@GergelyOrosz@AdamVoulstaker Check https://t.co/S9ksXUj504 or https://t.co/taVllam4N4 the leaders in identity verification. Their marketing material doesn’t include your use case but it would work OOTB IMO.
@doerkadrian 1. Everything is relative, if that's all a computer system has on you, that’s your digital id from its perspective
2. In an era of deep fakes and malware, users might never fully control their digital id, even with biometrics or SSI wallet keys.
@Sarah_Cecc I'd say it depends, an account with a strong and unique password is safer without SMS MFA (an attacker can not as easily compromise it). If SMS MFA is enabled, it doesn't matter how strong the password is, the phone/SIM is the weakest link.
@gepeto42 Cybersecurity is a long word to say, but cyber is such a meaningless shorter version. Hopefully it won't become as prevalent as the equally meaningless short version of "Agile Software Development"
@EmLindley I don't see the novelty of this attack. Signature forgery has been part of the SAML threat model since it was born. Own the Idp key = Own the SPs