SSO with Native Mobile Applications

Eric Goodman Eric.Goodman at ucop.edu
Tue Aug 26 14:57:38 EDT 2014


>>Per other threads, I presume your SAML ECP interface on your IdP:
>>
>>* is using basic-auth
>>* is world accessible

>Yes, but I imagine your main issue is more with the clients than the server. 
>Any Web SSO system by definition is going to have a trivially spoofable way 
>of phishing people while relaying credentials unless you're using certificates. 
>Basic auth makes it a little easier but it's not all that big a difference.

Correct. I'm more worried about the concept of "sanctioning" client logins that bypass the visible IdP login page (with its hopefully well known URL). 


>Mobile is a house of cards. I guess it's either that house of cards or the 
>web's house of cards. Either way, I wouldn't blow too hard.

Yeah, I expected that answer, but was holding my breath (pun intended) hoping that it wouldn't be. But at least I got another got Scott Cantor quote to throw around in future discussions! :)

--- Eric


More information about the users mailing list