%% You should probably cite draft-ietf-oauth-cross-device-security-06 instead of this revision. @techreport{ietf-oauth-cross-device-security-00, number = {draft-ietf-oauth-cross-device-security-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-oauth-cross-device-security/00/}, author = {Pieter Kasselman and Daniel Fett and Filip Skokan}, title = {{Cross-Device Flows: Security Best Current Practice}}, pagetotal = 31, year = 2022, month = dec, day = 7, abstract = {This document describes threats against cross-device flows along with near term mitigations, protocol selection guidance and the analytical tools needed to evaluate the effectiveness of these mitigations. It serves as a security guide to system designers, architects, product managers, security specialists, fraud analysts and engineers implementing cross-device flows.}, }