%% You should probably cite rfc6819 instead of this I-D. @techreport{ietf-oauth-v2-threatmodel-08, number = {draft-ietf-oauth-v2-threatmodel-08}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-oauth-v2-threatmodel/08/}, author = {Torsten Lodderstedt and Mark McGloin and Phil Hunt}, title = {{OAuth 2.0 Threat Model and Security Considerations}}, pagetotal = 71, year = 2012, month = oct, day = 6, abstract = {This document gives additional security considerations for OAuth, beyond those in the OAuth 2.0 specification, based on a comprehensive threat model for the OAuth 2.0 protocol. This document is not an Internet Standards Track specification; it is published for informational purposes.}, }