fanf: (Default)
[personal profile] fanf
This message contains a good rant about single sign-on:

The fact that "users don't necessarily want to have to manually authenticate each time some service wants authentication" is not the reason we want to promote single sign-on. We don't want the user to manually authenticate every time because doing so trains the user to supply their credentials so frequently that they will not think it is strange when they are asked to provide them to an attacker. The only way to prevent phishing attacks are by training users that they only authenticate in very small number of circumstances that rarely occur.

Date: 2006-04-12 02:01 (UTC)
From: [identity profile] trhodes.livejournal.com
Wow, that is a very interesting view point. And I understand that, in some ways. Less informed users, yes, more informed users, na. Yet, you can't just single group everyone. ;)

--
Tom Rhodes

Date: 2006-04-13 08:45 (UTC)
From: [identity profile] trhodes.livejournal.com
Interesting. Are there no other services but Kerberos which could provide for things like authentication tokens, etc?

--
Tom Rhodes

January 2026

S M T W T F S
    123
45678910
1112 13 14151617
18192021222324
25262728293031

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated 2026-01-25 10:23
Powered by Dreamwidth Studios