[Ext] RE: Flag to identify if user selected SSO or not

Nate Klingenstein nate.klingenstein at utah.edu
Tue Jun 7 07:06:21 EDT 2016


Not sure I agree unusable and confusing (IDP discovery) interfaces on
legitimate services is a use-case for pushing for MFA, but YMMV.

This is now a tangent of a tangent, but it’s the major layer of protection we really have as an IdP operator against phished credentials.

Variety in discovery interfaces makes phishing easier if you make the heroic assumption that users can defend themselves to some degree if they know what to expect.  That’s all I meant.

I’ll go back to my corner in the shadows now.  It’s clear that few agree with me, so I would proceed with Scott’s suggestion.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160607/35b4ba91/attachment.html>


More information about the users mailing list