SSO is a good concept BUT the implementation is fundamentally flawed that’s why it is not secure. Fortunately, that is very easy to fix and the solution on how to fix it it available now.
The access authentication should prove the identity of the human person, not the device they possess. If you do this we can stop bot attacks and access breaches.
The SINGULAR issue about access management is that AM never took into consideration to prove the identity of the user. All they were able to prove was the initial assertion of the user attempting to access. So AM is actually of no use, even dangerous unless the identity of…
Experience
Other Skills
Thanks
Answers
Almost 6 years ago
Identity and Access Management as a Service (IDaaS) (IAMaaS)