2 Factor Iframe Similar To Duo

Keith Hazelton keith.hazelton at wisc.edu
Fri Aug 5 14:29:09 EDT 2016


Does U2F offer a pathway?    --Keith
______________________

On 2016-08-05, 13:26 , "users on behalf of Cantor, Scott" <users-bounces at shibboleth.net on behalf of cantor.2 at osu.edu> wrote:

    On 8/5/16 2:04 PM, Jon Byers wrote:
    > Thanks.  All helpful information.  Didn't know there was a push to move away
    > from SMS as a method of 2-factor.
    
    NIST is deprecating it in their recommendations, to be exact.
    
    > From a cost perspective it seems like the less expensive way over Duo
    > or other providers.
    
    Well, it's less secure also, for some definitions of secure. If you
    really want to do something like that, I'd personally suggest OATH with
    a mobile phone authenticator app. That's even cheaper and doesn't depend
    on any messaging or network connectivity to the device.
    
    > I'll checkout SimpleSAMLphp, but we've pretty much fine tunes Shibboleth
    > so I'd hate to start over now.
    
    Point is just that Shibboleth means Java, it doesn't make a lot of sense
    to extend it with PHP.
    
    What is your time line?
    
    We are collectively looking at the schedule for 3.3, and there's a
    pretty strong sense from the team that we want to start pruning scope
    back down and getting this shipped. This year certainly.
    
    -- Scott
    -- 
    To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
    



More information about the users mailing list