WebApp Sec mailing list archives
Re: OpenID and the web
From: baldr <baldr.theinnocent () gmail com>
Date: Thu, 27 Mar 2008 22:29:59 +0000
Pete Jansson Thu, Mar 27, 2008 at 5:01 PM
Additionally, there would be nothing to prevent a user from having multiple OpenIDs. OpenID providers should have different levels of service with different authentication strengths -- from username/password to tokens, or whatever. Then the user can use their choice of OpenID with a particular account, making the choice based on the strength of authentication vs. the risk of the account. (I'm not sure if I really care whether someone gets my Slashdot comment account, but I would care about them having my Amazon One-Click account [if I weren't too paranoid to One-Click].)
I completly agree here openID as a protocol can support varying levels of security including security tokens & pki. currently most implmentations are for services where as said above people dont really care. we accept that these services are not as secure as our bank. personly i think openID is perfect for the use it provides. with a password system it isn't that secure, its online and gives access to many accounts; however they are all accounts you dont care about. if it where a SSO for my banks i would expect to be using a certificate but this wouldn't exclude openID. Well thats my two pence... As where on the subject i was curious what people thought about shibboleth. about 15 countries have adopted it for either education or health* as an SSO to many online journals. what do people feel are the security pros/cons here *https://spaces.internet2.edu/display/SHIB/ShibbolethFederations ------------------------------------------------------------------------- Sponsored by: Watchfire Methodologies & Tools for Web Application Security Assessment With the rapid rise in the number and types of security threats, web application security assessments should be considered a crucial phase in the development of any web application. What methodology should be followed? What tools can accelerate the assessment process? Download this Whitepaper today! https://www.watchfire.com/securearea/whitepapers.aspx?id=70170000000940F -------------------------------------------------------------------------
Current thread:
- Re: OpenID and the web, (continued)
- Re: OpenID and the web Babu.N (Mar 26)
- Re: OpenID and the web Razi Shaban (Mar 27)
- Re: OpenID and the web Jeff Robertson (Mar 27)
- RE: OpenID and the web Calderon, Juan Carlos (GE, Corporate, consultant) (Mar 27)
- Re: OpenID and the web Lucas Oman (Mar 27)
- Re: OpenID and the web Razi Shaban (Mar 27)
- Re: OpenID and the web Babu.N (Mar 26)
- Re: OpenID and the web David Wall (Mar 27)
- Re: OpenID and the web Jeremiah Cornelius (Mar 27)
- RE: OpenID and the web Chris Grove (Mar 28)
- Re: OpenID and the web baldr (Mar 27)