Elektrine lite

← Feed

@vees@jawns.club

Post #4277866

2026-07-30 20:04 UTC

@encthenet@flyovercountry.social As a site owner I'm not going to validate randomauthbox.win just so one or two users can hop on my service. Anything it "attests" to is no more credible than what you write in a form box. What does self-provided SAML SSO provider give you any more than a passkey (hardware or virtual) does?

Replies (1)

  • @vees@jawns.club You aren't trusting a user to [tell you to trust a party to] attest that the user is who they say they are? Are you saying you do a full security review or all the SSO providers (if any) you do trust? Or are you just trusting by their names/how large they are? It actually gives the user control. E.g. passkeys are not 2FA, so with a SAML provider they can do real 2FA which they can't with passkeys. It also lets the user use real 2FA on services that continue to think that an SMS counts as effective 2FA.

    Open ##4277867