IDP Logout, text asking user whether or not to kill the IDP session
Brian Tingle
Brian.Tingle at ucop.edu
Thu Oct 17 02:59:37 EDT 2013
> On Oct 16, 2013, at 8:52 PM, "Jim Fox" <fox at washington.edu> wrote:
>
> You are not really logged out of anything until you throw your workstation into saltwater.
What is recommended practice to educate service users regarding this issue. In one app we are developing, we just don't have a "logout" option. The other app is 3rd party app and has a "logout" that only nominally logs you out of the app but not the IdP.
Is this just something we should note in the privacy policy or the terms of use or help documentation?
Also; re: "nothing is easy" -- fair enough but it reminds me of a meeting I was in years ago about cross campus authentication for a 3rd party application where I told a director "this is pretty complicated" basically over and over till she got mad and yelled "well, make it simple!" at me.
More information about the users
mailing list