DISTINCT: Identity Theft using In-Browser Communications in Dual-Window Single Sign-On
Louis Jannett, Vladislav Mladenov, Christian Mainka, Jörg Schwenk
摘要
Single Sign-On (SSO) protocols like OAuth 2.0 and OpenID Connect 1.0 are cornerstones of modern web security, and have received much academic attention. Users sign in at a trusted Identity Provider (IdP) that subsequently allows many Service Providers (SPs) to verify the users' identities. Previous research concentrated on the standardized -called textbook SSO in this paper -authentication flows, which rely on HTTP redirects to transfer identity tokens between the SP and IdP. However, modern web applications like single page apps may not be able to execute the textbook flow because they lose the local state in case of HTTP redirects. By using novel browser technologies, such as postMessage, developers designed and implemented SSO protocols that were neither documented nor analyzed thoroughly. We call them dual-window SSO flows.
In this paper, we provide the first comprehensive evaluation of dual-window SSO flows. In particular, we focus on the In-Browser Communication (InBC) used to exchange authentication tokens between SPs and IdPs in iframes and popups. We automate our analysis by developing Distinct -a tool that dynamically analyzes the JavaScript code executing as part of the SSO flow. Distinct translates the flow into a sequence diagram depicting all communicating entities and their exchanged messages, highlights insecure communication channels, and quantifies novel threats in dual-window SSO flows. We found that 56% of the SPs in the Tranco top 1k list support dual-window SSO. Surprisingly, 28% of the SPs implemented dual-window SSO without using official SDKs, leading to identity theft and XSS in 31% of these self-implemented SPs.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- To Auth or Not To Auth? A Comparative Analysis of the Pre- and Post-Login Security LandscapeJannis Rautenstrauch, Metodi Mitkov, Thomas Helbrecht, Lorenz Hetterich 等S&P 2024 · 被引用 6 次
- Stealing Trust: Unraveling Blind Message Attacks in Web3 AuthenticationKailun Yan, Xiaokuan Zhang, Wenrui DiaoCCS 2024 · 被引用 5 次
- Universal Cross-app Attacks: Exploiting and Securing OAuth 2.0 in Integration PlatformsKaixuan Luo, Xianbo Wang, Adonis P. H. Fung, Wing Cheong Lau 等USENIX Security 2025
- "Only as Strong as the Weakest Link": On the Security of Brokered Single Sign-On on the WebTommaso Innocenti, Louis Jannett, Christian Mainka, Vladislav Mladenov 等S&P 2025
它引用的顶会 Paper12
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- A Comprehensive Formal Security Analysis of OAuth 2.0Daniel Fett, Ralf Küsters, Guido SchmitzCCS 2016 · 被引用 228 次
- How the Web Tangled Itself: Uncovering the History of Client-Side Web (In)SecurityBen Stock, Martin Johns, Marius Steffens, Michael BackesUSENIX Security 2017 · 被引用 67 次
- O Single Sign-Off, Where Art Thou? An Empirical Analysis of Single Sign-On Account Hijacking and Session Management on the WebMohammad Ghasemisharif, Amrutha Ramesh, Stephen Checkoway, Chris Kanich 等USENIX Security 2018 · 被引用 63 次
- AUTHSCOPE: Towards Automatic Discovery of Vulnerable Authorizations in Online ServicesChaoshun Zuo, Qingchuan Zhao, Zhiqiang LinCCS 2017 · 被引用 59 次
相关 Paper
- One Click to Leak: Characterizing the Real-World Usage and Threat Impact of MNO-based Single Sign-On WebsitesJiasheng Huang, Mingxuan Liu, Pei Chen, Baojun Liu 等CCS 2026
- WPSE: Fortifying Web Protocols via Browser-Side Security MonitoringStefano Calzavara, Riccardo Focardi, Matteo Maffei, Clara Schneidewind 等USENIX Security 2018 · 被引用 29 次
- The Leaky Web: Automated Discovery of Cross-Site Information Leaks in Browsers and the WebJannis Rautenstrauch, Giancarlo Pellegrino, Ben StockS&P 2023
- DoubleX: Statically Detecting Vulnerable Data Flows in Browser Extensions at ScaleAurore Fass, Dolière Francis Somé, Michael Backes, Ben StockCCS 2021 · 被引用 35 次
- Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On DeploymentsMohammad Ghasemisharif, Chris Kanich, Jason PolakisS&P 2022 · 被引用 25 次
