Skip to content

Commit bec718e

Browse files
Merge branch 'master' of github.com:stfbk/stfbk.github.io
2 parents 12c6aa6 + 598bccc commit bec718e

File tree

4 files changed

+48
-0
lines changed

4 files changed

+48
-0
lines changed

_complementary/OIDCPrivacy2025.md

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
---
2+
title: Best Current Practices for Privacy-Preserving OpenID Connect
3+
subtitle: A Study of Their Adoption in the Wild
4+
paper: OIDCPRIV2025
5+
6+
people:
7+
- GianlucaSassetti
8+
- AmirSharif
9+
- GiadaSciarretta
10+
- RobertoCarbone
11+
- SilvioRanise
12+
13+
peopleOrder: surname
14+
---
15+
16+
**Supplementary material**:
17+
A comprehensive results of our entire survey of OP's compliance is available [here](https://drive.google.com/drive/folders/11v_vF2eIk0alQVcQCTXDXXLEasT1vW6U).
18+
19+
**Privacy BCP Compliance Script** Our Python script queries the OPs discovery endpoints and checks for compliance with respect to the privacy BCPs is availble [here](https://github.com/ImGilbes/oidc_discovery_privacy/).

_data/dissemination.yml

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -531,4 +531,17 @@
531531
- name: Event
532532
url: https://www.internetfestival.it/programma/tecniche-avanzate-per-la-sicurezza-meccanismi-autenticazione-forte/
533533

534+
- id: W3CTPAC2025
535+
title: "Mitigate Threats for Digital Credentials API: Episode III - Revenge of the Wallet"
536+
participants:
537+
- ZahraEbadiAnsaroudi
538+
- AmirSharif
539+
eventName: W3C Technical Plenary and Advisory Committee (TPAC)
540+
startDate: "2025-11-10"
541+
endDate: "2025-11-14"
542+
category: Specialized
543+
links:
544+
- name: Event
545+
url: https://www.w3.org/events/meetings/202a8c77-ba79-42d9-8c60-33b10544a227/
546+
534547
# PLEASE KEEP CHRONOLOGICAL ORDER BY START DATE WITHIN YEARS

_data/publications.yml

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2342,6 +2342,21 @@
23422342
destination: JINS
23432343
year: 2025
23442344
doi: 10.1186/s13635-025-00187-6
2345+
2346+
- id: OIDCPRIV2025
2347+
id_iris:
2348+
title: "Best Current Practices for Privacy-Preserving OpenID Connect: A Study of Their Adoption in the Wild"
2349+
authors:
2350+
- GianlucaSassetti
2351+
- AmirSharif
2352+
- GiadaSciarretta
2353+
- RobertoCarbone
2354+
- SilvioRanise
2355+
abstract: >
2356+
The transition from centralized identity architecture to a decentralized one introduces profound shifts in the privacy protection of users' data. Yet, as decentralized identity continues to mature, today's online services still overwhelmingly depend on centralized identity management solutions built on top of OpenID Connect (OIDC) as the most widespread solution. Ensuring privacy-preserving OIDC deployments is therefore critical for safeguarding users' personal data and maintaining compliance with regulatory frameworks such as the General Data Protection Regulation (GDPR) and trust frameworks, such as the Electronic Identification, Authentication and Trust Services (eIDAS). However, the current OIDC ecosystem lacks a coherent set of privacy Best Current Practices (BCPs) and a study of how widely these privacy-enhancing features are adopted in real-world deployments. To this end, this work addresses the aforementioned gaps on two fronts. First, we propose a structured set of privacy BCPs derived from official OIDC specifications and current implementation trends, identifying easy-to-deploy privacy-enhancing features that strengthen the OIDC deployments' baseline privacy without altering the protocol or compromising interoperability. Furthermore, the BCPs also help achieve the GDPR privacy principles, such as data minimization, confidentiality, and unlinkability. Second, this work provides a comprehensive survey of OpenID Providers (OPs) in the wild to identify gaps in privacy-preserving configurations in both private and public (i.e., national) sectors OPs. The study employs a dual methodology: first, a manual review performed in 2022; subsequently, an automated compliance analysis performed in 2025 surveying a dataset of 10000 OPs worldwide. The results reveal a concerning lack of privacy-enhancing features among private OPs and a wide gap between private and national OPs, with the latter group providing, on average, much higher baseline privacy. We have also found a prevalence of misconfigured OPs not complying with the OIDC specifications, potentially resulting in misconfigured and non-compliant OPs. The paper emphasizes the importance of adopting actionable BCPs to improve baseline privacy and demonstrates the need for an automated framework for ongoing privacy compliance assessments in OIDC ecosystems.
2357+
destination: COSE
2358+
year: 2025
2359+
doi:
23452360

23462361
- id: SECRYPT2025
23472362
id_iris: 360987

_data/teaching.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -65,6 +65,7 @@
6565
- SilvioRanise
6666
- MatteoRizzi
6767
startYear: 2019
68+
endYear: 2024
6869
links:
6970
- name: 2019/2020
7071
url: "https://fbkjunior.fbk.eu/wp-content/uploads/2023/01/corso-cybersecurity.pdf"

0 commit comments

Comments
 (0)