RISC
Risk and Incident Sharing and Coordination
Adam Dawes (adawes at google.com)
http://goo.gl/aksGhx
Account breaches can result in cascading failures
http://goo.gl/aksGhx
Internet is built on web of dependencies
If an account from an email provider/identity provider is hacked, relying parties are at risk:
Sites where the hacked user:
Additionally, attackers can easily register for new accounts on relying parties while account is taken over
http://goo.gl/aksGhx
RISC Working Group background
Google, Yahoo, Microsoft, Facebook, LinkedIn, Twitter, Paypal, Ping Identity, AOL, Confyrm, Peercraft, Nomura�
http://goo.gl/aksGhx
Workgroup Charter
Objective
Scope and Deliverables
http://goo.gl/aksGhx
Security Events
Account Status Change
Credential Change
http://goo.gl/aksGhx
Receiving RISC events
http://goo.gl/aksGhx
THANKS
http://goo.gl/aksGhx
APPENDIX
http://goo.gl/aksGhx
RISC is a way for providers to work together to make it harder for bad guys
Focus:
http://goo.gl/aksGhx
Possible Options: What data should be shared?
Raw events
Recommendations
http://goo.gl/aksGhx
Who are relevant parties to this information?
IDP -> RP
RP -> IDP
RP -> RP
3rd parties?
http://goo.gl/aksGhx
What are the privacy implications of sharing?
http://goo.gl/aksGhx
What mechanisms should be used to share?
Proposal:
Publish security recommendations to qualified third party’s abuse endpoint
Proposed Feed� {"iss":"accounts.google.com",� "sub":"10769150350006150715113082367",� "aud":"1234987819200.apps.googleusercontent.com",� "time":1353604926� “reco”:”terminateSession”}
http://goo.gl/aksGhx
Next steps
http://goo.gl/aksGhx
Big Account Changes are a risk for RPs
Password change at IDP
Security best practice: on password change, RP should revoke:
But how is an RP to know that a user changed their password???
http://goo.gl/aksGhx
Google would like to be subscriber of changes too
http://goo.gl/aksGhx
OIDC Session Management is not enough
If the RP keeps login state synced with IDP, that should work right?�
http://goo.gl/aksGhx
Implicit RPs can subscribe too
http://goo.gl/aksGhx
What RPs to notify?
http://goo.gl/aksGhx