C. PKCE Chosen Challenge Attack

Issue #528 resolved
Nat Sakimura created an issue

Need to address what to do with C. PKCE Chosen Challenge Attack in FAPI 2.0

For the attack, see https://arxiv.org/pdf/1901.11520.pdf

Comments (6)

  1. Joseph Heenan

    The description of the attack says “This attack affects public clients who use the Read-Only profile of the FAPI.” - I can’t see an obvious way to apply the attack within the constrains of FAPI2?

  2. Tim Würtele

    I agree with Joseph here: FAPI 2.0 requires client authentication and the PKCE chosen challenge attack only works because a malicious client poses as a different, honest client when talking to the AS. Client authentication should prevent this.

  3. Log in to comment