[Ext] RE: Flag to identify if user selected SSO or not
Nate Klingenstein
nate.klingenstein at utah.edu
Tue Jun 7 07:06:21 EDT 2016
Not sure I agree unusable and confusing (IDP discovery) interfaces on
legitimate services is a use-case for pushing for MFA, but YMMV.
This is now a tangent of a tangent, but it’s the major layer of protection we really have as an IdP operator against phished credentials.
Variety in discovery interfaces makes phishing easier if you make the heroic assumption that users can defend themselves to some degree if they know what to expect. That’s all I meant.
I’ll go back to my corner in the shadows now. It’s clear that few agree with me, so I would proceed with Scott’s suggestion.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160607/35b4ba91/attachment.html>
More information about the users
mailing list