Preference regarding reporting of authentication errors
Cantor, Scott
cantor.2 at osu.edu
Tue Oct 11 09:20:28 EDT 2016
> The issue was filed because letting a potential attacker know if the username
> or the password was wrong is generally seen as bad practice.
There are a lot of things generally done that I don't agree with and this is one of them. If you need to keep your usernames secret, you've already lost the war.
> Shibboleth as a project generally seems to strive for firstly shipping secure and secondly convenience.
We do, so you can be sure I'm being very honest that I don't view this as a security issue.
> The filed issue could easily be resolved by defaulting to non-
> explicit errors and having doc (or just commented config) an admin could use
> to turn on the more explicit notifications.
Absolutely true, and I'm willing to go in whichever direction people prefer.
-- Scott
More information about the users
mailing list