Louis Jannett

dblp:332/3121 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
4since 2021 · last 2025
0000-0001-5448-5929ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 4 since 2021
YearPublicationVenuePosition
2025 "Only as Strong as the Weakest Link": On the Security of Brokered Single Sign-On on the Web
abstract
Single Sign-On (SSO) is an authentication process that allows users to access multiple services with a single set of login credentials. Although SSO improves the user experience, it poses challenges to developers to implement complex authentication protocols securely. External services, called brokers, simplify the integration of SSO. In this paper, we shed light on the emerging brokered SSO ecosystem, focusing on the security of the newly introduced actor, the broker. We systematically evaluate the landscape of brokered SSO, uncovering significant blind spots in previous research. Our study reveals that 25% of the websites with SSO integrate brokers for authentication, an area that has not been covered by any previous research. Through our comprehensive security evaluation, we identify three categories of threats associated with brokered SSO: (1) insufficient validation of redirect chains enabling injection attacks, (2) unauthorized data access enabling account takeovers, and (3) violations of security best current practices. We expose vulnerabilities in over 50 brokers, compromising the security of more than 2k websites. These findings represent only a lower bound of a critical situation, underscoring the urgent need for improved security measures and protocols to safeguard the integrity of brokered SSO systems.
Tommaso Innocenti, Louis Jannett, Christian Mainka, Vladislav Mladenov, Engin Kirda
SP2
2024 Single Sign-On Privacy: We Still Know What You Did Last Summer
abstract
Today, Single Sign-On (SSO) is omnipresent on the Internet. Every day, millions of users utilize SSO protocols such as OAuth 2.0 (OAuth) or OpenID Connect 1.0 (OIDC). These protocols allow users to log in to multiple websites or services, called Relying Partys (RPs), using their accounts from major Identity Providers (IdPs) such as Apple, Facebook, and Google. Consequently, these IdPs gain the ability to track their users across the Internet. In return, RPs gain access to an enriched set of the user’s personal data stored at the IdP, including names, email addresses, and profile pictures.In this paper, we present three novel SSO privacy leaks found in the wild. Contrary to prior work, our leaks occur automatically as soon as the user visits the RP, without their consent or awareness, in a non-transparent manner. To prove their prevalence, we conducted a large-scale study on the Tranco top 1M websites. Our measurement shows that 10,931 RPs automatically leak the user’s identity, the currently visited RP, and other metadata (e.g., time of access) to the IdPs (partial leak). Additionally, 2,947 RPs silently deanonymize users, logging them into their accounts without their awareness (full leak). Even worse, 6 RPs leak the user’s identity to third parties (escalated leak). Besides 4 major IdPs, including Facebook and Google, we identified privacy leaks affecting 1,032 additional, less-popular IdPs. Conversely, 7 IdPs, including Apple and Github, are exemplary in avoiding these leaks.To protect users, we present our browser extension called SSO Privacy Guard. We demonstrate its effectiveness in preventing all the identified leaks. Furthermore, we discuss if and how emerging initiatives by major browser vendors related to tracking prevention can also improve privacy in the SSO ecosystem. To promote reproducibility, we publicly release the source code and all artifacts, and we plan to release SSO Privacy Guard in the official Chrome and Firefox extension stores.
Maximilian Westers, Andreas Mayer, Louis Jannett
ACSAC3
2024 SoK: SSO-MONITOR - The Current State and Future Research Directions in Single Sign-on Security Measurements
abstract
Single Sign-On (SSO) with OAuth 2.0 and OpenID Connect 1.0 is essential for user authentication and autho-rization on the Internet. Billions of users rely on SSO services provided by Google, Facebook, and Apple. For large-scale measurements on the security of SSO, researchers need to reliably detect SSO implementations in the wild. In this paper, we survey the current state of 36 SSO measurement tools from prior work and discover gaps leading to blind spots in the SSO landscape that hinder the community from improving large-scale research. We observe unreliable measurements and a lack of reproducibility, making comparisons between studies difficult, if not impossible. We fill these gaps with SSO-MONITOR, our open-source, modular, and highly extensible framework for large-scale SSO landscape and security measurements. SSO-MONITOR achieves a high accuracy of 93% and, compared to pre-vious tools, significantly improves the reliability of SSO measurements by 19 %. It continuously takes snapshots of SSO implementations on the top 1M web sites to compose an SSO archive that is reproducible by design. Therefore, it passively monitors the SSO flows and provides an extensive set of landscape and security insights on sso-monitor.me. Our SSO archive allows researchers to perform comprehensive measurements over time and even beyond the scope of SSO. We use the data in our SSO archive to measure the security of 89k SSO authentication flows on the top 1M websites. Thereby, we discover 33k violations of OAuth Security Best Current Practices and 339 severe security vulnerabilities. They include 30 username and password leaks and 28 token leaks that allow full account takeovers.
Louis Jannett, Christian Mainka, Maximilian Westers, Andreas Mayer, Tobias Wich, Vladislav Mladenov
EuroS&P1
2022 DISTINCT: Identity Theft using In-Browser Communications in Dual-Window Single Sign-On
abstract
Single Sign-On (SSO) protocols like OAuth 2.0 and OpenID Connect 1.0 are cornerstones of modern web security, and have received much academic attention. Users sign in at a trusted Identity Provider (IdP) that subsequently allows many Service Providers (SPs) to verify the users' identities. Previous research concentrated on the standardized - called textbook SSO in this paper - authentication flows, which rely on HTTP redirects to transfer identity tokens between the SP and IdP. However, modern web applications like single page apps may not be able to execute the textbook flow because they lose the local state in case of HTTP redirects. By using novel browser technologies, such as postMessage, developers designed and implemented SSO protocols that were neither documented nor analyzed thoroughly. We call them dual-window SSO flows.
Louis Jannett, Vladislav Mladenov, Christian Mainka, Jörg Schwenk
CCS1