Default style (Cherry Eve). Switch styles (Capricorn). Atom Feed Calendar
http://blogs.sun.com/hubertsblog/date/20051208 Thursday December 08, 2005

Liberty is for real!

I usually don't stare at URLs when browsing the Internet especially if I'm doing online banking but yesterday I was paying some bills online when my eye caught something on the URL that pleased me. Look at the URL below (DON'T click on it - I modified the URL – you never know ;-) ) :

https://paymybill.wellsfargo.com/mn2_gw3_bp/billpay/application/Signon?pg=1&SAMLart=AADFwiu12qyeHqsrGO7ol4JWTTeWAh103PWjAZ2DOjA0&sessionId=12341blablaetc----&st=123456789

Not seeing anything?

Alright, below I highlighted (in red) the “interested “ aspect of this URL:

https://paymybill.wellsfargo.com/mn2_gw3_bp/billpay/application/Signon?pg=1&SAMLart=AADFwiu12qyeHqsrGO7ol4JWTTeWAh103PWjAZ2DOjA0&sessionId=12341blablaetc----&st=123456789

Hey!! Yes this is a SAML artifact that's being used for single sign-on – right there!

Actually Wells Fargo is a Sun customer for our Liberty-based Access Manager (see http://www.sun.com/software/products/access_mgr/ds_access_mgr.pdf for more info) so it's not a surprise but I think it is great to see real world deployment of the Liberty specifications (http://www.projectliberty.org). When one think of the importance of privacy and security for banks I think it is a great testimony to Liberty's work!



www.flickr.com
hubert_levangong's photos More of hubert_levangong's photos

View My Stats