W3C home > Mailing lists > Public > public-wsc-wg@w3.org > December 2006

Re: ACTION-11 SSO & Federated Identity

From: Michael(tm) Smith <mikes@opera.com>
Date: Wed, 6 Dec 2006 21:09:44 +0900
To: public-wsc-wg@w3.org
Message-ID: <20061206120944.GC6892@malware>

Hal Lockhart <hlockhar@bea.com>, 2006-12-04 13:30 -0800:

> Case 0. User establishes TLS session, signs on with username/password
> (usually with form post, sometimes http basic auth) server takes down
> TLS for rest of session. 
> [Should we worry about this case? Although password is protected from
> interception, there is no binding to rest of interaction allowing
> session hijack, interception of app data, etc. User sees lock during
> initial interaction and believes session is "secure."

Do you have any examples of sites that actually do this? (Or can
you create one for testing purposes?) Or can you descibe what
browsers currently do when they encounter this case?


  --Mike
Received on Wednesday, 6 December 2006 12:09:34 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Tuesday, 5 February 2008 03:52:44 GMT