ECP Newbie question

Ina Müller ina.mueller at zdv.uni-tuebingen.de
Wed Apr 4 13:54:57 BST 2012


Thank you for clarification.

The question came up in an internal discussion, whether ECP could be 
misused for phishing attacks, so one-time passwords are probably the 
best solution.

Ina


On 04.04.2012 13:09, Chad La Joie wrote:
> On Wed, Apr 4, 2012 at 06:57, Ina Müller
> <ina.mueller at zdv.uni-tuebingen.de>  wrote:
>> As I understand, an ECP client FIRST asks the user for credentials and
>> then afterwards contacts the IdP with these credentials (for example via
>> basic auth), is that right?
>
> Correct.
>
>> So if this ECP client (respectively the SP initially contacted by the
>> ECP client) is NOT an allowed relying party at our IdP, we can detect
>> this illegal access not until our users already gave away their
>> credentials, correct?
>
> Well, you can't ask the IdP via SAML, that is true.  That doesn't mean
> that your ECP client can't be configured with a list of acceptable
> SPs.  And the SP can send back a list of IdP's they accept which the
> ECP client could check against.
>
> I think though people would find this issue less of a concern than you
> seem to.  The ECP is software resident on the user's machine and only
> sends credentials to the user's IdP.  So it's not really any different
> than the browser.
>
>> Or is there any kind of verification between ECP/SP and IdP before the
>> user is asked for credentials?
>
> See above.  There is also no specific requirement on the
> authentication mechanism in general.  So, if you're concerned about
> what a client (ECP or browser) might do with the credential, then
> issue credentials that aren't easily exploitable by the client (e.g.,
> one-time use passwords).
>


More information about the users mailing list