Menu
Mozilla unmasks security flaw in Persona, warns other OpenID implementers

Mozilla unmasks security flaw in Persona, warns other OpenID implementers

OpenID-related vulnerability could have allowed attackers to impersonate users on websites using Mozilla Persona authentication

A vulnerability found recently in an OpenID-based feature of the Mozilla Persona online identity management service prompted the company to advise Web developers to check their OpenID implementations for similar issues.

Mozilla Persona allows users to verify their ownership of one or more email addresses and then use those addresses to authenticate on websites. Users have to remember only their Persona account password, because once they're logged into the service, authenticating on Persona-enabled websites only takes two mouse clicks.

To verify email addresses for use with Persona users typically have to click on a link sent to those addresses, except for Gmail and Yahoo addresses which are verified through what Mozilla calls "Identity Bridging," a feature based on the OpenID authentication protocol.

It's in this identity bridge feature that three security researchers from the University of Trier in Germany have recently found a serious vulnerability. The flaw, which was reported through the Mozilla bug bounty program and is now fixed, could have allowed an attacker to authenticate on Persona-enabled websites with the Gmail or Yahoo Mail addresses of other users.

The vulnerability had no bearing on the security of Gmail or Yahoo Mail accounts and only impacted the Persona service and websites that allow authentication based on it, Michael Coates, Mozilla's director of security assurance, said Wednesday in a blog post.

The initial patches were deployed last Friday and some additional ones on Tuesday of this week, he said.

The problem stemmed from incorrect security and behavior assumptions with two third-party OpenID libraries, meaning that other developers who use OpenID might have made the same mistakes.

Mozilla developer Lloyd Hilaiel explained two attack scenarios enabled by the issue in a separate blog post.

One involves an attacker generating a valid and signed OpenID response from an identity provider that doesn't contain an email address field, and then appending their own email field and value to it. "This simple attack combined with behavior common in OpenID libraries can lead to vulnerabilities," Hilaiel said.

The other attack scenario involves an attacker adding an email address field at the beginning of a response that already has a signed email address field. Depending on how the OpenID library extracts values from OpenID responses, this trick might be enough to cause the unsigned email address value to be used instead of the legitimate one.

"In a popular OpenID implementation we found a lack of rigor in value extraction that could lead to vulnerabilities of this nature," Hilaiel said.

OpenID library authors should make sure that rigorous validation is performed on the values returned by an identity provider and that libraries clearly indicate which values are signed and can be trusted and which are not, he said. Site owners who use OpenID should also check their implementations to ensure that identifying values they rely on from OpenID responses are actually signed.

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags Internet-based applications and servicessecuritymobile securityAccess control and authenticationExploits / vulnerabilitiesinternetmozilla

Slideshows

Top 50 defining moments of the New Zealand channel in 2016

Top 50 defining moments of the New Zealand channel in 2016

Reseller News looks back on a tumultuous 12 months for the New Zealand channel, assessing the fallout from a year of sizeable industry change. Whether it be local or global mergers and acquisitions, distribution deals or job changes, the channel that started the year differs somewhat to the one set to finish it - Reseller News assesses the key moments that made 2016.​

Top 50 defining moments of the New Zealand channel in 2016
​Hewlett Packard Enterprise honours high achieving NZ channel

​Hewlett Packard Enterprise honours high achieving NZ channel

Hewlett Packard Enterprise honoured its top performing Kiwi partners at the second running of its HPE Partner Awards in New Zealand, held at a glitzy ceremony in Auckland. Recognising excellence across eight categories - from distributors to resellers - the tech giant celebrated its first year as a standalone company, following its official split from HP in 2015.

​Hewlett Packard Enterprise honours high achieving NZ channel
Nutanix treats channel partners to Christmas cruise

Nutanix treats channel partners to Christmas cruise

Nutanix recently took to the seas for a Christmas Cruise around Sydney Harbour with its Australia and New Zealand staff, customers and partners to celebrate a stellar year for the vendor. With the sun out, they were all smiles and mingled over drinks and food.

Nutanix treats channel partners to Christmas cruise
Show Comments