[External] jetty

Cantor, Scott cantor.2 at osu.edu
Thu Mar 18 17:38:29 UTC 2021


On 3/18/21, 1:22 PM, "users on behalf of Matthew Slowe via users" <users-bounces at shibboleth.net on behalf of users at shibboleth.net> wrote:

>    On the other hand, do you want to actively make security-related compromises for legacy (read as
> "unsupported" or "unsupportable") clients? If the device is only capable of using protocols/ciphers etc that can
> be compromised then do you want them exchanging (high-value?) credentials with your authentication
> services over the big-bad-internet?

It helps that we increasingly don't really consider passwords high value. ;-)

We handed them over to Microsoft, so if anybody seriously tried to argue the point, I'd be right, though politically couldn't win the argument.

-- Scott




More information about the users mailing list