Single sign-on for Internet use had major vulnerabilites: Many now fixed

Online shopping, cloud computing, online CRM systems: Each day many IT systems require the user to identify himself/herself. Single Sign-On (SSO) systems were introduced to circumvent this problem, and to establish structured Identity Management (IDM) systems in industry: Here the user only has to identify once, all subsequent authentications are done automatically. However, SSO systems based on the industry standard SAML have huge vulnerabilities: Roughly 80 percent of these systems could be broken by the researchers.

Read more: Single sign-on for Internet use had major vulnerabilites: Many now fixed

Story added 15. August 2012, content source with full text you can find at link above.