2 Factor Iframe Similar To Duo
Cantor, Scott
cantor.2 at osu.edu
Fri Aug 5 14:26:46 EDT 2016
On 8/5/16 2:04 PM, Jon Byers wrote:
> Thanks. All helpful information. Didn't know there was a push to move away
> from SMS as a method of 2-factor.
NIST is deprecating it in their recommendations, to be exact.
> From a cost perspective it seems like the less expensive way over Duo
> or other providers.
Well, it's less secure also, for some definitions of secure. If you
really want to do something like that, I'd personally suggest OATH with
a mobile phone authenticator app. That's even cheaper and doesn't depend
on any messaging or network connectivity to the device.
> I'll checkout SimpleSAMLphp, but we've pretty much fine tunes Shibboleth
> so I'd hate to start over now.
Point is just that Shibboleth means Java, it doesn't make a lot of sense
to extend it with PHP.
What is your time line?
We are collectively looking at the schedule for 3.3, and there's a
pretty strong sense from the team that we want to start pruning scope
back down and getting this shipped. This year certainly.
-- Scott
More information about the users
mailing list