Burden of Authorization

federator wpadmin at identiainc.com
Thu Dec 18 18:33:06 EST 2014


Scott, one more comment and I will shut up..

Nick
On 12/18/14 5:02 PM, Cantor, Scott wrote:
> On 12/18/14, 9:43 PM, "federator" <wpadmin at identiainc.com> wrote:
>
>> That's very true because these vendors don't do authorization, and this
>> is why:  The hard reality is that 99% of the service provider
>> implementation today is still based on account-based security using
>> Role-based access control.
> It's true that a lot of them have that basic model, and yes, that means
> provisioning and so forth, which is a hassle. Those aren't usually the
> worst problem cases though. The more common case at scale (think Google
> Apps, Box, etc.) is that there is *no* authorization model.
>
> -- Scott
Yes, this is because in a consumer world, no authorization is needed.  
When a user is authenticated and got access on a SP, he/she owns all the 
data under his/her account on that server.   This is not the case in an 
enterprise world where data resources are not owned by individual users 
but by the corporation, and data are not arranged or separated by user 
accounts.   That's why a good authorization mechanism on the SP/RP side 
is really critical as an additional line of defense.  In some cases even 
a hacker can gain access to some user accounts, he may not be able to 
gain full access to all the data -- The damage made to Target, J.P. 
Morgen or Sony would be less severe if a solid authorization mechanism 
is implemented...



More information about the users mailing list