Trying to understand SSO. How is it more secure?

キャンセル
次の結果を表示 
表示  限定  | 次の代わりに検索 
もしかして: 

Trying to understand SSO. How is it more secure?

26件の閲覧回数
ragnar21
Contributor I

I'm struggling to understand this notion of SSO being more secure than enforcing unique passwords and MFA on accounts.

I can't figure out how this isn't going directly against the long held and logical advice of not re-using passwords because it enables credential stuffing.

In our experience, account compromises are almost always the result of a user being phished. The only protection we have against a single account being phished turning into a total user compromise is the fact that the phished password won't work anywhere else. SSO seems to strip away that protection and greatly expand the potential harm of the compromise.

Am I misunderstanding how it works? Are there some baked in protections against shared password credential stuffing that I am not aware of?

0 件の賞賛
返信
1 返信

4件の閲覧回数
Kan_Li
NXP TechSupport
NXP TechSupport

Hi @ragnar21 ,

 

Thank you for raising this question. The topic appears to be related to general SSO/MFA security practices, but before we comment further, could you let us know whether this question is associated with a specific NXP product or solution? If not, we can still discuss the general security concepts and trade-offs of SSO versus separate credentials.
 

Have a great day,
Kan


-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!
- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.
-------------------------------------------------------------------------------

0 件の賞賛
返信