SSO with Native Mobile Applications

Cantor, Scott cantor.2 at osu.edu
Tue Aug 26 14:02:02 EDT 2014


On 8/26/14, 1:49 PM, "Eric Goodman" <Eric.Goodman at ucop.edu> wrote:

>Is it bad form to hijack an old thread without changing the topic? Let me
>know and I'll repost in a new thread.

If it's the same topic, doesn't matter to me.

>Per other threads, I presume your SAML ECP interface on your IdP:
>
>* is using basic-auth
>* is world accessible

Yes, but I imagine your main issue is more with the clients than the
server. Any Web SSO system by definition is going to have a trivially
spoofable way of phishing people while relaying credentials unless you're
using certificates. Basic auth makes it a little easier but it's not all
that big a difference.

>Other than "mobile compatibility demanded it", were there any other
>discussions, requirements, mitigations that OSU went through before
>enabling that interface?

I tried to have the conversation, but nobody wanted to have it, so no.
I've tried fairly often since to have this conversation amongst
colleagues, but the security people I've interacted with just aren't
interested. It seems to be outside their scope of concern, or maybe it's
just too much of a swamp and they want to avoid it.

>In particular I'm thinking of anything you might have done that could
>help users understand what apps (especially mobile ones) are
>"sufficiently trustworthy" to hold or proxy their credentials. (This
>would include things beyond technical solutions, such as education
>campaigns, etc).

Not anything I was involved with, though I also raised that issue quite a
bit. If they've done that sort of user communication, I haven't seen it,
but it's possible they have.

Mobile is a house of cards. I guess it's either that house of cards or the
web's house of cards. Either way, I wouldn't blow too hard.

-- Scott



More information about the users mailing list