Assurance Enhancements for IdPv2
Tom Scavo
trscavo at gmail.com
Tue May 21 15:09:50 EDT 2013
On Tue, May 21, 2013 at 9:05 AM, William G. Thompson, Jr.
<wgthom at gmail.com> wrote:
>
> The RFP requires two methods for presenting possible
> AuthNContexts/Methods and more sophisticated behavior than static MFA,
> not sure we can achieve all of that at post-login time.
I don't claim to understand the RFP very well but a multi-stage
approach to authentication seems to be essential. Here's a quote from
a recent blog article that is relevant:
"entering a username and correct password isn’t the end of the
authentication but merely the trigger to begin the Risk-based Access
ceremony" http://blogs.kuppingercole.com/kearns/2013/05/21/passwords-authentications-zombies/
Tom
More information about the dev
mailing list