What are the modern methods of user authentication?

I am planning a web service and am a little versed in what are the current methods of securely authenticating users.

Is what Google and Facebook consider standard?

+3
source share
2 answers

Authentication to a "web service" ... Do you mean SOAP / HTTP (S) or a web page? The answers are different in two cases!

  • For SOAP / HTTPS, you are talking using the WS-Security suite with SAML / XACML tokens. Permissions can be obtained in several ways, such as Kerberos or VOMS. This is clearly non-trivial, and you will need to find out what all the other parts are in the “ecosystem” of services, and ensure that you interact with it.
  • - OpenID Shibboleth , . , OpenID , Shibboleth ( , - ).

-, -, , OpenID , . ! ( , , .)


[EDIT]: , , . , , -, , . , HTTPS, , HTTPS, -XSS ( SO!)

+2

, , , , , . .

-, ( ),

  • ssl ( )
  • (lightweigth)

, , , ,

+1

Source: https://habr.com/ru/post/1741616/


All Articles