fanf: (Default)
[personal profile] fanf
This message contains a good rant about single sign-on:

The fact that "users don't necessarily want to have to manually authenticate each time some service wants authentication" is not the reason we want to promote single sign-on. We don't want the user to manually authenticate every time because doing so trains the user to supply their credentials so frequently that they will not think it is strange when they are asked to provide them to an attacker. The only way to prevent phishing attacks are by training users that they only authenticate in very small number of circumstances that rarely occur.

Date: 2006-04-13 08:45 (UTC)
From: [identity profile] trhodes.livejournal.com
Interesting. Are there no other services but Kerberos which could provide for things like authentication tokens, etc?

--
Tom Rhodes

December 2025

S M T W T F S
 123456
78910111213
14151617181920
21222324 252627
28293031   

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated 2025-12-31 21:49
Powered by Dreamwidth Studios