The problem with IDP initiated SSO
Cantor, Scott
cantor.2 at osu.edu
Tue Dec 23 09:55:37 EST 2014
On 12/23/14, 1:25 PM, "Tom Scavo" <trscavo at gmail.com> wrote:
>>
>> It's also a XSRF attack by definition.
>
>Wouldn't user consent effectively thwart that issue?
Not in the way that the attack would normally work here. What's unusual
about this kind of XSRF attack is that it involves a user giving a valid
response to a *different* user. That is, I log in via a request from my
banking service and give your client the response so that you're logged
into my bank, but you think you're logged into yours.
-- Scott
More information about the users
mailing list