Security Vulnerabilities in Single-Sign On

A Very Unscientific Meta Analysis

OAuth
Author

errbufferoverfl

Published

October 28, 2023

Modified

June 18, 2025

In 2014, automated testing of the top twenty thousand top-ranked websites using the Facebook SDK, found over 20% were suffering from at least one of five security vulnerabilities.1

1 Zhou and Evans, “SSOScan: Automated Testing of Web Applications for Single Sign-On Vulnerabilities.”

The study focused on five unique vulnerabilities:

Regarding vulnerabilities identified:

Regarding the profile of affected sites:

Regarding remediation:

2 What does this even mean?! 😂

3 At the time personal data belonging to millions of Facebook users was collected without their consent by British consulting firm Cambridge Analytica.

4 One year prior to this paper being published in June 2013, there was news that a bug in the contact information archive that allowed personal data of approximately 6 million Facebook users to be leaked online. It is believed that the original issue was introduced in 2012.

Regarding Facebook:3 and 4