Zoom Integration with Shibboleth IdP

Cantor, Scott cantor.2 at osu.edu
Fri Jan 23 09:22:23 EST 2015


On 1/23/15, 2:06 PM, "Paul Hethmon" <paul.hethmon at clareitysecurity.com> 
wrote:


>
>So what’s the attack vector here?

Triggering thousands of RSA operations with simple unauthenticated web 
accesses, and in return you basically get nothing. It's harder to 
implement anything based on signed requests at the SP compared with just 
checking the outcome at the end. The main advantage is at the IdP, to skip 
endpoint checks.

It has its uses, but the threat is to the SP and the advantage to the IdP, 
and that's not usually a good combination to get acceptance.

-- Scott

>


More information about the users mailing list