OpenSAML dependency on Velocity breaks application

Chad La Joie lajoie at itumi.biz
Wed May 2 13:57:38 BST 2012


On Wed, May 2, 2012 at 8:28 AM, Tom van den Berge
<tom.vandenberge at gmail.com> wrote:
> I'm not sure what you mean with an "open" IdP, but if that means that one
> would have to register with shibboleth.net, and it is branded as such, that
> would be fine. I haven't seen a Jira installation not doing it like this, so
> that is what surprised me on your site.

Sorry, by "open" I meant that anyone would be able to create an
account (i.e., not just people in a particular organization).

Right, you don't see this much because Atlassian goes out of their way
to make sure their products can't be integrated with external
authentication systems.  The cynic in me notes that they sell a
separate product to sorta does this and so have a financial incentive
to ensure such integration is difficult in any of their other systems.

> What would you do if you wanted to raise an issue on my Jira, and I would
> let you set up an account with a seemingly unrelated company that you don't
> know?

Well, relationship clearly isn't the issue here.  You said you would
be fine using a Google account and there is no relationship between
them and your Jira.  The crux of the issue is really whether you trust
any given organization with some subset of your data.  I happen to be
okay with Google having a limited subset of my data so I'd be okay
using them for something like this.  If some one said I had to use
Facebook I'd tell them to go to hell because I don't trust that
organization at all.

So, to answer your specific question.  If your directions listed the
people your Jira instance accepted then I'd look for one that wasn't
on my blacklist of organizations (e.g., Facebook) and that didn't ask
for an unacceptable amount of data[1] and I'd use them.  If there was
no IdP left after my little mental filtering process then I wouldn't
create an account.

So, I understand your mental filtering process might exclude
ProtectNetwork.  And from what you said, a seemingly related domain
name and site appearance would be enough to allow a given IdP to make
it through that filtering process.  Which is good info for us.

While we're discussing this then, would it have mattered at all if
ProtectNetwork (or any other randomly selected IdP) had displayed our
logo, service name, and description on their page and stated you were
jumping through these hoops in order to work with our app?



[1] Incidentally, I think many people have a totally irrational view
of what is an acceptable set of data to provide to account bearing
organizations.  Anyone who thinks, for example, that asking for their
name, physical address, phone/fax/mobile number, or email address is
too much data doesn't understand that all that data is public data,
either by law (in the US) or in effect.

-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the dev mailing list