Person
Daniel Fett
Security consultant specializing in identity and web-protocol security, and contributor to OAuth and OpenID Connect work in the OpenID Foundation and IETF. His official IETF record includes RFC 9207, RFC 9449, RFC 9700, RFC 9901 and RFC 10027.
What to know first
- Public roleSecurity consultant specializing in identity and web-protocol security, and contributor to OAuth and OpenID Connect work in the OpenID Foundation and IETF. His official IETF record includes RFC 9207, RFC 9449, RFC 9700, RFC 9901 and RFC 10027.Medium confidence
- Source basisPublic directory evidenceMedium confidence
- Last verifiedAug 31, 2026High confidence
Basic information
- NameDaniel FettHigh confidence
- Public roleSecurity consultant specializing in identity and web-protocol security, and contributor to OAuth and OpenID Connect work in the OpenID Foundation and IETF. His official IETF record includes RFC 9207, RFC 9449, RFC 9700, RFC 9901 and RFC 10027.Medium confidence
- Last verifiedAug 31, 2026High confidence
Related entities, projects, and resources
- Editorial contextDaniel Fett and the Issuer Field That Named the Server, Not the Token, An OAuth callback can contain the right state and a real authorization code and still be on its way to the wrong server. RFC 9207 adds one small comparison before that mistake becomes a disclosure: did the server named in the response match the issuer the client recorded when the flow began?Medium confidence
- Editorial contextDaniel Fett and the QR Context That MFA Never Authenticated, The password was right, the second factor was real and the authorization server behaved as designed. The attacker still received the session, because the ceremony proved who the user was without proving whose request the user had approved.Medium confidence
