Post #4277868
2026-07-30 23:17 UTC
@encthenet@flyovercountry.social In most cases you are trusting the SSO to give you a unique identifier that you can leverage AND you're trusting the provider's security mechanisms as an extension of yours for account takeover. IDP size isn't *terrible* as a proxy of deciding if they're secure. I guess there's a world where you just check /.well-known/jwks.json and log your user's auth creds as iss+sub for subsequent logins if that's what they want, but then you'll have/need some secondary cred reset path anyway.
Replies (0)
No replies.