2 Factor Iframe Similar To Duo
Keith Hazelton
keith.hazelton at wisc.edu
Fri Aug 5 14:29:09 EDT 2016
Does U2F offer a pathway? --Keith
______________________
On 2016-08-05, 13:26 , "users on behalf of Cantor, Scott" <users-bounces at shibboleth.net on behalf of cantor.2 at osu.edu> wrote:
On 8/5/16 2:04 PM, Jon Byers wrote:
> Thanks. All helpful information. Didn't know there was a push to move away
> from SMS as a method of 2-factor.
NIST is deprecating it in their recommendations, to be exact.
> From a cost perspective it seems like the less expensive way over Duo
> or other providers.
Well, it's less secure also, for some definitions of secure. If you
really want to do something like that, I'd personally suggest OATH with
a mobile phone authenticator app. That's even cheaper and doesn't depend
on any messaging or network connectivity to the device.
> I'll checkout SimpleSAMLphp, but we've pretty much fine tunes Shibboleth
> so I'd hate to start over now.
Point is just that Shibboleth means Java, it doesn't make a lot of sense
to extend it with PHP.
What is your time line?
We are collectively looking at the schedule for 3.3, and there's a
pretty strong sense from the team that we want to start pruning scope
back down and getting this shipped. This year certainly.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list