Zoom Integration with Shibboleth IdP
Cantor, Scott
cantor.2 at osu.edu
Fri Jan 23 09:22:23 EST 2015
On 1/23/15, 2:06 PM, "Paul Hethmon" <paul.hethmon at clareitysecurity.com>
wrote:
>
>So what’s the attack vector here?
Triggering thousands of RSA operations with simple unauthenticated web
accesses, and in return you basically get nothing. It's harder to
implement anything based on signed requests at the SP compared with just
checking the outcome at the end. The main advantage is at the IdP, to skip
endpoint checks.
It has its uses, but the threat is to the SP and the advantage to the IdP,
and that's not usually a good combination to get acceptance.
-- Scott
>
More information about the users
mailing list