assurance - RE: [Assurance] Bronze password reset
Subject: Assurance
List archive
- From: "Michael W. Brogan" <>
- To: "" <>
- Subject: RE: [Assurance] Bronze password reset
- Date: Fri, 9 Jan 2015 23:57:18 +0000
- Accept-language: en-US
- Authentication-results: spf=none (sender IP is ) ;
Section 3.1 of the IAP says: “The InCommon Bronze identity assurance profile focuses on sequential identity, that is, reasonable assurance that the same person is authenticating each time with a particular Credential. Assertions under this profile are likely to represent the same Subject each time a Subject identifier is provided.” With the hypothetical web page password reset scenario described by Eric, I’m not sure how an institution would provide “reasonable assurance that the same person is authenticating each time with a particular
Credential.” --Michael From: [mailto:]
On Behalf Of Eric Goodman
So I could create a website that takes an account name and let's you reset the password for that account interactively, with no identity proofing whatsoever, and I can still assert the Bronze IAQ for that account. (At least, if I blank
out any PII I have from the original account registration). In the best case, your reading implies that there's a huge, unfortunate editing error in the iap language. If the intent of the IAP was really to have no requirements beyond registration record PII protection, then I'm going to go join
Mark in his rathole (see the original thread on participants for the reference there) because there's no longer even an amorphous "reasonable care" requirement in play.
--- Eric |
- [Assurance] Bronze password reset, Eric Goodman, 01/08/2015
- Re: [Assurance] Bronze password reset, David Walker, 01/09/2015
- Re: [Assurance] Bronze password reset, Eric Goodman, 01/09/2015
- RE: [Assurance] Bronze password reset, Michael W. Brogan, 01/10/2015
- RE: [Assurance] Bronze password reset, Capehart,Jeffrey D, 01/12/2015
- RE: [Assurance] Bronze password reset, Cantor, Scott, 01/12/2015
- Re: [Assurance] Bronze password reset, David Walker, 01/12/2015
- RE: [Assurance] Bronze password reset, Jones, Mark B, 01/12/2015
- RE: [Assurance] Bronze password reset, Cantor, Scott, 01/12/2015
- Re: [Assurance] Bronze password reset, David Walker, 01/12/2015
- RE: [Assurance] Bronze password reset, Jones, Mark B, 01/13/2015
- Re: [Assurance] Bronze password reset, David Walker, 01/13/2015
- Re: [Assurance] Bronze password reset, David Walker, 01/12/2015
- RE: [Assurance] Bronze password reset, Cantor, Scott, 01/12/2015
- RE: [Assurance] Bronze password reset, Capehart,Jeffrey D, 01/12/2015
- RE: [Assurance] Bronze password reset, Eric Goodman, 01/13/2015
- RE: [Assurance] Bronze password reset, Michael W. Brogan, 01/10/2015
- Re: [Assurance] Bronze password reset, Eric Goodman, 01/09/2015
- Re: [Assurance] Bronze password reset, David Walker, 01/09/2015
Archive powered by MHonArc 2.6.16.