Question on IDP session randomness (low entrophy)

Cantor, Scott cantor.2 at osu.edu
Wed Dec 12 11:55:08 EST 2012


On 12/12/12 11:52 AM, "Anand Somani" <meatforums at gmail.com> wrote:

>* But this means there is some state which is identified by something set
>in the cookie and I suppose this uses a more secure random key?

Yes.

>* Cause in theory I login as "joe" and I get redirected for getting
>Assertion, but if somebody "tom" else guesses that key and is able to get
>(by injecting between this redirect, from another bot) the assertion and
>redirect and now the SP lets in "tom" as
> "joe" - is this not possible?

If you steal a session cookie and spoof the IP address, yes.

-- Scott




More information about the users mailing list