Question about Shibboleth and MFA - Google Authenticator

Tom Scavo trscavo at gmail.com
Sat Feb 16 08:10:24 EST 2019


On Fri, Feb 15, 2019 at 12:49 PM Cantor, Scott <cantor.2 at osu.edu> wrote:
>
> > Out of curiosity, are members asking about W3C WebAuthn? [1] That's where
> > the authentication space seems to be headed at the moment.
>
> No, for the same reason. WebAuthn is only usable once you register the token (the browser in this case) and have a lifecycle management story for listing them, revoking them, reporting on them, etc. That's the step that's missing from "just implement X". It's no different than any other certificate-like model. The hard work is the same no matter what the technology is.

Indeed. If you have to do the hard work in either case, it would be
better to take one step forward (WebAuthn) instead of one step back
(OTP). Just my two cents.

Tom


More information about the users mailing list