<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Authentication Hub</title><link>http://blogs.msdn.com/alikl/archive/2007/04/11/authentication-hub.aspx</link><description>Windows Authentication Identity Flow Through Physical Tiers Identity Flow Through Physical Tiers - Impersonation Identity Flow Through Physical Tiers - Delegation Identity Flow Through Physical Tiers - Protocol Transition Certificates Different Ways To</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Authentication Hub</title><link>http://blogs.msdn.com/alikl/archive/2007/04/11/authentication-hub.aspx#2093772</link><pubDate>Thu, 12 Apr 2007 04:12:32 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2093772</guid><dc:creator>Anatoly Lubarsky</dc:creator><description>&lt;p&gt;Hi Alik&lt;/p&gt;
&lt;p&gt;Regarding SOA - currently only WSE (imho) gives complete solution because it implements oasis completely.&lt;/p&gt;
&lt;p&gt;The solution mentioned is not complete since it does not protect against replay attacks and http proxy interception and changing message.&lt;/p&gt;</description></item><item><title>re: Authentication Hub</title><link>http://blogs.msdn.com/alikl/archive/2007/04/11/authentication-hub.aspx#2095198</link><pubDate>Thu, 12 Apr 2007 07:02:13 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2095198</guid><dc:creator>alikl</dc:creator><description>&lt;p&gt;Anatoly, good points!&lt;/p&gt;
&lt;p&gt;The goal of &amp;quot;SOA..&amp;quot; post was not to present complete solution rather show Authentication (context 1) in internet scenario (another narrowing context 2)&lt;/p&gt;
&lt;p&gt;Complete solution is too broad statement so use above contexts to narrow.&lt;/p&gt;
&lt;p&gt;Re WSE - today i try to stay away from it since WCF replaces it&lt;/p&gt;
&lt;p&gt;Re replay attacks - Client certs are one of the strongest authentication mechanisms available&lt;/p&gt;
&lt;p&gt;Re proxies and tampering - countermeasure for these would be - input validation.&lt;/p&gt;
&lt;p&gt;imagie that i create proxy inside the WSE pipeline, or remoting pipeline like here&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.microsoft.co.il/blogs/alikl/archive/2006/11/25/App-Architecture-with-Security-in-mind-_2D00_-Video_2C00_-Part-II.aspx"&gt;http://blogs.microsoft.co.il/blogs/alikl/archive/2006/11/25/App-Architecture-with-Security-in-mind-_2D00_-Video_2C00_-Part-II.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;or WCF pipeline like here&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/alikl/archive/2007/03/04/how-to-hack-wcf-new-technology-old-hacking-tricks.aspx"&gt;http://blogs.msdn.com/alikl/archive/2007/03/04/how-to-hack-wcf-new-technology-old-hacking-tricks.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;So no signature would help to counter these but good input validation&lt;/p&gt;
&lt;p&gt;the full story is here &lt;a rel="nofollow" target="_new" href="http://msdn.com/SecurityEngineering"&gt;http://msdn.com/SecurityEngineering&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>.Net Security How To's</title><link>http://blogs.msdn.com/alikl/archive/2007/04/11/authentication-hub.aspx#2338667</link><pubDate>Mon, 30 Apr 2007 15:14:29 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2338667</guid><dc:creator>alik levin's</dc:creator><description>&lt;p&gt;patterns &amp;amp;amp; practices Security How To's Index ASP.NET 2.0 Security Questions and Answers Tamper detection&lt;/p&gt;</description></item><item><title>How I Setup Lab Domain Using VPC 2007</title><link>http://blogs.msdn.com/alikl/archive/2007/04/11/authentication-hub.aspx#2972711</link><pubDate>Tue, 29 May 2007 21:04:17 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2972711</guid><dc:creator>alik levin's</dc:creator><description>&lt;p&gt;To quickly set lab environment I use VPC 2007 ( free download ). It really saves me lots of time. For&lt;/p&gt;</description></item><item><title>Security Educational Workshop - Authentication Explained</title><link>http://blogs.msdn.com/alikl/archive/2007/04/11/authentication-hub.aspx#3011761</link><pubDate>Thu, 31 May 2007 22:08:24 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:3011761</guid><dc:creator>alik levin's</dc:creator><description>&lt;p&gt;I just finished building another security workshop that covers authentication and identity technologies&lt;/p&gt;</description></item><item><title>Web Services Over SSL - Is It Really That Slow Like They Say?</title><link>http://blogs.msdn.com/alikl/archive/2007/04/11/authentication-hub.aspx#4169343</link><pubDate>Wed, 01 Aug 2007 17:35:19 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4169343</guid><dc:creator>alik levin's</dc:creator><description>&lt;p&gt;My answer is &amp;quot;no&amp;quot; . I am working on solution where there is no Windows Active Directory Domain so we&lt;/p&gt;</description></item><item><title>Avoid Manipulating Passwords In Memory - It Is Easy To Reveal</title><link>http://blogs.msdn.com/alikl/archive/2007/04/11/authentication-hub.aspx#6701114</link><pubDate>Sat, 08 Dec 2007 08:55:44 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:6701114</guid><dc:creator>alik levin's</dc:creator><description>&lt;p&gt;Revealing clear text passwords in memory seems to be a trivial task. This post describes how to reveal&lt;/p&gt;
</description></item><item><title>Avoid Manipulating Passwords In Memory - It Is Easy To Reveal</title><link>http://blogs.msdn.com/alikl/archive/2007/04/11/authentication-hub.aspx#6701519</link><pubDate>Sat, 08 Dec 2007 09:45:44 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:6701519</guid><dc:creator>Noticias externas</dc:creator><description>&lt;p&gt;Revealing clear text passwords in memory seems to be a trivial task. This post describes how to reveal&lt;/p&gt;
</description></item></channel></rss>