Experimental browser for the Atmosphere
Hanno Böck (of badkeys.info among other projects) posted an interesting article about OpenID Connect implementations that mix up their public and private keys:
Feb 25, 2025, 7:55 PM
{ "uri": "at://did:plc:rzrcljpec5e52wvcacwxds4w/app.bsky.feed.post/3liznfdrgrw2h", "cid": "bafyreidz57jcmhhmgpeybzttugk2f7fyqywxcckrjmvouh27fzospuzps4", "value": { "text": "Hanno Böck (of badkeys.info among other projects) posted an interesting article about OpenID Connect implementations that mix up their public and private keys:", "$type": "app.bsky.feed.post", "embed": { "$type": "app.bsky.embed.external", "external": { "uri": "https://blog.hboeck.de/archives/909-Mixing-up-Public-and-Private-Keys-in-OpenID-Connect-deployments.html", "thumb": { "$type": "blob", "ref": { "$link": "bafkreidww6cnlc7mvsct25oylk4ebwjg53mm2xxroi32qkjkgvkpcqtucq" }, "mimeType": "image/png", "size": 34915 }, "title": "Mixing up Public and Private Keys in OpenID Connect deployments - Hanno's blog", "description": "This blog is written by Hanno Böck. Unless noted otherwise, its content is licensed as CC0." } }, "facets": [ { "index": { "byteEnd": 28, "byteStart": 16 }, "features": [ { "uri": "https://badkeys.info", "$type": "app.bsky.richtext.facet#link" } ] } ], "createdAt": "2025-02-25T19:55:26.482Z" } }