Skip to content

Releases: oauth-wg/oauth-cross-device-security

draft-ietf-oauth-cross-device-security-16

02 Mar 16:15
9ee8174

Choose a tag to compare

What's Changed

  • Update affiliation
  • Update references and add mentions of the DC API using BLE enabled proximity by @danielfett in #274
  • Added document history section by @PieterKas in #275

Full Changelog: draft-ietf-oauth-cross-device-security-15...draft-ietf-oauth-cross-device-security-16

draft-ietf-oauth-cross-device-security-15

23 Jan 18:54
003a506

Choose a tag to compare

Updated with feedback received from area reviews and IESG

What's Changed

  • Fix typo in cross-device security document by @PieterKas in #254
  • Clarify best practices for cross-device security by @PieterKas in #246
  • Update guidance for defending against cross-device attacks by @PieterKas in #247
  • Update user education and add NIST phishing reference by @PieterKas in #253
  • Clarify practical mitigations summary wording by @PieterKas in #252
  • Update authorization server misuse detection language by @PieterKas in #250
  • Enhance trusted network section with SIM inference by @PieterKas in #251
  • Refine proximity considerations in authorization scenarios by @PieterKas in #249
  • Remind implementors to evaluate privacy implications. by @PieterKas in #248
  • Nits flagged in Med's IESG Review by @boucadair in #237
  • Enhance physical connectivity section with security risks by @PieterKas in #264
  • Clarify user interface for declining authorization requests by @PieterKas in #265
  • Clarify mitigation selection process in best practices by @PieterKas in #267
  • Refine authorization data flow and examples by @PieterKas in #269
  • Update cross-device protocol guidance for same-device use by @PieterKas in #270
  • Clarify proximity checks in cross-device security guidelines by @PieterKas in #268
  • Update CTAP title and add publisher information by @PieterKas in #266
  • Fix spelling and grammatical issues in document by @PieterKas in #271
  • Figure numbering by @PieterKas in #273

New Contributors

Full Changelog: draft-ietf-oauth-cross-device-security-14...draft-ietf-oauth-cross-device-security-15

draft-ietf-oauth-cross-device-security-14

05 Jan 12:39
276e2a1

Choose a tag to compare

Changes

Updates to text and diagrams to provide additional clarity based on IETF Last Call feedback

Details

Full Changelog: draft-ietf-oauth-cross-device-security-13...draft-ietf-oauth-cross-device-security-14

draft-ietf-oauth-cross-device-security-13

02 Dec 14:09
66fe44b

Choose a tag to compare

Address Area Director (AD) feedback - details below:

What's Changed

Full Changelog: draft-ietf-oauth-cross-device-security-12...draft-ietf-oauth-cross-device-security-13

draft-ietf-oauth-cross-device-security-12

05 Sep 09:52
ee386e9

Choose a tag to compare

Fixed references to point to final versions of specifications

What's Changed

Full Changelog: draft-ietf-oauth-cross-device-security-11...draft-ietf-oauth-cross-device-security-12

draft-ietf-oauth-cross-device-security-11

22 Jul 07:51
326e66d

Choose a tag to compare

Includes formatting and editorial changes to clarify existing text.

What's Changed

Full Changelog: draft-ietf-oauth-cross-device-security-10...draft-ietf-oauth-cross-device-security-11

draft-ietf-oauth-cross-device-security-10

17 Jun 14:16
6e83ca1

Choose a tag to compare

Addresses shepherd feedback

  • Shepherd feedback: Describe unauthenticated channel.
  • Shepherd feedback: Separate normative and informative references.
  • Shepherd feedback: Update FIDO/WebAuthn references

draft-ietf-oauth-cross-device-security-09

06 Jan 10:35
8af0d5f

Choose a tag to compare

  • Affiliation change to allow publication to Datatracker.
  • No content changes - re-published to avoid expiry while waiting on shepherd review.

draft-ietf-oauth-cross-device-security-08

08 Jul 09:26
d25da44

Choose a tag to compare

draft-ietf-oauth-cross-device-security-07

13 May 19:49
b37f62d

Choose a tag to compare

Includes feedback from Working Group Last Call. Changes include:

  1. Clarification of FIDO\WebAuthn section.
  2. Updated langugage in section on FIDO to allow for use of FIDO keys on consumption devices.
  3. Clarified origin of QR Code.
  4. Editorial updates
  5. Updated examples to be consistent.
  6. Made diagram description clearer.
  7. Added CTAP 2.2 Draft.
  8. Added additional guidance on geolocation inaccuracies.
  9. Added Roy Williams to acknowledgements
  10. Clarified that authorization servers can detect
  11. Consistent use of "smart TV"
  12. Fixed references