Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On Deployments
Mohammad Ghasemisharif, Chris Kanich, Jason Polakis
Abstract
Single Sign-On (SSO) is both a core and critical component of user authentication and authorization on the modern web, as it is often offered by web and mobile applications alongside credential-based authentication to facilitate the account creation and login process. However, the interplay between local account management and SSO functionality in the backend leads to flaws that enable or magnify account hijacking attacks. These flaws are not baked into the actual SSO protocols, but manifest due to the complexity of supporting separate but intermingling authentication paths. As a result, these types of flaws cannot be detected by the SSO protocol or implementation verification tools proposed in prior work. In this paper we introduce SAAT, a fully automated modular framework that assesses whether relying parties (RPs) that use Facebook as the IdP comply with secure practices and guidelines, and uncovers flaws in account and session management that stem from or are affected by the interplay of SSO and local functionality. We conduct a large-scale exploration of authentication and session practices in Facebook’s RPs, revealing a volatile ecosystem where SSO support can be suddenly dropped and 17.6% of the tested RPs exhibit non-functional SSO implementations. This highlights the need for the continuous and systematic testing of the SSO ecosystem made possible by SAAT. More critically, we find that security measures are often missing and official guidelines are routinely overlooked or misconfigured, with only 0.8% of the RPs fully enabling re-authentication which can prevent compromise from hijacked identity provider (IdP) cookies. Our study also shows that less than 2% of RPs correctly react to SSO revocation and 67% continue to allow account access even 10 days after revocation. Overall, we envision our framework as a tool for enabling and guiding widespread remediation efforts by major SSO identity providers, which were previously infeasible due to the sheer scale and inherent mutability of this ecosystem.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3d59c0c8-786e-44be-ab08-9f9a0cb62f1fCited by top-tier papers11
- DISTINCT: Identity Theft using In-Browser Communications in Dual-Window Single Sign-OnLouis Jannett, Vladislav Mladenov, Christian Mainka, Jörg SchwenkCCS 2022 · 11 citations
- All Your Shops Are Belong to Us: Security Weaknesses in E-commerce PlatformsRohan Pagey, Mohammad Mannan, Amr M. YoussefWWW 2023 · 10 citations
- Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-procedural Path-Sensitive Taint AnalysisYuchen Ji, Ting Dai, Zhichao Zhou, Yutian Tang et al.OOPSLA 2025 · 9 citations
- Stealing Trust: Unraveling Blind Message Attacks in Web3 AuthenticationKailun Yan, Xiaokuan Zhang, Wenrui DiaoCCS 2024 · 5 citations
- Understanding and Detecting Abused Image Hosting Modules as Malicious ServicesGeng Hong, Mengying Wu, Pei Chen, Xiaojing Liao et al.CCS 2023 · 3 citations
Builds on13
- Measuring HTTPS Adoption on the WebAdrienne Porter Felt, Richard Barnes, April King, Chris Palmer et al.USENIX Security 2017 · 177 citations
- You've Got Vulnerability: Exploring Effective Vulnerability NotificationsFrank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami et al.USENIX Security 2016 · 149 citations
- Hey, You Have a Problem: On the Feasibility of Large-Scale Web Vulnerability NotificationBen Stock, Giancarlo Pellegrino, Christian Rossow, Martin Johns et al.USENIX Security 2016 · 130 citations
- CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security PolicyLukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies, Artur JancCCS 2016 · 114 citations
- Tracking Certificate Misissuance in the WildDeepak Kumar, Zhengping Wang, Matthew Hyder, Joseph Dickinson et al.S&P 2018 · 86 citations
Related papers
- O Single Sign-Off, Where Art Thou? An Empirical Analysis of Single Sign-On Account Hijacking and Session Management on the WebMohammad Ghasemisharif, Amrutha Ramesh, Stephen Checkoway, Chris Kanich et al.USENIX Security 2018 · 63 citations
- The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization FlawsKostas Drakonakis, Sotiris Ioannidis, Jason PolakisCCS 2020 · 56 citations
- One Click to Leak: Characterizing the Real-World Usage and Threat Impact of MNO-based Single Sign-On WebsitesJiasheng Huang, Mingxuan Liu, Pei Chen, Baojun Liu et al.CCS 2026
- Demystifying the (In)Security of Oauth-Based Account Linking in Connector EcosystemsKaixuan Luo, Xianbo Wang, Adonis P. H. Fung, Wing Cheong LauS&P 2026
- Vetting Single Sign-On SDK Implementations via Symbolic ReasoningRonghai Yang, Wing Cheong Lau, Jiongyi Chen, Kehuan ZhangUSENIX Security 2018 · 20 citations
