Covert Redirect is No Heartbleed | Internet News

Covert Redirect is No Heartbleed

May 7, 2014
1 minute read

On May 2, my inbox was bombarded with claims and comments about the “next Heartbleed,” a security flaw in the pervasive OAuth and OpenID authentication protocols, dubbed “covert redirect.” The claims stemmed from a report published by Jin Wang, a Ph.D. student at Nanyang Technological University in Singapore. OAuth and OpenID are widely deployed technologies that provide an easy way for users to authenticate to services.

“Almost all major OAuth 2.0 and OpenID providers are affected, such as Facebook, Google, Yahoo, LinkedIn, Microsoft, PayPal, GitHub, QQ, Taobao, Weibo, VK, Mail.Ru, Sohu, etc.,” Wang wrote. “The vulnerability could lead to Open Redirect attacks to both clients and providers of OAuth 2.0 or OpenID.”

In an “open redirect” attack, a user’s information is unknowingly redirected to an unauthorized location. The prospect of a flaw in OAuth and OpenID is one that could well have the same kind of impact as a Heartbleed vulnerability, but the simple fact is that the two vulnerabilities are vastly different.

Read the full story at eWEEK:
Heartbleed-Like Security Flaws Far-Reaching but Rare

Sean Michael Kerner is a senior editor at InternetNews.com. Follow him on Twitter @TechJournalist.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.