
Reliance on system is "multi-factor problem"
By Tom Espiner
Published: 14 August 2008 08:53 GMT
A fundamental issue affects the OpenID authentication system, due to its reliance on the Domain Name System, a Sun identity-technology specialist has warned.
Robin Wilton, a corporate architect for federated identity at Sun, described OpenID's reliance on the integrity of the Domain Name System (DNS) as a "multi-factor problem" in light of the discovery of a fundamental flaw in DNS by security researcher Dan Kaminsky.
Security from A to Z
Click on the links below to find out more...
A is for Antivirus
B is for Botnets
C is for CMA
D is for DDoS
E is for Extradition
F is for Federated identity
G is for Google
H is for Hackers
I is for IM
J is for Jaschan (Sven)
K is for Kids
L is for Love Bug
M is for Microsoft
N is for Neologisms
O is for Orange
P is for Passwords
Q is for Questions
R is for Rootkits
S is for Spyware
T is for Two-factor authentication
U is for USB sticks/devices
V is for Virus variants
W is for Wi-fi
X is for OS X
Y is for You
Z is for Zero-day
Wilton wrote in a blog post on Friday: "You may have seen the recent announcements about DNS cache poisoning, and the potential effect of this on all kinds of internet-based applications' security. One area in which it can have a particularly significant impact is OpenID."
OpenID is a shared, online identity service that lets people create one single login to use on multiple sites. Its supporters include major organisations such as Microsoft, Yahoo! and the BBC.
Wilton wrote that OpenID is not designed to require the prior exchange of security information between parties for the process to work. Instead, it relies on the integrity of the underlying DNS system to ensure that identity is vouched for by the "correct" trust provider. This means that, if the underlying DNS system is compromised (for example, through cache poisoning), authentication is undermined, as it is impossible to tell whether an entity vouching for an identity can be trusted.
Wilton wrote that none of Sun's enterprise authentication systems had been affected as it uses the Liberty authentication mechanism, a rival to OpenID. Sun had been investigating OpenID as a research project, he said.
Another problem with OpenID was highlighted in a security advisory published last week, which quoted findings by Google researcher Ben Laurie, and Richard Clayton, of the Cambridge University Computer Labs. Various OpenID providers have TLS server certificates that use weak private keys, the researchers said, as a result of a previously reported flaw in the Debian random-number generator. This opens the door to a cache-poisoning attack where a malicious server would pretend to be the true OpenID provider.
Writing in a blog post on Saturday, Clayton said that this flaw particularly affected Sun's implementations of OpenID.
Clayton wrote: "The problem that Ben [Laurie] and I have identified is that an attacker can poison a DNS cache so it serves up the wrong IP address for openid.sun.com. Then, even if the victim is really cautious and uses HTTPS and checks the cert, their credentials can be phished. Thereafter, anyone who trusts Sun as an [OpenID] identity provider could be very disappointed."
Original article: OpenID at risk due to DNS flaw, warns researcher from ZDNet UK
Degree level education in one of the following technical disciplines: Engineering, Computer Science, Software Design, Information Systems or ...
Your specific responsibilities are likely to include: Leading teams of technologists/engineers to develop high integrity complex systems for medical ...
Provide pre and post sales & implementation support *Provide input into ITT & proposal responses *Maintain awareness of new and emerging technologies ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...
Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech