-
Embedding of Security Components in Untrusted Third-Party Websites
Security-sensitive components, such as single sign-on APIs, need to be safely deployed on untrusted webpages. We present several new attacks on security components... -
Discovering Concrete Attacks on Website Authorization by Formal Analysis
Social sign-on and social sharing are becoming an ever more popular feature of web applications. This success is largely due to the APIs and support offered by...
