearer Tokens.&amp;lt;ref&amp;gt;M. Jones, D. Hardt, ''The OAuth 2.0 Authorization Framework: Bearer Token Usage.'' RFC 6750&amp;lt;/ref&amp;gt; The conclusion is that Bearer Tokens themselves are the problem and we need to be working on finding better ways to authorize the release of resources on the web.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;'''Author: [http://tomjones.us Tom Jones]&amp;#160; Date: 2018-10-03 revision 2018-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;10&lt;/del&gt;-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;25&lt;/del&gt;'''&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;'''Author: [http://tomjones.us Tom Jones]&amp;#160; Date: 2018-10-03 revision 2018-&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;11&lt;/ins&gt;-&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;11&lt;/ins&gt;'''&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==History==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==History==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Tom</name></author>	</entry>

	<entry>
		<id>http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=4148&amp;oldid=prev</id>
		<title>Tom: /* Problems */</title>
		<link rel="alternate" type="text/html" href="http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=4148&amp;oldid=prev"/>
				<updated>2018-11-14T00:27:18Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Problems&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 00:27, 14 November 2018&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l19&quot; &gt;Line 19:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 19:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;It was into this environment that OAuth 1.0 (using a convoluted version of shared secrets) morphed into [[OAuth 2.0]] (using public key) which was still based on one computer talking to another computer. Among the many fields that could be addressed was the HTTP header with the type of authorization used, (e.g. Authorization: Bearer mF_9.B5f-4.1JqM). Unfortunately only type &amp;quot;Bearer&amp;quot; is actually supported by any existing implementation. So, in order to expand the functionality of authorization, all modifications to date have been to hack the bearer token in some way to make it more secure. The final solution has been Token Binding&amp;lt;ref&amp;gt;A. Popov +5, Token Binding over HTTP (approved but not yet released RFC) https://datatracker.ietf.org/doc/draft-ietf-tokbind-https/ &amp;lt;/ref&amp;gt; only the first of many standards is listing in the draft RFC of 3 to 5 depending on how you count. If you have been counting this is now the hack of a hack of hack. Also known as the great grand hack. But the real problem with the latest (token binding) hack is that while the earlier hacks could be implemented at the Enterprise level by the same development team, token binding requires that all developers of internet solutions implement the hack with no security vulnerabilities. That is certainly something that has never worked in the past.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;It was into this environment that OAuth 1.0 (using a convoluted version of shared secrets) morphed into [[OAuth 2.0]] (using public key) which was still based on one computer talking to another computer. Among the many fields that could be addressed was the HTTP header with the type of authorization used, (e.g. Authorization: Bearer mF_9.B5f-4.1JqM). Unfortunately only type &amp;quot;Bearer&amp;quot; is actually supported by any existing implementation. So, in order to expand the functionality of authorization, all modifications to date have been to hack the bearer token in some way to make it more secure. The final solution has been Token Binding&amp;lt;ref&amp;gt;A. Popov +5, Token Binding over HTTP (approved but not yet released RFC) https://datatracker.ietf.org/doc/draft-ietf-tokbind-https/ &amp;lt;/ref&amp;gt; only the first of many standards is listing in the draft RFC of 3 to 5 depending on how you count. If you have been counting this is now the hack of a hack of hack. Also known as the great grand hack. But the real problem with the latest (token binding) hack is that while the earlier hacks could be implemented at the Enterprise level by the same development team, token binding requires that all developers of internet solutions implement the hack with no security vulnerabilities. That is certainly something that has never worked in the past.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The assumption that binding the token to the HTTPS channel will in some manner assure that only sites trusted by the user are able to access user information is flawed. The [[Identifier]] in the HTTPS channel is simply the DN in an [[X.509 &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;certificate&lt;/del&gt;]]. That certificate does chain up to a root authority which is trusted by the browser manufacturer, which offers some level of [[Assurance]], but says little about the real-world [[Entity]] behind the [[Web Site]]. It is possible for the site to acquire an [[EV Cert]] which will provide some [[Assurance]] that the site is grounded in some real-world address, but none as to the trust that the user should place in that [[Entity]].&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The assumption that binding the token to the HTTPS channel will in some manner assure that only sites trusted by the user are able to access user information is flawed. The [[Identifier]] in the HTTPS channel is simply the DN in an [[X.509 &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Certificate&lt;/ins&gt;]]. That certificate does chain up to a root authority which is trusted by the browser manufacturer, which offers some level of [[Assurance]], but says little about the real-world [[Entity]] behind the [[Web Site]]. It is possible for the site to acquire an [[EV Cert]] which will provide some [[Assurance]] that the site is grounded in some real-world address, but none as to the trust that the user should place in that [[Entity]].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Now we have a large number of people using OAuth 2.0, but increasing evidence that not only can Facebook not get it right,&amp;lt;ref&amp;gt;Thomas Brewster, ''How Facebook Was Hacked And Why It's A Disaster For Internet Security.'' (2018-09-28)Forbes https://www.forbes.com/sites/thomasbrewster/2018/09/29/how-facebook-was-hacked-and-why-its-a-disaster-for-internet-security/#5a64b0b82033&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;Issie Lapowsky, ''The Facebook Hack Exposes an Internet-Wide Failure.'' (2018-10-02) Wired https://www.wired.com/story/facebook-hack-single-sign-on-data-exposed/?CNDID=45183233&amp;amp;mbid=nl_100218_daily_list1_p4&amp;lt;/ref&amp;gt; but the UK Open Banking community is not convinced that bearer tokens are acceptable for payment protocols. Note that Facebook acknowledged that they &amp;quot;cannot fix this&amp;quot; as early as 2014&amp;lt;ref&amp;gt;Wang Wei, ''Hacking Facebook User 'Access Token' with Man-in-the-Middle Attack'' (2014-03-11)The Hacker News https://thehackernews.com/2014/03/hacking-facebook-user-access-token-with.html&amp;lt;/ref&amp;gt; but they again have promised to find a solution. Does anyone still believe that it will be possible for them to do that?&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Now we have a large number of people using OAuth 2.0, but increasing evidence that not only can Facebook not get it right,&amp;lt;ref&amp;gt;Thomas Brewster, ''How Facebook Was Hacked And Why It's A Disaster For Internet Security.'' (2018-09-28)Forbes https://www.forbes.com/sites/thomasbrewster/2018/09/29/how-facebook-was-hacked-and-why-its-a-disaster-for-internet-security/#5a64b0b82033&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;Issie Lapowsky, ''The Facebook Hack Exposes an Internet-Wide Failure.'' (2018-10-02) Wired https://www.wired.com/story/facebook-hack-single-sign-on-data-exposed/?CNDID=45183233&amp;amp;mbid=nl_100218_daily_list1_p4&amp;lt;/ref&amp;gt; but the UK Open Banking community is not convinced that bearer tokens are acceptable for payment protocols. Note that Facebook acknowledged that they &amp;quot;cannot fix this&amp;quot; as early as 2014&amp;lt;ref&amp;gt;Wang Wei, ''Hacking Facebook User 'Access Token' with Man-in-the-Middle Attack'' (2014-03-11)The Hacker News https://thehackernews.com/2014/03/hacking-facebook-user-access-token-with.html&amp;lt;/ref&amp;gt; but they again have promised to find a solution. Does anyone still believe that it will be possible for them to do that?&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Tom</name></author>	</entry>

	<entry>
		<id>http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=4147&amp;oldid=prev</id>
		<title>Tom: /* Problems */</title>
		<link rel="alternate" type="text/html" href="http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=4147&amp;oldid=prev"/>
				<updated>2018-11-14T00:26:36Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Problems&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 00:26, 14 November 2018&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l19&quot; &gt;Line 19:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 19:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;It was into this environment that OAuth 1.0 (using a convoluted version of shared secrets) morphed into [[OAuth 2.0]] (using public key) which was still based on one computer talking to another computer. Among the many fields that could be addressed was the HTTP header with the type of authorization used, (e.g. Authorization: Bearer mF_9.B5f-4.1JqM). Unfortunately only type &amp;quot;Bearer&amp;quot; is actually supported by any existing implementation. So, in order to expand the functionality of authorization, all modifications to date have been to hack the bearer token in some way to make it more secure. The final solution has been Token Binding&amp;lt;ref&amp;gt;A. Popov +5, Token Binding over HTTP (approved but not yet released RFC) https://datatracker.ietf.org/doc/draft-ietf-tokbind-https/ &amp;lt;/ref&amp;gt; only the first of many standards is listing in the draft RFC of 3 to 5 depending on how you count. If you have been counting this is now the hack of a hack of hack. Also known as the great grand hack. But the real problem with the latest (token binding) hack is that while the earlier hacks could be implemented at the Enterprise level by the same development team, token binding requires that all developers of internet solutions implement the hack with no security vulnerabilities. That is certainly something that has never worked in the past.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;It was into this environment that OAuth 1.0 (using a convoluted version of shared secrets) morphed into [[OAuth 2.0]] (using public key) which was still based on one computer talking to another computer. Among the many fields that could be addressed was the HTTP header with the type of authorization used, (e.g. Authorization: Bearer mF_9.B5f-4.1JqM). Unfortunately only type &amp;quot;Bearer&amp;quot; is actually supported by any existing implementation. So, in order to expand the functionality of authorization, all modifications to date have been to hack the bearer token in some way to make it more secure. The final solution has been Token Binding&amp;lt;ref&amp;gt;A. Popov +5, Token Binding over HTTP (approved but not yet released RFC) https://datatracker.ietf.org/doc/draft-ietf-tokbind-https/ &amp;lt;/ref&amp;gt; only the first of many standards is listing in the draft RFC of 3 to 5 depending on how you count. If you have been counting this is now the hack of a hack of hack. Also known as the great grand hack. But the real problem with the latest (token binding) hack is that while the earlier hacks could be implemented at the Enterprise level by the same development team, token binding requires that all developers of internet solutions implement the hack with no security vulnerabilities. That is certainly something that has never worked in the past.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The assumption that binding the token to the HTTPS channel will in some manner assure that only sites trusted by the user are able to access user information is flawed. The [[Identifier]] in the HTTPS channel is simply the DN in an [[X.509]] &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;certificate&lt;/del&gt;. That certificate does chain up to a root authority which is trusted by the browser manufacturer, which offers some level of [[Assurance]], but says little about the real-world [[Entity]] behind the [[Web Site]]. It is possible for the site to acquire an [[EV Cert]] which will provide some [[Assurance]] that the site is grounded in some real-world address, but none as to the trust that the user should place in that [[Entity]].&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The assumption that binding the token to the HTTPS channel will in some manner assure that only sites trusted by the user are able to access user information is flawed. The [[Identifier]] in the HTTPS channel is simply the DN in an [[X.509 &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;certificate&lt;/ins&gt;]]. That certificate does chain up to a root authority which is trusted by the browser manufacturer, which offers some level of [[Assurance]], but says little about the real-world [[Entity]] behind the [[Web Site]]. It is possible for the site to acquire an [[EV Cert]] which will provide some [[Assurance]] that the site is grounded in some real-world address, but none as to the trust that the user should place in that [[Entity]].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Now we have a large number of people using OAuth 2.0, but increasing evidence that not only can Facebook not get it right,&amp;lt;ref&amp;gt;Thomas Brewster, ''How Facebook Was Hacked And Why It's A Disaster For Internet Security.'' (2018-09-28)Forbes https://www.forbes.com/sites/thomasbrewster/2018/09/29/how-facebook-was-hacked-and-why-its-a-disaster-for-internet-security/#5a64b0b82033&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;Issie Lapowsky, ''The Facebook Hack Exposes an Internet-Wide Failure.'' (2018-10-02) Wired https://www.wired.com/story/facebook-hack-single-sign-on-data-exposed/?CNDID=45183233&amp;amp;mbid=nl_100218_daily_list1_p4&amp;lt;/ref&amp;gt; but the UK Open Banking community is not convinced that bearer tokens are acceptable for payment protocols. Note that Facebook acknowledged that they &amp;quot;cannot fix this&amp;quot; as early as 2014&amp;lt;ref&amp;gt;Wang Wei, ''Hacking Facebook User 'Access Token' with Man-in-the-Middle Attack'' (2014-03-11)The Hacker News https://thehackernews.com/2014/03/hacking-facebook-user-access-token-with.html&amp;lt;/ref&amp;gt; but they again have promised to find a solution. Does anyone still believe that it will be possible for them to do that?&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Now we have a large number of people using OAuth 2.0, but increasing evidence that not only can Facebook not get it right,&amp;lt;ref&amp;gt;Thomas Brewster, ''How Facebook Was Hacked And Why It's A Disaster For Internet Security.'' (2018-09-28)Forbes https://www.forbes.com/sites/thomasbrewster/2018/09/29/how-facebook-was-hacked-and-why-its-a-disaster-for-internet-security/#5a64b0b82033&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;Issie Lapowsky, ''The Facebook Hack Exposes an Internet-Wide Failure.'' (2018-10-02) Wired https://www.wired.com/story/facebook-hack-single-sign-on-data-exposed/?CNDID=45183233&amp;amp;mbid=nl_100218_daily_list1_p4&amp;lt;/ref&amp;gt; but the UK Open Banking community is not convinced that bearer tokens are acceptable for payment protocols. Note that Facebook acknowledged that they &amp;quot;cannot fix this&amp;quot; as early as 2014&amp;lt;ref&amp;gt;Wang Wei, ''Hacking Facebook User 'Access Token' with Man-in-the-Middle Attack'' (2014-03-11)The Hacker News https://thehackernews.com/2014/03/hacking-facebook-user-access-token-with.html&amp;lt;/ref&amp;gt; but they again have promised to find a solution. Does anyone still believe that it will be possible for them to do that?&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Tom</name></author>	</entry>

	<entry>
		<id>http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=4146&amp;oldid=prev</id>
		<title>Tom: /* Problems */</title>
		<link rel="alternate" type="text/html" href="http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=4146&amp;oldid=prev"/>
				<updated>2018-11-14T00:25:45Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Problems&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 00:25, 14 November 2018&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l18&quot; &gt;Line 18:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 18:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Problems==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Problems==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;It was into this environment that OAuth 1.0 (using a convoluted version of shared secrets) morphed into [[OAuth 2.0]] (using public key) which was still based on one computer talking to another computer. Among the many fields that could be addressed was the HTTP header with the type of authorization used, (e.g. Authorization: Bearer mF_9.B5f-4.1JqM). Unfortunately only type &amp;quot;Bearer&amp;quot; is actually supported by any existing implementation. So, in order to expand the functionality of authorization, all modifications to date have been to hack the bearer token in some way to make it more secure. The final solution has been Token Binding&amp;lt;ref&amp;gt;A. Popov +5, Token Binding over HTTP (approved but not yet released RFC) https://datatracker.ietf.org/doc/draft-ietf-tokbind-https/ &amp;lt;/ref&amp;gt; only the first of many standards is listing in the draft RFC of 3 to 5 depending on how you count. If you have been counting this is now the hack of a hack of hack. Also known as the great grand hack. But the real problem with the latest (token binding) hack is that while the earlier hacks could be implemented at the Enterprise level by the same development team, token binding requires that all developers of internet solutions implement the hack with no security vulnerabilities. That is certainly something that has never worked in the past.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;It was into this environment that OAuth 1.0 (using a convoluted version of shared secrets) morphed into [[OAuth 2.0]] (using public key) which was still based on one computer talking to another computer. Among the many fields that could be addressed was the HTTP header with the type of authorization used, (e.g. Authorization: Bearer mF_9.B5f-4.1JqM). Unfortunately only type &amp;quot;Bearer&amp;quot; is actually supported by any existing implementation. So, in order to expand the functionality of authorization, all modifications to date have been to hack the bearer token in some way to make it more secure. The final solution has been Token Binding&amp;lt;ref&amp;gt;A. Popov +5, Token Binding over HTTP (approved but not yet released RFC) https://datatracker.ietf.org/doc/draft-ietf-tokbind-https/ &amp;lt;/ref&amp;gt; only the first of many standards is listing in the draft RFC of 3 to 5 depending on how you count. If you have been counting this is now the hack of a hack of hack. Also known as the great grand hack. But the real problem with the latest (token binding) hack is that while the earlier hacks could be implemented at the Enterprise level by the same development team, token binding requires that all developers of internet solutions implement the hack with no security vulnerabilities. That is certainly something that has never worked in the past.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;The assumption that binding the token to the HTTPS channel will in some manner assure that only sites trusted by the user are able to access user information is flawed. The [[Identifier]] in the HTTPS channel is simply the DN in an [[X.509]] certificate. That certificate does chain up to a root authority which is trusted by the browser manufacturer, which offers some level of [[Assurance]], but says little about the real-world [[Entity]] behind the [[Web Site]]. It is possible for the site to acquire an [[EV Cert]] which will provide some [[Assurance]] that the site is grounded in some real-world address, but none as to the trust that the user should place in that [[Entity]].&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Now we have a large number of people using OAuth 2.0, but increasing evidence that not only can Facebook not get it right,&amp;lt;ref&amp;gt;Thomas Brewster, ''How Facebook Was Hacked And Why It's A Disaster For Internet Security.'' (2018-09-28)Forbes https://www.forbes.com/sites/thomasbrewster/2018/09/29/how-facebook-was-hacked-and-why-its-a-disaster-for-internet-security/#5a64b0b82033&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;Issie Lapowsky, ''The Facebook Hack Exposes an Internet-Wide Failure.'' (2018-10-02) Wired https://www.wired.com/story/facebook-hack-single-sign-on-data-exposed/?CNDID=45183233&amp;amp;mbid=nl_100218_daily_list1_p4&amp;lt;/ref&amp;gt; but the UK Open Banking community is not convinced that bearer tokens are acceptable for payment protocols. Note that Facebook acknowledged that they &amp;quot;cannot fix this&amp;quot; as early as 2014&amp;lt;ref&amp;gt;Wang Wei, ''Hacking Facebook User 'Access Token' with Man-in-the-Middle Attack'' (2014-03-11)The Hacker News https://thehackernews.com/2014/03/hacking-facebook-user-access-token-with.html&amp;lt;/ref&amp;gt; but they again have promised to find a solution. Does anyone still believe that it will be possible for them to do that?&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Now we have a large number of people using OAuth 2.0, but increasing evidence that not only can Facebook not get it right,&amp;lt;ref&amp;gt;Thomas Brewster, ''How Facebook Was Hacked And Why It's A Disaster For Internet Security.'' (2018-09-28)Forbes https://www.forbes.com/sites/thomasbrewster/2018/09/29/how-facebook-was-hacked-and-why-its-a-disaster-for-internet-security/#5a64b0b82033&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;Issie Lapowsky, ''The Facebook Hack Exposes an Internet-Wide Failure.'' (2018-10-02) Wired https://www.wired.com/story/facebook-hack-single-sign-on-data-exposed/?CNDID=45183233&amp;amp;mbid=nl_100218_daily_list1_p4&amp;lt;/ref&amp;gt; but the UK Open Banking community is not convinced that bearer tokens are acceptable for payment protocols. Note that Facebook acknowledged that they &amp;quot;cannot fix this&amp;quot; as early as 2014&amp;lt;ref&amp;gt;Wang Wei, ''Hacking Facebook User 'Access Token' with Man-in-the-Middle Attack'' (2014-03-11)The Hacker News https://thehackernews.com/2014/03/hacking-facebook-user-access-token-with.html&amp;lt;/ref&amp;gt; but they again have promised to find a solution. Does anyone still believe that it will be possible for them to do that?&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Tom</name></author>	</entry>

	<entry>
		<id>http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=4129&amp;oldid=prev</id>
		<title>Tom at 21:43, 13 November 2018</title>
		<link rel="alternate" type="text/html" href="http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=4129&amp;oldid=prev"/>
				<updated>2018-11-13T21:43:02Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 21:43, 13 November 2018&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Banned: This paper was rejected&amp;#160; by the IDPro organization. Probably because it contains ideas that are not in complete agreement with the folks that fund the IDPro organization. It is a response to Brian Campbell of Ping Identity in their newsletter telling people why they should use Token Binding.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Banned: This paper was rejected&amp;#160; by the IDPro organization. Probably because it contains ideas that are not in complete agreement with the folks that fund the IDPro organization. It is a response to Brian Campbell of Ping Identity in their newsletter telling people why they should use &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[[&lt;/ins&gt;Token Binding&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;]]&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;'''This paper tells you why you should not use Token Binding.'''&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;'''This paper tells you why you should not use Token Binding.'''&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Tom</name></author>	</entry>

	<entry>
		<id>http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=3990&amp;oldid=prev</id>
		<title>Tom: /* Introduction */</title>
		<link rel="alternate" type="text/html" href="http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=3990&amp;oldid=prev"/>
				<updated>2018-10-31T19:07:27Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 19:07, 31 October 2018&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l6&quot; &gt;Line 6:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 6:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This paper discusses the limitations of Channel Binding or other half-way measures to fix a broken security feature introduced with OAuth 2.0,&amp;lt;ref&amp;gt;D. Hardt, ''The OAuth 2.0 Authorization Framework.'' RFC 6749&amp;lt;/ref&amp;gt; Bearer Tokens.&amp;lt;ref&amp;gt;M. Jones, D. Hardt, ''The OAuth 2.0 Authorization Framework: Bearer Token Usage.'' RFC 6750&amp;lt;/ref&amp;gt; The conclusion is that Bearer Tokens themselves are the problem and we need to be working on finding better ways to authorize the release of resources on the web.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This paper discusses the limitations of Channel Binding or other half-way measures to fix a broken security feature introduced with OAuth 2.0,&amp;lt;ref&amp;gt;D. Hardt, ''The OAuth 2.0 Authorization Framework.'' RFC 6749&amp;lt;/ref&amp;gt; Bearer Tokens.&amp;lt;ref&amp;gt;M. Jones, D. Hardt, ''The OAuth 2.0 Authorization Framework: Bearer Token Usage.'' RFC 6750&amp;lt;/ref&amp;gt; The conclusion is that Bearer Tokens themselves are the problem and we need to be working on finding better ways to authorize the release of resources on the web.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;'''Author: Tom Jones&amp;#160; Date: 2018-10-03 revision 2018-10-25'''&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;'''Author: &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[http://tomjones.us &lt;/ins&gt;Tom Jones&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;] &lt;/ins&gt; Date: 2018-10-03 revision 2018-10-25'''&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==History==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==History==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Tom</name></author>	</entry>

	<entry>
		<id>http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=3989&amp;oldid=prev</id>
		<title>Tom: /* Solution */</title>
		<link rel="alternate" type="text/html" href="http://tcwiki.azurewebsites.net/index.php?title=Bearer_Tokens_Considered_Harmful&amp;diff=3989&amp;oldid=prev"/>
				<updated>2018-10-31T18:52:27Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Solution&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 18:52, 31 October 2018&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l26&quot; &gt;Line 26:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 26:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The obvious solution is a different token type in OAuth 2.0, or perhaps even a different version of OAuth, I guess 3.0. The obvious objection will be that &amp;quot;everybody is using OAuth 2.0 with bearer, we have no choice.&amp;quot; The obvious answer is &amp;quot;bollocks, let's do this thing right!&amp;quot; Besides, if so few developers are able to handle the security complexity of OAuth 2.0 as it is, then we would be better off with something new that has securely bound to the user, or perhaps to the user's device. Given the ubiquitous deployment of computers with trusted execution environment, the later should be eminently practical. Of course FIDO U2F could provide this functionality as well, so perhaps the predicted wide deployment of web authentication will provide an answer. That protocol does require a binding of the web site to the user token. While that does require a trusted user agent, we know that Android, at least, is committed to validating the source of any app that validates the site binding. Apple seems to take user issues seriously, so there is a good chance they will follow suit.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The obvious solution is a different token type in OAuth 2.0, or perhaps even a different version of OAuth, I guess 3.0. The obvious objection will be that &amp;quot;everybody is using OAuth 2.0 with bearer, we have no choice.&amp;quot; The obvious answer is &amp;quot;bollocks, let's do this thing right!&amp;quot; Besides, if so few developers are able to handle the security complexity of OAuth 2.0 as it is, then we would be better off with something new that has securely bound to the user, or perhaps to the user's device. Given the ubiquitous deployment of computers with trusted execution environment, the later should be eminently practical. Of course FIDO U2F could provide this functionality as well, so perhaps the predicted wide deployment of web authentication will provide an answer. That protocol does require a binding of the web site to the user token. While that does require a trusted user agent, we know that Android, at least, is committed to validating the source of any app that validates the site binding. Apple seems to take user issues seriously, so there is a good chance they will follow suit.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In summary, OAuth 2.0 has wide adoption across a wide range of deployments. This success is fantastic and somehow it should be leveraged to lead us to the next level of security. I personally have no confidence in the complex binding protocols now being proposed and strongly recommend a new token design with binding as a part of the token itself, not in some separate process that a developer needs to get right for a deployment to be secure. I would also explicitly ban the use of impersonation.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In summary, OAuth 2.0 has wide adoption across a wide range of deployments. This success is fantastic and somehow it should be leveraged to lead us to the next level of security. I personally have no confidence in the complex binding protocols now being proposed and strongly recommend a new token design with binding as a part of the token itself, not in some separate process that a developer needs to get right for a deployment to be secure. I would also explicitly ban the use of impersonation&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;. The opposite view is that the OAuth 2.0 standards are successful precisely because they are flexible and not too hard line on security. I suspect it is obvious that I tend to be hard line on security, which is what applications like banking require&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==What's in a Name==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==What's in a Name==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Tom</name></author>	</entry>

	</feed>