Question on IDP session randomness (low entrophy)

Anand Somani meatforums at gmail.com
Wed Dec 12 12:33:18 EST 2012


Awesome! thanks for your prompt responses.

On Wed, Dec 12, 2012 at 8:55 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> On 12/12/12 11:52 AM, "Anand Somani" <meatforums at gmail.com> wrote:
>
> >* But this means there is some state which is identified by something set
> >in the cookie and I suppose this uses a more secure random key?
>
> Yes.
>
Awesome!

>
> >* Cause in theory I login as "joe" and I get redirected for getting
> >Assertion, but if somebody "tom" else guesses that key and is able to get
> >(by injecting between this redirect, from another bot) the assertion and
> >redirect and now the SP lets in "tom" as
> > "joe" - is this not possible?
>
> If you steal a session cookie and spoof the IP address, yes.
>
Yeah not much you can do about that.

>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20121212/edbe3f9c/attachment.html 


More information about the users mailing list