websecurity@lists.webappsec.org

The Web Security Mailing List

View all threads

Re: [WEB SECURITY] Social login / federated identity

MO
Martin O'Neal
Fri, Feb 22, 2013 11:52 PM

I wouldn't expect a bank to use OAuth
to secure their services but WS-Federation
definitely could.

This isn't a technology issue though, it is one of theology.

Handing off your authentication credentials to a third-party is a great
idea until the third-party is compromised.

Martin...

> I wouldn't expect a bank to use OAuth > to secure their services but WS-Federation > definitely could. This isn't a technology issue though, it is one of theology. Handing off your authentication credentials to a third-party is a great idea until the third-party is compromised. Martin...