On Breaking SAML

Paul Hethmon paul.hethmon at clareitysecurity.com
Fri Aug 10 09:57:15 EDT 2012


I just read through the paper myself and I note that Scott is credited
with helping them out. So hopefully that means they've already implemented
some of the changes necessary to prevent the attacks.

Paul

On 8/10/12 9:44 AM, "Tom Scavo" <trscavo at gmail.com> wrote:

>I assume you've already heard about this, but just in case you haven't:
>
>http://www.nds.rub.de/research/publications/BreakingSAML/
>
>Shibboleth is mentioned (implicated?) in this research paper.
>
>Tom
>--
>To unsubscribe from this list send an email to
>dev-unsubscribe at shibboleth.net



More information about the dev mailing list