A well-known cryptographic attack could be used by hackers to log into web applications used by millions of users, according to two security experts who plan to discuss the issue at an upcoming security conference. Researchers Nate Lawson and Taylor Nelson say they've discovered a basic security flaw that affects dozens of open-source software libraries - including those used by software that implements the OAuth and OpenID standards - that are used to check passwords and user names when people
read full article




