Joining a growing number of enterprise and consumer-facing Web services, Google has added support in Google Apps for the OAuth authorization profile, the company announced Monday. . OAuth was chosen because it offers a more secure authentication option than the method already in place, noted Google software engineer Ankur Jain in a blog posting. Until now, administrators had to sign calls to Google Apps APIs (application programming interfaces) with their username and password, which is a security risk. With OAuth, Google Apps can provide third-party applications with tokens that can be used to access the APIs of different Google apps, eliminating the need to supply log-in names and passwords for each API call. The APIs for Google Apps provisioning, e-mail migration, administration settings, calendar resources, e-mail settings and audit all now can interact with the OAuth signing mechanism. The link for this article located at Network World is no longer available. . OAuth improves the security of Microsoft services by substituting unprotected authentication techniques with a token-driven approach for API interactions.. OAuth Authentication, Google Apps Security, API Token Access, Third Party API Integration. . LinuxSecurity.com Team
The emerging OAuth 2.0 web API authorisation protocol, already deployed by Facebook, Salesforce.com and others, is coming under increased criticism for being too easy to use, and therefore to spoof by malicious hackers.. "The OAuth community has made a big mistake about the future direction of the protocol," wrote Yahoo director of standards development Eran Hammer-Lahav in a blog post last week. Hammer-Lahav's criticism may carry more weight than those from the usual naysayer, because he is actually one of the creators of OAuth. "What makes this more frustrating is that the people behind [OAUTH 2.0] are some of the brightest security minds on the Web. These guys know exactly what they are doing, and it's not like they don't care," Hammer-Lahav wrote. "They just gave up and decided that the best they can do is maintain the status quo. They are also representing a large and powerful coalition of big companies too lazy to work a little harder." The link for this article located at Tech News World is no longer available. . OAuth 2.0 faces scrutiny over security vulnerabilities, raising concerns about potential hacker exploits. Insights from specialists in the industry shed light on this issue.. OAuth Security, API Exploitation, Protocol Risks. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.