Preference regarding reporting of authentication errors

Cantor, Scott cantor.2 at osu.edu
Tue Oct 11 09:20:28 EDT 2016


> The issue was filed because letting a potential attacker know if the username
> or the password was wrong is generally seen as bad practice.

There are a lot of things generally done that I don't agree with and this is one of them. If you need to keep your usernames secret, you've already lost the war.
 
> Shibboleth as a project generally seems to strive for firstly shipping secure and secondly convenience.

We do, so you can be sure I'm being very honest that I don't view this as a security issue.

>  The filed issue could easily be resolved by defaulting to non-
> explicit errors and having doc (or just commented config) an admin could use
> to turn on the more explicit notifications.

Absolutely true, and I'm willing to go in whichever direction people prefer.
 
-- Scott



More information about the users mailing list