Shib SP ECP - a few woes
Leif Johansson
leifj at sunet.se
Sun Oct 20 04:03:57 EDT 2013
> 19 okt 2013 kl. 21:00 skrev "Cantor, Scott" <cantor.2 at osu.edu>:
>
>> On 10/19/13 2:57 PM, "Giovanni Bajo" <rasky at develer.com> wrote:
>>
>> What I meant is that, in the WebSSO profile, there is no need for this
>> additional out-of-band information. When the browser accesses the SP, it
>> gets redirected to the IdP URL for authenticating the user.
>
> Yes, which is a horrible, horrible thing. It's why phishing exists, in
> part.
>
>> On the contrary, on the ECP profile, the SP doesn't convey this
>> information to the client, and the client needs to be aware of where the
>> IdP is located.
>
> Yes, that's a feature, not a bug.
>
> If you have an authentication flow in which the potential attacker tells
> the client where to go, you have a serious problem. The web has very
> serious problems.
>
yep, i believe this sort of thing has bitten oauth more than once for instance, and not just as a theoretical thing either
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list