Shibboleth Security Advisory [24 October 2011]
Chad La Joie
lajoie at itumi.biz
Tue Oct 25 18:35:31 BST 2011
On Tue, Oct 25, 2011 at 13:26, James F. Green <jfgreen1 at gmail.com> wrote:
> I am trying to be sure I understand all the implications of this advisory. I am hindered by my ignorance of the inner workings of the IdP and SP software (not to mention networking and security). I'm concerned about this statement:
>
>> Therefore, if deployers are sending sensitive information and either the
>> browser is not trusted or the SP is not using TLS, we recommend that you
>> do not "push" attributes[3] within the SSO assertion.
>
> Is it only attributes that are exposed? Or does the SSO assertion contain other items, for example, session or SSO tokens, that might also be revealed?
The only other bit of data that may be sensitive is that some
individuals send their userids not as attributes but as name
identifiers. So, if you configure the IdP to do this (and it has to
be deliberate, the IdP doesn't ship with this configuration) and you
view userids as sensitive, then that would be an issue.
> Also, I am confused by the idea of whether "the browser is not trusted." My understanding is the browser is not trusted until the user has authenticated successfully, and then it is (for better or worse). Or am I confused, I mean, can attributes be pushed to the browser even without successful authentication -- if that's so, then the browser would never be trusted. Yes, I am definitely confused.
One reason people have wanted to use encrypted assertions is because
they fear the browser might have malware on it and that that malware
might look for SAML assertions and relay potentially sensitive
attributes back to some nefarious person/group.
I personally have never really bought this line of reasoning because
the step just prior to sending the assertion, in most cases, was
entering your username/password. Given that information, an attacker
could probably get far more information than is ever sent in the SAML
assertion anyways.
--
Chad La Joie
www.itumi.biz
trusted identities, delivered
More information about the users
mailing list