Burden of Authorization
federator
wpadmin at identiainc.com
Thu Dec 18 18:33:06 EST 2014
Scott, one more comment and I will shut up..
Nick
On 12/18/14 5:02 PM, Cantor, Scott wrote:
> On 12/18/14, 9:43 PM, "federator" <wpadmin at identiainc.com> wrote:
>
>> That's very true because these vendors don't do authorization, and this
>> is why: The hard reality is that 99% of the service provider
>> implementation today is still based on account-based security using
>> Role-based access control.
> It's true that a lot of them have that basic model, and yes, that means
> provisioning and so forth, which is a hassle. Those aren't usually the
> worst problem cases though. The more common case at scale (think Google
> Apps, Box, etc.) is that there is *no* authorization model.
>
> -- Scott
Yes, this is because in a consumer world, no authorization is needed.
When a user is authenticated and got access on a SP, he/she owns all the
data under his/her account on that server. This is not the case in an
enterprise world where data resources are not owned by individual users
but by the corporation, and data are not arranged or separated by user
accounts. That's why a good authorization mechanism on the SP/RP side
is really critical as an additional line of defense. In some cases even
a hacker can gain access to some user accounts, he may not be able to
gain full access to all the data -- The damage made to Target, J.P.
Morgen or Sony would be less severe if a solid authorization mechanism
is implemented...
More information about the users
mailing list