Android Application Question

Marc Boorshtein mboorshtein at gmail.com
Wed Jan 4 16:35:30 EST 2017


>
>
>
> Right. And I think that's unacceptable, at least until we have TLS token
> binding or other solutions to elevate security. Which is in fact what
> they're doing, so it bears (sic) noting that even the people producing this
> nonsense know it's nonsense.
>
>
sure.  i didn't say i agreed with it :-)  I'd love to see a solution where
every device has its own unique certificate that is signed by the
manufacturer's CA and stored in crypto hw that you can bind to your account
(did something similar for a customer a few years ago before OIDC was an
option) but thats an entirely different discussion...
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170104/b88dbd8f/attachment.html>


More information about the users mailing list