OAuth 2.0 Hack Exposes 1 Billion Mobile Apps to Account Hijacking [telecom]

Nov 14, 2016 0 Replies

OAuth 2.0 Hack Exposes 1 Billion Mobile Apps to Account Hijacking



by Michael Mimoso



Third-party applications that allow single sign-on via Facebook and Google and support the OAuth 2.0 protocol, are exposed to account hijacking. Three Chinese University of Hong Kong researchers presented at Black Hat EU last week a paper called "Signing into One Billion Mobile LApp Accounts Effortlessly with OAuth 2.0." The paper describes an attack that takes advantage of poor OAuth 2.0 implementations and puts more than one billion apps in jeopardy.



formatting link


Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required