Nytro Posted March 20, 2012 Report Posted March 20, 2012 Signing Me onto Your Accounts through Facebook and Google: a Traffic-GuidedSecurity Study of Commercially Deployed Single-Sign-On Web ServicesRui WangIndiana University BloomingtonBloomington, IN, USAwang63 @indiana.eduShuo ChenMicrosoft ResearchRedmond, WA, USAshuochen @microsoft.comXiaoFeng WangIndiana University BloomingtonBloomington, IN, USAxw7 @indiana.eduAbstract— With the boom of software-as-a-service and socialnetworking, web-based single sign-on (SSO) schemes are beingdeployed by more and more commercial websites to safeguardmany web resources. Despite prior research in formalverification, little has been done to analyze the security qualityof SSO schemes that are commercially deployed in the realworld. Such an analysis faces unique technical challenges,including lack of access to well-documented protocols and code,and the complexity brought in by the rich browser elements(script, Flash, etc.). In this paper, we report the first “fieldstudy” on popular web SSO systems. In every studied case, wefocused on the actual web traffic going through the browser,and used an algorithm to recover important semanticinformation and identify potential exploit opportunities. Suchopportunities guided us to the discoveries of real flaws. In thisstudy, we discovered 8 serious logic flaws in high-profile IDproviders and relying party websites, such as OpenID(including Google ID and PayPal Access), Facebook, JanRain,Freelancer, FarmVille, Sears.com, etc. Every flaw allows anattacker to sign in as the victim user. We reported our findingsto affected companies, and received their acknowledgements invarious ways. All the reported flaws, except those discoveredvery recently, have been fixed. This study shows that theoverall security quality of SSO deployments seems worrisome.We hope that the SSO community conducts a study similar toours, but in a larger scale, to better understand to what extentSSO is insecurely deployed and how to respond to the situation.Keywords— Single-Sign-ODownload:http://research.microsoft.com/pubs/160659/websso-final.pdf Quote