Shib SP ECP - a few woes

Leif Johansson leifj at sunet.se
Sun Oct 20 04:03:57 EDT 2013




> 19 okt 2013 kl. 21:00 skrev "Cantor, Scott" <cantor.2 at osu.edu>:
> 
>> On 10/19/13 2:57 PM, "Giovanni Bajo" <rasky at develer.com> wrote:
>> 
>> What I meant is that, in the WebSSO profile, there is no need for this
>> additional out-of-band information. When the browser accesses the SP, it
>> gets redirected to the IdP URL for authenticating the user.
> 
> Yes, which is a horrible, horrible thing. It's why phishing exists, in
> part.
> 
>> On the contrary, on the ECP profile, the SP doesn't convey this
>> information to the client, and the client needs to be aware of where the
>> IdP is located.
> 
> Yes, that's a feature, not a bug.
> 
> If you have an authentication flow in which the potential attacker tells
> the client where to go, you have a serious problem. The web has very
> serious problems.
> 

yep, i believe this sort of thing has bitten oauth more than once for instance, and not just as a theoretical thing either

> -- Scott
> 
> 
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



More information about the users mailing list