> Building a protocol over HTTP has the added benefit of making security easy
Not to take away from that, it's also very easy to get wrong as well.
- Not doing CA verification check[1]
- No alerts/monitoring of new certificates used by the IDP
- No verification on certificate-transparency of new certificates used by the IDP
- No online CRL checking
If you do not do these things, then your application-on-HTTP is insecure. Remember that it's very easy to get a new certificate if you can break IP either by MITMing the server or by BGP takeover of some space near the CA. Both of these things have happened.
If there's a way you can detect incorrect implementations, then blacklist them. For example, I use OAuth2 in my own systems, but I require clients retry (by randomly failing during onboarding) and implement fuzzing whereby the client_secret is invalidated if they accept an invalid certificate.
[1]: http://web.archive.org/web/20120317165131/http://forum.devel...