ATProto Browser

ATProto Browser

Experimental browser for the Atmosphere

Post

Hanno Böck (of badkeys.info among other projects) posted an interesting article about OpenID Connect implementations that mix up their public and private keys:

Feb 25, 2025, 7:55 PM

Record data

{
  "uri": "at://did:plc:rzrcljpec5e52wvcacwxds4w/app.bsky.feed.post/3liznfdrgrw2h",
  "cid": "bafyreidz57jcmhhmgpeybzttugk2f7fyqywxcckrjmvouh27fzospuzps4",
  "value": {
    "text": "Hanno Böck (of badkeys.info among other projects) posted an interesting article about OpenID Connect implementations that mix up their public and private keys:",
    "$type": "app.bsky.feed.post",
    "embed": {
      "$type": "app.bsky.embed.external",
      "external": {
        "uri": "https://blog.hboeck.de/archives/909-Mixing-up-Public-and-Private-Keys-in-OpenID-Connect-deployments.html",
        "thumb": {
          "$type": "blob",
          "ref": {
            "$link": "bafkreidww6cnlc7mvsct25oylk4ebwjg53mm2xxroi32qkjkgvkpcqtucq"
          },
          "mimeType": "image/png",
          "size": 34915
        },
        "title": "Mixing up Public and Private Keys in OpenID Connect deployments  - Hanno's blog",
        "description": "This blog is written by Hanno Böck. Unless noted otherwise, its content is licensed as CC0."
      }
    },
    "facets": [
      {
        "index": {
          "byteEnd": 28,
          "byteStart": 16
        },
        "features": [
          {
            "uri": "https://badkeys.info",
            "$type": "app.bsky.richtext.facet#link"
          }
        ]
      }
    ],
    "createdAt": "2025-02-25T19:55:26.482Z"
  }
}