SSO with Native Mobile Applications
Eric Goodman
Eric.Goodman at ucop.edu
Tue Aug 26 14:57:38 EDT 2014
>>Per other threads, I presume your SAML ECP interface on your IdP:
>>
>>* is using basic-auth
>>* is world accessible
>Yes, but I imagine your main issue is more with the clients than the server.
>Any Web SSO system by definition is going to have a trivially spoofable way
>of phishing people while relaying credentials unless you're using certificates.
>Basic auth makes it a little easier but it's not all that big a difference.
Correct. I'm more worried about the concept of "sanctioning" client logins that bypass the visible IdP login page (with its hopefully well known URL).
>Mobile is a house of cards. I guess it's either that house of cards or the
>web's house of cards. Either way, I wouldn't blow too hard.
Yeah, I expected that answer, but was holding my breath (pun intended) hoping that it wouldn't be. But at least I got another got Scott Cantor quote to throw around in future discussions! :)
--- Eric
More information about the users
mailing list