Reducing the number of re-authentications
Cantor, Scott
cantor.2 at osu.edu
Thu Mar 7 21:12:43 EST 2019
> Does the Shibboleth IdP support some kind of filter or predicate for that check?
For the whole session it's a property, on/off. Every login flow has a more fine grained condition property for controlling reuse at a programmable level.
Either address controls are effective and hard to circumvent or they aren't. I have heard both sides. If they're so weak that they don't matter then we have all sorts of server-side controls and policies that amount to nothing and have a lot of problems. I suspect they're more effective than that, in which case it's a real reduction in security to do this given the weak security of browsers.
Token binding was supposed to fix this and then Google all but killed it.
-- Scott
More information about the users
mailing list