Skip to content

Releases: oauth-wg/oauth-cross-device-security

draft-ietf-oauth-cross-device-security-12

05 Sep 09:52
ee386e9
Compare
Choose a tag to compare

Fixed references to point to final versions of specifications

What's Changed

Full Changelog: draft-ietf-oauth-cross-device-security-11...draft-ietf-oauth-cross-device-security-12

draft-ietf-oauth-cross-device-security-11

22 Jul 07:51
326e66d
Compare
Choose a tag to compare

Includes formatting and editorial changes to clarify existing text.

What's Changed

Full Changelog: draft-ietf-oauth-cross-device-security-10...draft-ietf-oauth-cross-device-security-11

draft-ietf-oauth-cross-device-security-10

17 Jun 14:16
6e83ca1
Compare
Choose a tag to compare

Addresses shepherd feedback

  • Shepherd feedback: Describe unauthenticated channel.
  • Shepherd feedback: Separate normative and informative references.
  • Shepherd feedback: Update FIDO/WebAuthn references

draft-ietf-oauth-cross-device-security-09

06 Jan 10:35
8af0d5f
Compare
Choose a tag to compare
  • Affiliation change to allow publication to Datatracker.
  • No content changes - re-published to avoid expiry while waiting on shepherd review.

draft-ietf-oauth-cross-device-security-08

08 Jul 09:26
d25da44
Compare
Choose a tag to compare

draft-ietf-oauth-cross-device-security-07

13 May 19:49
b37f62d
Compare
Choose a tag to compare

Includes feedback from Working Group Last Call. Changes include:

  1. Clarification of FIDO\WebAuthn section.
  2. Updated langugage in section on FIDO to allow for use of FIDO keys on consumption devices.
  3. Clarified origin of QR Code.
  4. Editorial updates
  5. Updated examples to be consistent.
  6. Made diagram description clearer.
  7. Added CTAP 2.2 Draft.
  8. Added additional guidance on geolocation inaccuracies.
  9. Added Roy Williams to acknowledgements
  10. Clarified that authorization servers can detect
  11. Consistent use of "smart TV"
  12. Fixed references

draft-ietf-oauth-cross-device-security-06

04 Apr 16:11
a7f4f8c
Compare
Choose a tag to compare

draft-ietf-oauth-cross-device-security-05

01 Mar 09:45
f413141
Compare
Choose a tag to compare
  • Added section to provide actionable guidance to implementers on how to use this document.
  • Expanded section on formal analysis to include completed research projects.
  • Added reference to OpenID for Verifiable Presentations.

draft-ietf-oauth-cross-device-security-04

22 Oct 19:58
ed6e170
Compare
Choose a tag to compare

Corrected formatting issue that prevented the document history from displaying correctly.

draft-ietf-oauth-cross-device-security-03

22 Oct 19:26
69dcdec
Compare
Choose a tag to compare
  • Introduced normative SHOULD, RECOMMENDED and MAY when applied to actions the Authorization Server, Resource Server or Client may implement.
  • Added User Education as a standalone mitigation.
  • Added Maryam Mehrnezhad, Marco Pernpruner and Giada Sciarretta to the contributors list.
  • Added Request Binding with Out-of-Band Data as an additional mitigation (feedback received at OSW 2023)
  • Adopted the OpenID Foundation terminology from [CIBA] and changed Initiating Device to Consumption Device
  • Added Fake Helpdesk and Consent Request Overload examples (new variations of attacks observed in the wild)
  • Replaced "Authenticated Flow" mitigation name with "Authenticate-then-Intitiate"
  • Added Cross-Device Session Transfer pattern (feedback received at OSW 2023)

What's Changed

New Contributors

Full Changelog: draft-ietf-oauth-cross-device-security-02...draft-ietf-oauth-cross-device-security-03