LIVE · cybersecurity feed
Live wire
cloud

From all-or-nothing to task-based OAuth consent

Cloudflare OAuth now supports optional scopes, giving users more control over what an app can access and helping developers build secure consent flows around the task at hand.

zeroday.news ·

A significant enhancement to the OAuth consent process, moving from an "all-or-nothing" model to a more granular, task-based approach, has been introduced. This update aims to provide users with finer control over the permissions granted to third-party applications, addressing long-standing security and privacy concerns associated with broad consent requests.

Previously, when a user authorized an application via OAuth, they were often presented with a single, comprehensive request for all necessary permissions. This meant that even if an application only needed to perform a specific task, it would typically request access to a wider range of data or functionalities than strictly necessary. Users had little choice but to accept all permissions or deny the application entirely.

The new task-based consent mechanism allows applications to request specific permissions for individual tasks. For example, instead of an application asking for "full access to your calendar," it might now request "permission to create new events" or "permission to view event details," depending on the exact functionality required. This provides a clearer understanding of what data or actions an application intends to perform.

This shift is designed to mitigate risks associated with over-privileged applications. By limiting an application's access to only what is essential for its intended function, the potential impact of a compromised application or a malicious developer is reduced. Should an application be exploited, the attacker's access would be confined to the specific, task-based permissions granted, rather than a broad sweep of user data.

The change also empowers users with more informed decision-making. They can now review and approve or deny individual permissions, rather than being forced into an all-or-nothing choice. This increased transparency is expected to foster greater trust in third-party integrations and improve overall user privacy.

Developers are encouraged to update their applications to leverage this new consent model, ensuring they request only the minimum necessary permissions for each task. This best practice aligns with the principle of least privilege, a fundamental concept in cybersecurity. The implementation of this feature is a direct response to feedback from the developer community and user advocates who have long sought more refined control over OAuth permissions.

cloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

security

China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?

This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt Typhoon

nation-state

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive

malware

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware

Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.

security

What We Missed: Delta Flight Disrupted With Wi-Fi Hack

In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest "hack back" strategy.

security

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist

Kyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting. The post Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist appeared first on CyberScoop.