IDP Logout, text asking user whether or not to kill the IDP session

Cantor, Scott cantor.2 at osu.edu
Tue Oct 15 21:06:03 EDT 2013


On 10/15/13 6:31 PM, "Bryan E. Wooten" <bryan.wooten at utah.edu> wrote:

>You aren't wrong. I wonder if MFA helps this situation?

Not really. No matter what, you can't authenticate on every request to a
service, which means you have a cookie. At that point, it's game over.

The web is just badly broken I'm afraid unless you give up on shared
devices.

-- Scott




More information about the users mailing list