Mozilla unmasks security flaw in Persona, warns other OpenID - TopicsExpress



          

Mozilla unmasks security flaw in Persona, warns other OpenID implementers A vulnerability found recently in an OpenID-based feature of the Mozilla Persona online-identity management service prompted the company to advise web developers to check their OpenID implementations for similar issues. Mozilla Persona allows users to verify their ownership of one or more email addresses and then use those addresses to authenticate on websites. Users have to remember only their Persona account password, because once they’re logged into the service, authenticating on Persona-enabled websites only takes two mouse clicks. To verify email addresses for use with Persona users typically have to click on a link sent to those addresses, except for Gmail and Yahoo addresses which are verified through what Mozilla calls “Identity Bridging,” a feature based on the OpenID authentication protocol.
Posted on: Fri, 04 Oct 2013 06:53:12 +0000

Trending Topics



Recently Viewed Topics




© 2015