Shib SP ECP - a few woes
Cantor, Scott
cantor.2 at osu.edu
Sat Oct 19 14:59:53 EDT 2013
On 10/19/13 2:57 PM, "Giovanni Bajo" <rasky at develer.com> wrote:
>
>What I meant is that, in the WebSSO profile, there is no need for this
>additional out-of-band information. When the browser accesses the SP, it
>gets redirected to the IdP URL for authenticating the user.
Yes, which is a horrible, horrible thing. It's why phishing exists, in
part.
>On the contrary, on the ECP profile, the SP doesn't convey this
>information to the client, and the client needs to be aware of where the
>IdP is located.
Yes, that's a feature, not a bug.
If you have an authentication flow in which the potential attacker tells
the client where to go, you have a serious problem. The web has very
serious problems.
-- Scott
More information about the users
mailing list