On Security Vulnerabilities

cheap cialis pill certified cialis cheap viagra in canada cialis buy drug buy generic cialis viagra buy 25mg viagra cheap viagra without prescription buy cheapest viagra on line purchase viagra cialis 10mg buying generic viagra cialis pills viagra from india cheapest sildenafil citrate cheap cialis no rx viagra india cialis bangkok viagra for order buy sildenafil internet buy generic viagra online buying cialis online where to order cialis tablet cialis find cialis no prescription required viagra cheap drug order cialis cheap online online pharmacy cialis cialis no rx order generic cialis price of cialis viagra soft drug viagra cheap viagra from uk order cialis no prescription order cheap viagra viagra drug order cheap cialis cheap cialis pharmacy best price for viagra cheap viagra from usa cost cialis cialis overnight shipping cheapest generic cialis online generic viagra online online viagra viagra sales cheap cialis in canada compare cialis prices online cialis online drug viagra online purchase discount cialis without prescription no rx viagra cialis overnight viagra uk cialis order cheap cialis from usa buying cialis cialis overnight delivery cialis in bangkok buy and purchase sildenafil online impotence treatment cheap price viagra viagra sale cheap cialis tablet drug cialis generic cialis online cheap viagra pharmacy find discount cialis online viagra malaysia cialis without a prescription buy cialis online cheap viagra rx buy no rx viagra cialis 20mg viagra in malaysia discount viagra online buy sildenafil cheap buy viagra low price buy cialis cialis cheap price cialis cheap generic viagra cialis canada low cost viagra buy cheap viagra cialis vs viagra order cialis from us cialis tablets find no rx cialis buy generic cialis online buy viagra overnight delivery cheapest cialis price buy cheapest cialis on line order cialis in canada viagra tablet viagra no online prescription find cheap cialis online viagra price order viagra no prescription cheap generic cialis buy viagra online cheap cialis uk cialis without rx generic cialis cheap viagra vs cialis order cialis on internet viagra tablets viagra purchase impotence drugs buy cialis generic cialis tablet cialis cheapest price order viagra from canada viagra generic cheap viagra from canada order cialis compare viagra prices online find cheap cialis impotence cure pfizer viagra find discount cialis cheapest cialis buy cialis from india impotence buy cheapest viagra online cialis side effects viagra order discount cialis online cialis in malaysia cialis in uk viagra in uk cialis online without prescription cialis online pharmacy order viagra buy viagra online viagra side effects cialis sale discount cialis no rx cheapest viagra find cialis order cialis no rx buy cialis low price buy viagra cheap drug cialis online purchase order discount viagra online 50 mg viagra 100 mg viagra 10mg cialis cost of cialis cheapest cialis prices buy discount viagra online cialis sales 50mg viagra cialis price buy viagra on internet cialis pill cheapest cialis online purchase viagra overnight delivery cheap cialis from canada cheapest viagra price cialis 20 mg buy sildenafil low cost order viagra without prescription buy viagra lowest price no prescription cialis order viagra on internet discount cialis overnight delivery cialis cheap drug viagra approved viagra no rx required compare viagra prices no rx cialis cheap cialis on internet buy viagra from india buy discount cialis online viagra pharmacy online order viagra from us cialis free delivery cialis for order buy cialis from canada viagra without rx viagra online review 10 mg cialis cheap viagra no rx cheapest viagra prices viagra prices cialis pharmacy order no rx cialis buy cialis in us buy cialis no prescription required order cialis from canada lowest price cialis cheap cialis internet online pharmacy viagra cheapest generic cialis generic drugs cialis india find cialis without prescription best price cialis buy viagra without prescription cheap cialis in uk where to buy viagra 20 mg cialis cheap cialis from uk buy sildenafil canada cialis no rx required cialis in us buy cialis overnight delivery cialis cheap price order cheap viagra online 20mg cialis buy cheap viagra online viagra internet viagra without prescription free cialis buy cialis us cialis buy buy viagra in canada order viagra cheap online find viagra without prescription viagra pills cheap cialis no prescription viagra online without prescription order generic viagra cialis discount viagra cheapest price purchase viagra no rx viagra no rx viagra cheap discount viagra overnight delivery sale cialis cialis pharmacy online purchase cialis without prescription pharmacy online cialis medication discount viagra buy cheap cialis impotence medication viagra medication find cialis on internet impotence pills cialis prices discount viagra without prescription cialis online cheap cialis online review find cheap viagra online buy viagra us purchase cialis online certified viagra where to order viagra buy cheapest viagra buy cialis internet order cialis online buy sildenafil online buy cialis cheap cheap viagra purchase cialis find discount viagra buy cialis on internet cialis buy online buy sildenafil online without a prescription viagra buy online order cheap cialis online viagra information no prescription viagra cost of viagra buy cialis in canada buy cialis online buy viagra cheapest generic viagra cialis us cialis australia fda approved cialis lowest price for viagra viagra bangkok cialis prescription cialis cost buy no rx cialis buy viagra internet viagra discount order viagra overnight delivery generic cialis viagra australia 25 mg viagra order viagra online viagra overnight cialis rx order cialis in us order viagra no rx order discount cialis online viagra vendors order viagra in us buy sildenafil in uk viagra us buy generic viagra viagra canada viagra no prescription viagra cheap price cheap viagra tablet viagra free delivery overnight viagra purchase viagra online find cheap viagra cialis malaysia best price viagra cialis free sample find viagra on internet cialis generic buy sildenafil in canada order cialis no prescription required cheapest viagra online purchase cialis no rx viagra in us order discount cialis cheap viagra internet free viagra cialis approved best price for cialis cialis from india find no rx viagra generic viagra viagra from canada viagra online pharmacy buy viagra from canada cheapest generic viagra online buy cheapest cialis discount cialis viagra overnight delivery cialis without prescription 100mg viagra cialis in australia price of viagra order cialis overnight delivery cheap viagra in uk buying generic cialis viagra pill buy cialis on line low cost cialis find discount viagra online buying viagra cheap cialis overnight delivery pharmacy cialis cheap viagra pill viagra prescription find viagra online buy cialis lowest price discount viagra no rx online cialis viagra free sample cheap viagra in usa find viagra cheap viagra online buy viagra no rx generic viagra cheap buy cialis without prescription buy viagra in us cheap viagra overnight delivery cheap cialis in usa cheap cialis online viagra order no rx viagra viagra soft tab find cialis online lowest price viagra cialis drug cialis vendors viagra online stores erectile dysfunction order viagra in canada buy viagra on line viagra overnight shipping viagra online cheap lowest price for cialis approved viagra pharmacy cialis 10 mg cialis no online prescription cialis purchase cialis from canada order cialis without prescription viagra for sale viagra in australia approved cialis pharmacy buy viagra generic buy sildenafil in spain find viagra no prescription required cialis no prescription buy viagra from us order viagra no prescription required cost viagra purchase viagra without prescription buy cialis no rx cialis cheap cialis internet tablet viagra cheap viagra on internet viagra cost pharmacy viagra cialis soft tab cialis information buy cheap cialis internet purchase cialis overnight delivery cheap cialis without prescription buy viagra no prescription required compare cialis prices buy cheap cialis online overnight cialis where to buy cialis cheap cialis buy cheap viagra internet buy discount cialis viagra buy drug cheap viagra no prescription buy sildenafil citrate buying viagra online buy discount viagra fda approved viagra cialis online stores cheap cialis tablets buy cheapest cialis online cheap viagra tablets order discount viagra sale viagra viagra online cialis for sale cialis soft viagra pharmacy buy cialis from us viagra without a prescription viagra in bangkok

We here at JanRain pride ourselves on our responsiveness to the community and our customers. We strongly believe in OpenID as a platform and put our money where our mouth is by having a highly robust and secure identity provider. From time to time we get messages from users who believe they have found a security vulnerability in our libraries or MyOpenID server. We take these reports serviously and when there is a problem we patch things very quickly and release an update. We’ve done this with our libraries as well as MyOpenID. We have had people make claims about our security before and we have had to refute them. This is just part of participating in an open community.

On Friday 11/24/2006 at 11:28 AM PST we received an email from Dmitry Shechtman that stated the following:

Hello,

I think I just found a big hole in your site’s security.

I successfully signed up for an existing account with a different email address.

Regards,

Dmitry

Dmitry is the author of the phpBB OpenID plugin that we’ve all been looking forward to seeing. I’m really excited about this plugin as I believe forum adoption will be critical to the success of OpenID. Dmitry has been using MyOpenID.com as a test server while he works on implementing the plugin. The message was received and was immediately put in our support queue. By 3pm I got a note from one of my engineers who had looked at the problem saying:

If you signup for an account and you use the same password as an account
that already exists, it effectively works like confirming a change of email
address. I’m guessing this is what happened with this guy. I tried signing up
for an account I already have, and it only works if I enter the same password
that is already set for the account.

You can actually still see this behavior on the MyOpenID.com site right now. If you go to the new account registration screen and enter in the username and password of an existing account (you have to know both of them) and then enter an email address in, a mail will go out for that MyOpenID account even if the email is different from the original email used to create the account. This is effectively like changing your email address. The functionality is flawed in that its confusing. We’ll be fixing this in the next couple of days. However, you still have to know the username and password of the account to make it work. If someone has that, the account is already compromised.

Since we determined that is was not a security vulnerability but really a usability problem, we waited until Saturday to reply to Dmitry. I did my best to respond to the public claims made by Dmitry on Saturday but he was not convinced. He disabled access to the test.phpbb.cc site for any MyOpenID accounts and continued to state that there was a security vulnerability.

I chatted with him via IM today and tried to talk through the issues that he saw and hopefully have him post a retraction about the MyOpenID service. His concern was that we could have easily changed the behavior of the site to solve this problem over the weekend and he would never know. Drilling down further, he actually said that he hadn’t looked all that hard at the problem on Friday. This puts the burden of proof on us to show that we haven’t “secretly” changed the sites behavior over the weekend to avoid an embarrassing announcement. If we screw up, we’re at fault and we’ll take any and all actions necessary to fix the problem as well as admit to the mistakes we might have made. That’s our duty in providing identities for end-users and something we believe very strongly in.

Just for the record; we have not made any changes to the MyOpenID service since Thursday afternoon and we have done nothing to try to cover up this claimed security vulnerability. Go try it out for yourself; the behavior is still there today.

Update: I fixed the link to the phpBB OpenID plugin site.

Update v2.0: Fixed some links that broke when Dmitry moved some things around on the forum links above.

About The Author

kveton

Other posts bykveton

Author his web sitehttp://kveton.myvidoop.com

26th

November 2006

5 Comments Add Yours ↓

The upper is the most recent comment

  1. 1

    As I repeatedly noted in our conversation, a test board hardly counts as an arena for public claims. But since we have gone public with this now, here are a few backlinks:

    http://test.phpbb.cc/viewtopic.php?t=37
    http://test.phpbb.cc/viewtopic.php?t=38

    Vulnerability or not, coverup or not — you are invited to draw your conclusion.

  2. 2

    That wasn’t the only place you made that public claim:

    http://startrekguide.com/forum/viewtopic.php?p=12128

    We take security seriously here so we respond to any and all questions about the quality of the services we provide. Test site or otherwise, people might happen upon that site via Google and not know its a test site. I’d rather err on the side of full-disclosure and discussion than not.

    Thanks for the post Dmitry!

  3. 3

    Full disclosure is open source to me. Why didn’t you agree to open your code repository, not even under NDA?

    And what’s wrong with your clock?

  4. 4

    For the very reason that you have not given me any cause to do so. From previous experience, I’m not convinced you could do a thorough analysis.

    I’m sorry we didn’t get back to you as quickly as we normally respond to such events. However, the timing of these events were correct, we simply failed to notify you in a timely fashion.

    You continue to question my integrity at every opportunity and yet you have not shown one bit of proof of a security vulnerability.

  5. j3h #
    5

    We have just made a release that changes the behavior so that it rejects sign-ups even if the entered credentials match an existing account. This should make the sign-up process less confusing if people are testing it.



Your Comment

Note: This post is over 3 years old. You may want to check later in this blog to see if there is new information relevant to your comment.

Additional comments powered by BackType