[OAUTH-WG] Fwd: OAuth Security Consideration Text

2011-05-11 Thread Hannes Tschofenig
Breno did a review of the security draft. Thanks a lot! Begin forwarded message: From: Breno de Medeiros br...@google.com Date: May 7, 2011 4:25:53 AM GMT+03:00 To: Hannes Tschofenig hannes.tschofe...@gmx.net Subject: Re: OAuth Security Consideration Text Hi Hannes, I have gone through

Re: [OAUTH-WG] Fwd: OAuth Security Consideration Text

2011-05-11 Thread Lodderstedt, Torsten
Hi Breno, thanks for the feedback. Please find my comments inline. Now higher level comments: On Native Apps protection of refresh token: On section Definitions, there is a sentence in the Native Apps It is assumed that such applications can protect dynamically issued secrets,

Re: [OAUTH-WG] Fwd: OAuth Security Consideration Text

2011-05-11 Thread Breno
On Wed, May 11, 2011 at 7:23 PM, Lodderstedt, Torsten t.lodderst...@telekom.de wrote: Hi Breno, thanks for the feedback. Please find my comments inline. Now higher level comments: On Native Apps protection of refresh token: On section Definitions, there is a sentence in the