ECP Newbie question

Chad La Joie lajoie at itumi.biz
Wed Apr 4 15:24:29 BST 2012


I can't see how an ECP client would be susceptible to phishing.  The
whole point of ECP is that it's a "smart", secure client, resident on
the user's hardware and knows about your specific IdP.  So, there
shouldn't be anything that a rogue site could do in order to get the
client to send unintended data back to it.

All the above, of course, assume that the ECP client isn't just broken
in some very unfortunate manner.

On Wed, Apr 4, 2012 at 08:54, Ina Müller
<ina.mueller at zdv.uni-tuebingen.de> wrote:
> Thank you for clarification.
>
> The question came up in an internal discussion, whether ECP could be
> misused for phishing attacks, so one-time passwords are probably the
> best solution.
>
> Ina
>
>
> On 04.04.2012 13:09, Chad La Joie wrote:
>> On Wed, Apr 4, 2012 at 06:57, Ina Müller
>> <ina.mueller at zdv.uni-tuebingen.de>  wrote:
>>> As I understand, an ECP client FIRST asks the user for credentials and
>>> then afterwards contacts the IdP with these credentials (for example via
>>> basic auth), is that right?
>>
>> Correct.
>>
>>> So if this ECP client (respectively the SP initially contacted by the
>>> ECP client) is NOT an allowed relying party at our IdP, we can detect
>>> this illegal access not until our users already gave away their
>>> credentials, correct?
>>
>> Well, you can't ask the IdP via SAML, that is true.  That doesn't mean
>> that your ECP client can't be configured with a list of acceptable
>> SPs.  And the SP can send back a list of IdP's they accept which the
>> ECP client could check against.
>>
>> I think though people would find this issue less of a concern than you
>> seem to.  The ECP is software resident on the user's machine and only
>> sends credentials to the user's IdP.  So it's not really any different
>> than the browser.
>>
>>> Or is there any kind of verification between ECP/SP and IdP before the
>>> user is asked for credentials?
>>
>> See above.  There is also no specific requirement on the
>> authentication mechanism in general.  So, if you're concerned about
>> what a client (ECP or browser) might do with the credential, then
>> issue credentials that aren't easily exploitable by the client (e.g.,
>> one-time use passwords).
>>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the users mailing list