[{"author": "Hannes Tschofenig", "text": "<p>I am taking notes. Feel free to help me...</p>", "time": "2025-01-27T17:05:30Z"}, {"author": "Justin Richer", "text": "<p>Mike Jones, you're on mic still</p>", "time": "2025-01-27T17:05:35Z"}, {"author": "Brian Campbell", "text": "<p>nobody watches those tho</p>", "time": "2025-01-27T17:07:33Z"}, {"author": "Aaron Parecki", "text": "<p>i do! <span aria-label=\"eyes\" class=\"emoji emoji-1f440\" role=\"img\" title=\"eyes\">:eyes:</span></p>", "time": "2025-01-27T17:07:57Z"}, {"author": "Brian Campbell", "text": "<p>where nobody is not very many people</p>", "time": "2025-01-27T17:08:14Z"}, {"author": "Deb Cooley", "text": "<p>I know one person who does not.</p>", "time": "2025-01-27T17:09:13Z"}, {"author": "Deb Cooley", "text": "<p>but that person doesn't know what oauth is, let alone jwk</p>", "time": "2025-01-27T17:10:07Z"}, {"author": "Michael Jones", "text": "<p>Vulnerability Disclosure - Please do not post publicly: <a href=\"https://openid.net/wp-content/uploads/2025/01/OIDF-Responsible-Disclosure-Notice-on-Security-Vulnerability-for-private_key_jwt.pdf\">https://openid.net/wp-content/uploads/2025/01/OIDF-Responsible-Disclosure-Notice-on-Security-Vulnerability-for-private_key_jwt.pdf</a></p>", "time": "2025-01-27T17:10:12Z"}, {"author": "Justin Richer", "text": "<p>The chat is part of the recording fyi ....</p>", "time": "2025-01-27T17:10:33Z"}, {"author": "Justin Richer", "text": "<p>There's a difference in making it \"public\" here and drawing attention to it in more public forums.</p>", "time": "2025-01-27T17:11:13Z"}, {"author": "Brian Campbell", "text": "<p>^ what Justin said</p>", "time": "2025-01-27T17:11:28Z"}, {"author": "Aaron Parecki", "text": "<p>Right, I think what is being asked is to not publicize this beyond this working group. No blog posts or press releases yet please.</p>", "time": "2025-01-27T17:11:43Z"}, {"author": "Michael Jones", "text": "<p>Correct</p>", "time": "2025-01-27T17:11:54Z"}, {"author": "Hannes Tschofenig", "text": "<p>Fair. Just wanted to make sure the implications of posting stuff in the chat or saying during this meeting are well understood.</p>", "time": "2025-01-27T17:12:28Z"}, {"author": "Brian Campbell", "text": "<p>i tell the story because much of it is my fault</p>", "time": "2025-01-27T17:13:05Z"}, {"author": "Hannes Tschofenig", "text": "<p>Noted!</p>", "time": "2025-01-27T17:13:25Z"}, {"author": "Brian Campbell", "text": "<p>JAR is NOT my fault</p>", "time": "2025-01-27T17:14:56Z"}, {"author": "Brian Campbell", "text": "<p>for the record</p>", "time": "2025-01-27T17:15:01Z"}, {"author": "Brian Campbell", "text": "<p>:)</p>", "time": "2025-01-27T17:15:05Z"}, {"author": "Michael Jones", "text": "<p>How we got \"should\" past the working group and the RFC Editor is beyond me.  Life and learn!</p>", "time": "2025-01-27T17:15:34Z"}, {"author": "Pieter Kasselman", "text": "<p>aha - so the attacker is in the middle and now have an assertion it can use to authenticate with</p>", "time": "2025-01-27T17:17:21Z"}, {"author": "Pieter Kasselman", "text": "<p>?</p>", "time": "2025-01-27T17:17:28Z"}, {"author": "Michael Jones", "text": "<p>Yes, Pieter</p>", "time": "2025-01-27T17:17:34Z"}, {"author": "Brian Campbell", "text": "<p>not in the middle exactly but yes</p>", "time": "2025-01-27T17:17:39Z"}, {"author": "Brian Campbell", "text": "<p>kinda on the side</p>", "time": "2025-01-27T17:17:52Z"}, {"author": "Pieter Kasselman", "text": "<p>yes - almost like a kind of phishing attack...</p>", "time": "2025-01-27T17:18:04Z"}, {"author": "Brian Campbell", "text": "<p>if you squint at it right, yeah</p>", "time": "2025-01-27T17:18:43Z"}, {"author": "Pieter Kasselman", "text": "<p>:)</p>", "time": "2025-01-27T17:18:52Z"}, {"author": "Brian Campbell", "text": "<p>note that jwt/saml authorization grants are only sent to the token endpoint</p>", "time": "2025-01-27T17:19:42Z"}, {"author": "Hannes Tschofenig", "text": "<p>I would not call this a phishing attack because of the requirement for a bank to become malcious</p>", "time": "2025-01-27T17:19:53Z"}, {"author": "Pieter Kasselman", "text": "<p>That's fair Hannes</p>", "time": "2025-01-27T17:20:16Z"}, {"author": "Deb Cooley", "text": "<p>Isn't the attacker pretending to be  bank?</p>", "time": "2025-01-27T17:20:51Z"}, {"author": "Deb Cooley", "text": "<p>(a fake bank)</p>", "time": "2025-01-27T17:21:06Z"}, {"author": "Hannes Tschofenig", "text": "<p>It has to be a real bank, at least in my understanding.</p>", "time": "2025-01-27T17:21:43Z"}, {"author": "Aaron Parecki", "text": "<p>A fake bank is one way to do it, assuming they can get in to the federation somehow</p>", "time": "2025-01-27T17:21:53Z"}, {"author": "Brian Campbell", "text": "<p>the attacker has to be an authorization server that the client trusts the same as a legit authorization server</p>", "time": "2025-01-27T17:22:19Z"}, {"author": "Hannes Tschofenig", "text": "<p>But if you manage to get yourself added to the federation you are considered to be a bank in that scenario</p>", "time": "2025-01-27T17:22:28Z"}, {"author": "Daniel Fett", "text": "<p>That's the same assumption as for the Mix-up Attack. Very possible in some ecosystems, hard to impossible in others.</p>", "time": "2025-01-27T17:22:42Z"}, {"author": "Hannes Tschofenig", "text": "<p>Definitely a high-bar for an attacker.</p>", "time": "2025-01-27T17:23:16Z"}, {"author": "Pieter Kasselman", "text": "<p>It depends a lot on the quality of the eco-system rules and their adherence/engforcement.</p>", "time": "2025-01-27T17:23:25Z"}, {"author": "Brian Campbell", "text": "<p>not necessarily a bank - but yes - that's a vertical where this kind of deployment occurs</p>", "time": "2025-01-27T17:23:30Z"}, {"author": "Joseph Heenan", "text": "<p>Yes, exactly. The key requirement is that the fintech trusts the attacker's AS as a place to send their users - federation is one way that could happen but there are definitely many ways. Obtaining control of a legitimate but poorly secured bank as a way to pivot to a high value target is not impossible.</p>", "time": "2025-01-27T17:24:02Z"}, {"author": "Brian Campbell", "text": "<p>note again: note that jwt/saml authorization grants are only sent to the token endpoint</p>", "time": "2025-01-27T17:24:10Z"}, {"author": "Daniel Fett", "text": "<p>There are 5000 banks in europe; we had ~1100 AS in the yes ecosystem. In both cases, it is not unreasonable to assume that one of those could be compromised.</p>", "time": "2025-01-27T17:24:25Z"}, {"author": "Kristina Yasuda", "text": "<p>I guess the same solution decided on here would apply to openid4vc specs too? Since they also use JAR and PAR?</p>", "time": "2025-01-27T17:25:07Z"}, {"author": "Hannes Tschofenig", "text": "<p>I read through the OpenID4VC specs and they are full of options. That is a security problem too</p>", "time": "2025-01-27T17:25:39Z"}, {"author": "Kristina Yasuda", "text": "<p>RFC6749 is full of options</p>", "time": "2025-01-27T17:27:42Z"}, {"author": "Brian Campbell", "text": "<p>saml assertions are used in practice with saml entity ids</p>", "time": "2025-01-27T17:27:56Z"}, {"author": "Aaron Parecki", "text": "<p>and that's why we're updating RFC6749 too</p>", "time": "2025-01-27T17:28:07Z"}, {"author": "Hannes Tschofenig", "text": "<p>This is something we should be talking about in this meeting.</p>", "time": "2025-01-27T17:28:31Z"}, {"author": "Brian Campbell", "text": "<p>is or is not?</p>", "time": "2025-01-27T17:28:56Z"}, {"author": "Kristina Yasuda", "text": "<p>And thats why rfc6749 has FAPI and openid4vc has HAIP</p>", "time": "2025-01-27T17:30:00Z"}, {"author": "Kristina Yasuda", "text": "<p>but any comments on those please raise in DCP wg</p>", "time": "2025-01-27T17:30:14Z"}, {"author": "Kristina Yasuda", "text": "<p>Don\u2019t think my original question was answered but I\u2019ll take it as a yes, this applies there too</p>", "time": "2025-01-27T17:30:40Z"}, {"author": "Pieter Kasselman", "text": "<p>Kristina, what does HAIP stand for (asking for a friend ;))</p>", "time": "2025-01-27T17:30:45Z"}, {"author": "Kristina Yasuda", "text": "<p>High assurance interoperability profile</p>", "time": "2025-01-27T17:31:09Z"}, {"author": "Kristina Yasuda", "text": "<p>It should have been high-assurance API, so that\u2019s it\u2019s HAPI</p>", "time": "2025-01-27T17:31:28Z"}, {"author": "Pieter Kasselman", "text": "<p>:) thanks</p>", "time": "2025-01-27T17:31:52Z"}, {"author": "Brian Campbell", "text": "<p>I want to be HAPI ...</p>", "time": "2025-01-27T17:32:11Z"}, {"author": "Joseph Heenan", "text": "<p>I'm not sure too many people are/will use openid4vc will use private_key_jwt, but yes the same change could be used there too / will automatically apply there when the RFCs are updated.</p>", "time": "2025-01-27T17:32:23Z"}, {"author": "Brian Campbell", "text": "<p>no</p>", "time": "2025-01-27T17:36:20Z"}, {"author": "Brian Campbell", "text": "<p>^ on the sec BCP</p>", "time": "2025-01-27T17:36:32Z"}, {"author": "Justin Richer", "text": "<p>^-- what brian said</p>", "time": "2025-01-27T17:36:41Z"}, {"author": "Hannes Tschofenig", "text": "<p>I would add a reference to the paper</p>", "time": "2025-01-27T17:36:47Z"}, {"author": "Daniel Fett", "text": "<p>We can't add a reference without describing the problem.</p>", "time": "2025-01-27T17:37:09Z"}, {"author": "Brian Campbell", "text": "<p>^ what Dr. Fett said</p>", "time": "2025-01-27T17:37:33Z"}, {"author": "Hannes Tschofenig", "text": "<p>But there is a line between a reference and reproducing the paper</p>", "time": "2025-01-27T17:37:35Z"}, {"author": "Daniel Fett", "text": "<p>I don't understand.</p>", "time": "2025-01-27T17:37:49Z"}, {"author": "Hannes Tschofenig", "text": "<p>Will explain later</p>", "time": "2025-01-27T17:37:56Z"}, {"author": "Brian Campbell", "text": "<p>what Justin's saying</p>", "time": "2025-01-27T17:38:07Z"}, {"author": "Dean Saxe", "text": "<p>I agree with Justin.</p>", "time": "2025-01-27T17:38:30Z"}, {"author": "Brian Campbell", "text": "<p>now less what Justin's saying</p>", "time": "2025-01-27T17:39:15Z"}, {"author": "Brian Campbell", "text": "<p>the scope thing is real</p>", "time": "2025-01-27T17:40:11Z"}, {"author": "Aaron Parecki", "text": "<p>I like the idea of a tightly scoped edit to several documents</p>", "time": "2025-01-27T17:40:14Z"}, {"author": "Hannes Tschofenig", "text": "<p>If there are no proposals for other changes, then the scope discussion is artificial</p>", "time": "2025-01-27T17:40:40Z"}, {"author": "Justin Richer", "text": "<p>There will be proposals once the door is opened unless the chairs say not to do that.</p>", "time": "2025-01-27T17:41:06Z"}, {"author": "Dean Saxe", "text": "<p>I'm not sure it's artificial - it's a way to prevent others from trying to add scope.</p>", "time": "2025-01-27T17:41:09Z"}, {"author": "Joseph Heenan", "text": "<p>I think the scope discussion could, for example, determine how you word the working group last call message.</p>", "time": "2025-01-27T17:41:17Z"}, {"author": "Dean Saxe", "text": "<p>By defining a tight scope now, we can speed up the actions to publish updated RFCs.</p>", "time": "2025-01-27T17:41:44Z"}, {"author": "Justin Richer", "text": "<p>my proposal: we start writing the bIS to the BCP now</p>", "time": "2025-01-27T17:41:50Z"}, {"author": "Hannes Tschofenig", "text": "<p>I make it clear: Dean, do you want new content in RFC 7523</p>", "time": "2025-01-27T17:41:53Z"}, {"author": "Justin Richer", "text": "<p>publish what we have now</p>", "time": "2025-01-27T17:41:54Z"}, {"author": "Dean Saxe", "text": "<p>I do not want new content beyond what is being discussed today.</p>", "time": "2025-01-27T17:42:22Z"}, {"author": "Hannes Tschofenig", "text": "<p>Then, the answer in your case is no. I have no heard anyone suggesting anything new.</p>", "time": "2025-01-27T17:42:51Z"}, {"author": "Hannes Tschofenig", "text": "<p>We are discussing a problem that does not exist</p>", "time": "2025-01-27T17:43:05Z"}, {"author": "Dean Saxe", "text": "<p>I see it as preventing scope creep from becoming a problem.</p>", "time": "2025-01-27T17:43:41Z"}, {"author": "Dean Saxe", "text": "<p>but I'll defer to the chairs</p>", "time": "2025-01-27T17:43:51Z"}, {"author": "George Fletcher", "text": "<p>+1 for publishing the Security BCP</p>", "time": "2025-01-27T17:43:56Z"}, {"author": "Brian Campbell", "text": "<p>\"We are discussing a problem that does not exist\" - that is a great metaphor for the problem that will exist</p>", "time": "2025-01-27T17:48:36Z"}, {"author": "Daniel Fett", "text": "<p>Can we (later) have a show of hands re the security BCP addition?</p>", "time": "2025-01-27T17:49:26Z"}, {"author": "Brian Campbell", "text": "<p>and SAML</p>", "time": "2025-01-27T17:50:06Z"}, {"author": "Brian Campbell", "text": "<p>the long answer is no</p>", "time": "2025-01-27T17:50:51Z"}, {"author": "Brian Campbell", "text": "<p>which is turns out to be short</p>", "time": "2025-01-27T17:51:11Z"}, {"author": "Brian Campbell", "text": "<p>yes, the AS changes only kinda help flush out clients that are not doing the right thing</p>", "time": "2025-01-27T17:54:18Z"}, {"author": "Pieter Kasselman", "text": "<p>+1 to brian</p>", "time": "2025-01-27T17:56:01Z"}, {"author": "Brian Campbell", "text": "<p><em>heart</em> Filip</p>", "time": "2025-01-27T17:56:24Z"}, {"author": "Daniel Fett", "text": "<p>show of hands before end of session?</p>", "time": "2025-01-27T17:57:13Z"}, {"author": "Deb Cooley", "text": "<p>would that show of hands deal with both attacks?</p>", "time": "2025-01-27T17:57:47Z"}, {"author": "Deb Cooley", "text": "<p>or just this attack?</p>", "time": "2025-01-27T17:57:56Z"}, {"author": "Hannes Tschofenig", "text": "<p>Daniel wants to know how to proceed with the security BCP</p>", "time": "2025-01-27T17:58:17Z"}, {"author": "Daniel Fett", "text": "<p>Just this. The other would definitely need even more discussion.</p>", "time": "2025-01-27T17:58:25Z"}, {"author": "Brian Campbell", "text": "<p>Daniel is asking for a show of hands for action or not on the BCP in the RFC ed q</p>", "time": "2025-01-27T17:58:34Z"}, {"author": "Deb Cooley", "text": "<p>yeah, I understand that (I get those emails)</p>", "time": "2025-01-27T17:58:54Z"}, {"author": "Brian Campbell", "text": "<p>i don't, nor does the WG, which was kinda his point but that just got decided and i can't type fast enough</p>", "time": "2025-01-27T17:59:46Z"}]