Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Document possible phishing attacks during authentication with Solid-OIDC #6

Open
VirginiaBalseiro opened this issue May 23, 2024 · 0 comments

Comments

@VirginiaBalseiro
Copy link
Member

Document how Solid-OIDC can be vulnerable to phishing attacks where attackers create malicious applications or fake login pages to capture user credentials. For example, users might be redirected to a fake IdP that mimics a legitimate one, tricking them into entering their credentials.
Some remediations might involve some way of verifying the legitimacy/integrity of the redirect URIs or requiring MFA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant