Other nomination
Security and Privacy of Social Logins
A master's thesis that reverse-engineers the Sign in with Apple, Google Sign-In and Facebook Login protocols, then audits how their SDKs and 63 real-world sites use postMessage for the popup handoff. Missing origin and destination checks let any website steal SSO tokens for account takeover or land DOM-based XSS, and prompt=none with login_hint gives XS-Leaks revealing which accounts and identity a visitor holds.
Record
- Researcher
- Louis Christopher Jannett
- Format
- Whitepaper
In the archive
Related sources
- Part I: Single Sign-On Protocols in the Wild
- Part II: PostMessage Security in Single Sign-On
- Part III: Privacy in Single Sign-On Protocols
- Research browser extension
Tags
This page is the archive's own catalogue record. The research is the work of Louis Christopher Jannett, first published at the original source. Preserved copies are kept so the citation survives its host.