ECP Newbie question
Ina Müller
ina.mueller at zdv.uni-tuebingen.de
Wed Apr 4 13:54:57 BST 2012
Thank you for clarification.
The question came up in an internal discussion, whether ECP could be
misused for phishing attacks, so one-time passwords are probably the
best solution.
Ina
On 04.04.2012 13:09, Chad La Joie wrote:
> On Wed, Apr 4, 2012 at 06:57, Ina Müller
> <ina.mueller at zdv.uni-tuebingen.de> wrote:
>> As I understand, an ECP client FIRST asks the user for credentials and
>> then afterwards contacts the IdP with these credentials (for example via
>> basic auth), is that right?
>
> Correct.
>
>> So if this ECP client (respectively the SP initially contacted by the
>> ECP client) is NOT an allowed relying party at our IdP, we can detect
>> this illegal access not until our users already gave away their
>> credentials, correct?
>
> Well, you can't ask the IdP via SAML, that is true. That doesn't mean
> that your ECP client can't be configured with a list of acceptable
> SPs. And the SP can send back a list of IdP's they accept which the
> ECP client could check against.
>
> I think though people would find this issue less of a concern than you
> seem to. The ECP is software resident on the user's machine and only
> sends credentials to the user's IdP. So it's not really any different
> than the browser.
>
>> Or is there any kind of verification between ECP/SP and IdP before the
>> user is asked for credentials?
>
> See above. There is also no specific requirement on the
> authentication mechanism in general. So, if you're concerned about
> what a client (ECP or browser) might do with the credential, then
> issue credentials that aren't easily exploitable by the client (e.g.,
> one-time use passwords).
>
More information about the users
mailing list