Re: [OAUTH-WG] [EXT] Re: WGLC review of draft-ietf-oauth-security-topics-13

2019-11-28 Thread Torsten Lodderstedt
Hi, > On 27. Nov 2019, at 15:04, Pedram Hosseyni > wrote: > > Hi Mike, > > > Wouldn't most RSs only trust access tokens from a single AS anyways? > > At the last OSW, there was broad agreement that this is typically the case. > Otherwise, the mitigation that we suggested in the paper would n

[OAUTH-WG] draft-ietf-oauth-security-topics: Migration strategies for deprecated password grant

2019-11-28 Thread Jorge Bernal
Hi all, We are currently discussing[1] an implementation of oAuth for WordPress and what this would mean for our mobile apps[2]. It was noted that the new recommendation will completely discourage the use of the password grant. While I agree in principle that this is a good thing overall, we will