Boston Linux & Unix (BLU) Home | Calendar | Mail Lists | List Archives | Desktop SIG | Hardware Hacking SIG
Wiki | Flickr | PicasaWeb | Video | Maps & Directions | Installfests | Keysignings
Linux Cafe | Meeting Notes | Blog | Linux Links | Bling | About BLU

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] single sign-on



Kent Borg wrote:
> That is why my hypothetical bad guy was hoping Lastpass becomes very
> common, then it will become fertile ground for theft.

Yep. The biggest flaw with federated identity is identical to the 
biggest flaw with SSL. It's entirely dependent on the security of the 
provider. We already know how easy it is to compromise SSL certificate 
authorities. Why should anyone expect federated identity providers to be 
at all different? Because they promise to be better?

-- 
Rich P.



BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org