The problem with IDP initiated SSO

Cantor, Scott cantor.2 at osu.edu
Tue Dec 23 09:55:37 EST 2014


On 12/23/14, 1:25 PM, "Tom Scavo" <trscavo at gmail.com> wrote:
>>
>> It's also a XSRF attack by definition.
>
>Wouldn't user consent effectively thwart that issue?

Not in the way that the attack would normally work here. What's unusual 
about this kind of XSRF attack is that it involves a user giving a valid 
response to a *different* user. That is, I log in via a request from my 
banking service and give your client the response so that you're logged 
into my bank, but you think you're logged into yours.

-- Scott



More information about the users mailing list