SlideShare a Scribd company logo
1 of 25
Download to read offline
Federated Authentication
Browser changes and what to expect
Jason Griffey
Director of Strategic Initiatives, NISO
Amanda Ferrante
Principal Product Manager, Identity & Access Management, EBSCO
[ 2 ]
Topics for Today
Problem
Statement
About Tracking Timing and
Browser
Development
Activities
Next Steps
[ 3 ]
Non-transparent, uncontrollable tracking
of users across the web needs to be
addressed and prevented.
Problem Statement for the Web
[ 4 ]
Libraries and Publishing is Important But
The experience and
lead driver of the
browser vendors is in
the consumer web.
[ 5 ]
Regulation Trumps Standardization
Browser vendors are
being held
accountable for
tracking.
They will implement
tech that breaks
things in order to
avoid legal action.
LEARNING ABOUT TRACKING
[ 7 ]
Browsers vs Browser Engines
• Browsers = Chrome, Firefox, Safari, Edge, Brave
• Browser engines = Blink (aka, Chromium), Gecko, WebKit
• Functionality is based on the browser engine more than the
browser
• ALL browsers on iOS and iPadOS are actually built on WebKit;
WebKit does not support third-party cookies
• Edge and Chrome are built on Blink; they will show much the
same behaviors when it comes to features
This matters when you start troubleshooting why someone can’t get to a website or service
[ 8 ]
How Does Tracking Happen
Third-Party
Cookies
IP Addresses Browser
Fingerprinting
Link
Decoration
Bounce
Tracking
[ 9 ]
HTTP cookies (also called web cookies, Internet cookies, browser
cookies, or simply cookies) are small blocks of data created by a
web server while a user is browsing a website and placed on the
user's computer or other device by the user’s web browser.
• First-Party Cookies
• Accessible only by the domain that created it
• Third-Party Cookies
• Accessible to any site at any domain
Cookies
[ 10 ]
IP Addresses
Used to identify machines and/or services
• Tracking mitigations for Browser Fingerprinting often impact IP address
information
• Often used to make authorization decisions in:
• Libraries
• Enterprise Resource Planning (ERP) systems
[ 11 ]
Browser Fingerprinting
Information collected about the software and hardware of a remote
computing device for the purpose of identification
Includes capture of information such as
• Browser used
• Fonts used
• Add-ons used
• Browser security configuration
• IP address
• …
[ 12 ]
Link Decoration
A method of adding extra information to the URL. Also known
as “navigation-based tracking”
Used for:
• Query strings
• Some authentication tokens (i.e., “Front-channel”)
• Tracking information
https://2023alaannual.eventscribe.net/myplan.asp?mode=sessions&afp=MkMxM
Tc3MTo2MTUyNjc2MDpNc1N1SDVYYg
[ 13 ]
Bounce Tracking
Used by trackers to get around third-party limitations, also
known as redirect tracking
● Website A sends the browser to the tracker to get a
first-party cookie.
○ The tracker then sends the browser on to the user's
destination with additional information stored in the
browser that will allow the tracker to ’follow’ the user
around the web.
● The end-user does not see this transition; they only see
Website A and then the destination page.
[ 14 ]
Many applications and services need
to work through the browser to
support SSO/federated login (and
other library services), and yet these
and tracking tools use the same
features and are indistinguishable from
the browser’s perspective.
[ 15 ]
Sites use features like cookies for more than
just authentication and authorization
• Storing user preferences
• Session information across frames
• Demographic info for targeted advertising / content
It’s About More Than Just Authentication
THINGS TO KNOW
[ 17 ]
Implications to Remember
• Authentication that uses SAML will continue to work as designed for at
least the next 1-3 years.
• (except, the ability to globally log out of all SAML sessions)
• WAYF IdP Discovery services will continue to work.
• (previous organizations will likely be forgotten (e.g.,
SeamlessAcccess).
• Services that share information between third-parties in frames (e.g.,
Teams, ILS/LMS) will have mixed results.
• Other features that enable tracking (IP addresses, browser fingerprinting)
are already breaking, depending on which browser is being used.
• WAYFless linking (link decoration) may be affected depending on
implementation.
[ 18 ]
Timelines
• Apple’s timeline:
• n/a (Apple started blocking third-party cookies by default in 2017
as part of Intelligent Tracking Protection)
• With Safari 17, they are also removing known link decoration
trackers in Private Browsing Mode.
• Mozilla’s timeline:
• n/a (Mozilla also blocks third-party cookies by default as of June
2022 with Total Cookie Protection)
• Google’s timeline:
• https://privacysandbox.com/timeline
• “As developers adopt these APIs, we now intend to begin phasing
out third-party cookies in Chrome in the second half of 2024.”
Safari Private Browsing
[ 20 ]
What is happening Right Now?
• Seamless Access developers are meeting regularly with
browser vendors
○ Other library vendors are in that group as well
• Discussions w/ Mozilla, Google re: creating a test environment
• Discussions with FedID CG, FIDO Alliance, others on forming a
W3C Working Group to standardize FedCM
[ 21 ]
Want to Learn More?
To be a part of developing the solution (or at least lurk and learn)
• Federated Identity Community Group
• https://www.w3.org/community/fed-id/
• Private Advertising Technology Community Group
• https://www.w3.org/community/patcg/
• REFEDS Browser Changes and Federation WG
• https://wiki.refeds.org/display/GROUPS/Browser+Changes+
and+Federation
[ 22 ]
Q&A
AI & Machine Learning in Scholarly
Publishing: Services, Data, and Ethics
October 3, 2023
Washington, DC
IN PERSON
Week of February 12, 2024
Baltimore, MD
http://niso.plus
Link to these slides

More Related Content

Similar to Ferrante and Griffey "Federated Authentication_ Browser changes and what to expect"

Design Summit - User stories from the field - Chris Jung
Design Summit - User stories from the field - Chris JungDesign Summit - User stories from the field - Chris Jung
Design Summit - User stories from the field - Chris JungManageIQ
 
Customized Browser Displaying Multiple Sessions in a Carousel View
Customized Browser Displaying Multiple Sessions in a Carousel ViewCustomized Browser Displaying Multiple Sessions in a Carousel View
Customized Browser Displaying Multiple Sessions in a Carousel ViewMike Taylor
 
Chrome Extensions: Masking risks in entertainment
Chrome Extensions: Masking risks in entertainmentChrome Extensions: Masking risks in entertainment
Chrome Extensions: Masking risks in entertainmentEduardo Chavarro
 
19BCP072_Presentation_Final.pdf
19BCP072_Presentation_Final.pdf19BCP072_Presentation_Final.pdf
19BCP072_Presentation_Final.pdfKunjJoshi14
 
Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...OpenAthens
 
Experimental Analysis of Web Browser Sessions Using Live Forensics Method
Experimental Analysis of Web Browser Sessions Using Live Forensics Method Experimental Analysis of Web Browser Sessions Using Live Forensics Method
Experimental Analysis of Web Browser Sessions Using Live Forensics Method IJECEIAES
 
Sitecore 9 - What's new?
Sitecore 9 - What's new?Sitecore 9 - What's new?
Sitecore 9 - What's new?Adrian IORGU
 
Developing Secure Web Apps
Developing Secure Web AppsDeveloping Secure Web Apps
Developing Secure Web AppsMark Garratt
 
E Commerce Analytics Demandware
E Commerce Analytics DemandwareE Commerce Analytics Demandware
E Commerce Analytics Demandwareloripelletier
 
Browser Security – Issues and Best Practices1Outli
Browser Security – Issues and Best Practices1OutliBrowser Security – Issues and Best Practices1Outli
Browser Security – Issues and Best Practices1OutliVannaSchrader3
 
A Brave New World
A Brave New WorldA Brave New World
A Brave New WorldSensePost
 
A security note for web developers
A security note for web developersA security note for web developers
A security note for web developersJohn Ombagi
 
DFS____________________Presentation.pptx
DFS____________________Presentation.pptxDFS____________________Presentation.pptx
DFS____________________Presentation.pptxOnlyLogin
 

Similar to Ferrante and Griffey "Federated Authentication_ Browser changes and what to expect" (20)

Design Summit - User stories from the field - Chris Jung
Design Summit - User stories from the field - Chris JungDesign Summit - User stories from the field - Chris Jung
Design Summit - User stories from the field - Chris Jung
 
Customized Browser Displaying Multiple Sessions in a Carousel View
Customized Browser Displaying Multiple Sessions in a Carousel ViewCustomized Browser Displaying Multiple Sessions in a Carousel View
Customized Browser Displaying Multiple Sessions in a Carousel View
 
Privacy in private browsing mode
Privacy in private browsing modePrivacy in private browsing mode
Privacy in private browsing mode
 
What is web scraping?
What is web scraping?What is web scraping?
What is web scraping?
 
Web analytics & Online privacy
Web analytics & Online privacyWeb analytics & Online privacy
Web analytics & Online privacy
 
Maths
MathsMaths
Maths
 
Chrome Extensions: Masking risks in entertainment
Chrome Extensions: Masking risks in entertainmentChrome Extensions: Masking risks in entertainment
Chrome Extensions: Masking risks in entertainment
 
19BCP072_Presentation_Final.pdf
19BCP072_Presentation_Final.pdf19BCP072_Presentation_Final.pdf
19BCP072_Presentation_Final.pdf
 
Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...Access interrupted? How changes in browser technology may impact researchers'...
Access interrupted? How changes in browser technology may impact researchers'...
 
Experimental Analysis of Web Browser Sessions Using Live Forensics Method
Experimental Analysis of Web Browser Sessions Using Live Forensics Method Experimental Analysis of Web Browser Sessions Using Live Forensics Method
Experimental Analysis of Web Browser Sessions Using Live Forensics Method
 
Sitecore 9 - What's new?
Sitecore 9 - What's new?Sitecore 9 - What's new?
Sitecore 9 - What's new?
 
Developing Secure Web Apps
Developing Secure Web AppsDeveloping Secure Web Apps
Developing Secure Web Apps
 
E Commerce Analytics Demandware
E Commerce Analytics DemandwareE Commerce Analytics Demandware
E Commerce Analytics Demandware
 
Seguridad Corporativa Con Internet Explorer 8(1)
Seguridad Corporativa Con Internet Explorer 8(1)Seguridad Corporativa Con Internet Explorer 8(1)
Seguridad Corporativa Con Internet Explorer 8(1)
 
Browser Security – Issues and Best Practices1Outli
Browser Security – Issues and Best Practices1OutliBrowser Security – Issues and Best Practices1Outli
Browser Security – Issues and Best Practices1Outli
 
A Brave New World
A Brave New WorldA Brave New World
A Brave New World
 
A security note for web developers
A security note for web developersA security note for web developers
A security note for web developers
 
iot_basic_1.pptx
iot_basic_1.pptxiot_basic_1.pptx
iot_basic_1.pptx
 
Ch21 system administration
Ch21 system administration Ch21 system administration
Ch21 system administration
 
DFS____________________Presentation.pptx
DFS____________________Presentation.pptxDFS____________________Presentation.pptx
DFS____________________Presentation.pptx
 

More from National Information Standards Organization (NISO)

More from National Information Standards Organization (NISO) (20)

Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
 
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
 
Bazargan "NISO Webinar, Sustainability in Publishing"
Bazargan "NISO Webinar, Sustainability in Publishing"Bazargan "NISO Webinar, Sustainability in Publishing"
Bazargan "NISO Webinar, Sustainability in Publishing"
 
Rapple "Scholarly Communications and the Sustainable Development Goals"
Rapple "Scholarly Communications and the Sustainable Development Goals"Rapple "Scholarly Communications and the Sustainable Development Goals"
Rapple "Scholarly Communications and the Sustainable Development Goals"
 
Compton "NISO Webinar, Sustainability in Publishing"
Compton "NISO Webinar, Sustainability in Publishing"Compton "NISO Webinar, Sustainability in Publishing"
Compton "NISO Webinar, Sustainability in Publishing"
 
Mattingly "AI & Prompt Design: Large Language Models"
Mattingly "AI & Prompt Design: Large Language Models"Mattingly "AI & Prompt Design: Large Language Models"
Mattingly "AI & Prompt Design: Large Language Models"
 
Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...
Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...
Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...
 
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
 
Mattingly "Text and Data Mining: Building Data Driven Applications"
Mattingly "Text and Data Mining: Building Data Driven Applications"Mattingly "Text and Data Mining: Building Data Driven Applications"
Mattingly "Text and Data Mining: Building Data Driven Applications"
 
Mattingly "Text and Data Mining: Searching Vectors"
Mattingly "Text and Data Mining: Searching Vectors"Mattingly "Text and Data Mining: Searching Vectors"
Mattingly "Text and Data Mining: Searching Vectors"
 
Mattingly "Text Mining Techniques"
Mattingly "Text Mining Techniques"Mattingly "Text Mining Techniques"
Mattingly "Text Mining Techniques"
 
Mattingly "Text Processing for Library Data: Representing Text as Data"
Mattingly "Text Processing for Library Data: Representing Text as Data"Mattingly "Text Processing for Library Data: Representing Text as Data"
Mattingly "Text Processing for Library Data: Representing Text as Data"
 
Carpenter "Designing NISO's New Strategic Plan: 2023-2026"
Carpenter "Designing NISO's New Strategic Plan: 2023-2026"Carpenter "Designing NISO's New Strategic Plan: 2023-2026"
Carpenter "Designing NISO's New Strategic Plan: 2023-2026"
 
Ross and Clark "Strategic Planning"
Ross and Clark "Strategic Planning"Ross and Clark "Strategic Planning"
Ross and Clark "Strategic Planning"
 
Mattingly "Data Mining Techniques: Classification and Clustering"
Mattingly "Data Mining Techniques: Classification and Clustering"Mattingly "Data Mining Techniques: Classification and Clustering"
Mattingly "Data Mining Techniques: Classification and Clustering"
 
Straza "Global collaboration towards equitable and open science: UNESCO Recom...
Straza "Global collaboration towards equitable and open science: UNESCO Recom...Straza "Global collaboration towards equitable and open science: UNESCO Recom...
Straza "Global collaboration towards equitable and open science: UNESCO Recom...
 
Lippincott "Beyond access: Accelerating discovery and increasing trust throug...
Lippincott "Beyond access: Accelerating discovery and increasing trust throug...Lippincott "Beyond access: Accelerating discovery and increasing trust throug...
Lippincott "Beyond access: Accelerating discovery and increasing trust throug...
 
Kriegsman "Integrating Open and Equitable Research into Open Science"
Kriegsman "Integrating Open and Equitable Research into Open Science"Kriegsman "Integrating Open and Equitable Research into Open Science"
Kriegsman "Integrating Open and Equitable Research into Open Science"
 
Mattingly "Ethics and Cleaning Data"
Mattingly "Ethics and Cleaning Data"Mattingly "Ethics and Cleaning Data"
Mattingly "Ethics and Cleaning Data"
 
Mercado-Lara "Open & Equitable Program"
Mercado-Lara "Open & Equitable Program"Mercado-Lara "Open & Equitable Program"
Mercado-Lara "Open & Equitable Program"
 

Recently uploaded

mini mental status format.docx
mini    mental       status     format.docxmini    mental       status     format.docx
mini mental status format.docxPoojaSen20
 
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdfssuser54595a
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeThiyagu K
 
Student login on Anyboli platform.helpin
Student login on Anyboli platform.helpinStudent login on Anyboli platform.helpin
Student login on Anyboli platform.helpinRaunakKeshri1
 
Z Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot GraphZ Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot GraphThiyagu K
 
Activity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfActivity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfciinovamais
 
Web & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfWeb & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfJayanti Pande
 
Separation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and ActinidesSeparation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and ActinidesFatimaKhan178732
 
Accessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactAccessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactdawncurless
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Educationpboyjonauth
 
How to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptxHow to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptxmanuelaromero2013
 
Nutritional Needs Presentation - HLTH 104
Nutritional Needs Presentation - HLTH 104Nutritional Needs Presentation - HLTH 104
Nutritional Needs Presentation - HLTH 104misteraugie
 
Privatization and Disinvestment - Meaning, Objectives, Advantages and Disadva...
Privatization and Disinvestment - Meaning, Objectives, Advantages and Disadva...Privatization and Disinvestment - Meaning, Objectives, Advantages and Disadva...
Privatization and Disinvestment - Meaning, Objectives, Advantages and Disadva...RKavithamani
 
1029-Danh muc Sach Giao Khoa khoi 6.pdf
1029-Danh muc Sach Giao Khoa khoi  6.pdf1029-Danh muc Sach Giao Khoa khoi  6.pdf
1029-Danh muc Sach Giao Khoa khoi 6.pdfQucHHunhnh
 
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...EduSkills OECD
 
The Most Excellent Way | 1 Corinthians 13
The Most Excellent Way | 1 Corinthians 13The Most Excellent Way | 1 Corinthians 13
The Most Excellent Way | 1 Corinthians 13Steve Thomason
 
1029 - Danh muc Sach Giao Khoa 10 . pdf
1029 -  Danh muc Sach Giao Khoa 10 . pdf1029 -  Danh muc Sach Giao Khoa 10 . pdf
1029 - Danh muc Sach Giao Khoa 10 . pdfQucHHunhnh
 
Mastering the Unannounced Regulatory Inspection
Mastering the Unannounced Regulatory InspectionMastering the Unannounced Regulatory Inspection
Mastering the Unannounced Regulatory InspectionSafetyChain Software
 

Recently uploaded (20)

mini mental status format.docx
mini    mental       status     format.docxmini    mental       status     format.docx
mini mental status format.docx
 
Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1
 
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and Mode
 
Student login on Anyboli platform.helpin
Student login on Anyboli platform.helpinStudent login on Anyboli platform.helpin
Student login on Anyboli platform.helpin
 
Z Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot GraphZ Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot Graph
 
Activity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfActivity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdf
 
Web & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfWeb & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdf
 
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptxINDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
 
Separation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and ActinidesSeparation of Lanthanides/ Lanthanides and Actinides
Separation of Lanthanides/ Lanthanides and Actinides
 
Accessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactAccessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impact
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Education
 
How to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptxHow to Make a Pirate ship Primary Education.pptx
How to Make a Pirate ship Primary Education.pptx
 
Nutritional Needs Presentation - HLTH 104
Nutritional Needs Presentation - HLTH 104Nutritional Needs Presentation - HLTH 104
Nutritional Needs Presentation - HLTH 104
 
Privatization and Disinvestment - Meaning, Objectives, Advantages and Disadva...
Privatization and Disinvestment - Meaning, Objectives, Advantages and Disadva...Privatization and Disinvestment - Meaning, Objectives, Advantages and Disadva...
Privatization and Disinvestment - Meaning, Objectives, Advantages and Disadva...
 
1029-Danh muc Sach Giao Khoa khoi 6.pdf
1029-Danh muc Sach Giao Khoa khoi  6.pdf1029-Danh muc Sach Giao Khoa khoi  6.pdf
1029-Danh muc Sach Giao Khoa khoi 6.pdf
 
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
 
The Most Excellent Way | 1 Corinthians 13
The Most Excellent Way | 1 Corinthians 13The Most Excellent Way | 1 Corinthians 13
The Most Excellent Way | 1 Corinthians 13
 
1029 - Danh muc Sach Giao Khoa 10 . pdf
1029 -  Danh muc Sach Giao Khoa 10 . pdf1029 -  Danh muc Sach Giao Khoa 10 . pdf
1029 - Danh muc Sach Giao Khoa 10 . pdf
 
Mastering the Unannounced Regulatory Inspection
Mastering the Unannounced Regulatory InspectionMastering the Unannounced Regulatory Inspection
Mastering the Unannounced Regulatory Inspection
 

Ferrante and Griffey "Federated Authentication_ Browser changes and what to expect"

  • 1. Federated Authentication Browser changes and what to expect Jason Griffey Director of Strategic Initiatives, NISO Amanda Ferrante Principal Product Manager, Identity & Access Management, EBSCO
  • 2. [ 2 ] Topics for Today Problem Statement About Tracking Timing and Browser Development Activities Next Steps
  • 3. [ 3 ] Non-transparent, uncontrollable tracking of users across the web needs to be addressed and prevented. Problem Statement for the Web
  • 4. [ 4 ] Libraries and Publishing is Important But The experience and lead driver of the browser vendors is in the consumer web.
  • 5. [ 5 ] Regulation Trumps Standardization Browser vendors are being held accountable for tracking. They will implement tech that breaks things in order to avoid legal action.
  • 7. [ 7 ] Browsers vs Browser Engines • Browsers = Chrome, Firefox, Safari, Edge, Brave • Browser engines = Blink (aka, Chromium), Gecko, WebKit • Functionality is based on the browser engine more than the browser • ALL browsers on iOS and iPadOS are actually built on WebKit; WebKit does not support third-party cookies • Edge and Chrome are built on Blink; they will show much the same behaviors when it comes to features This matters when you start troubleshooting why someone can’t get to a website or service
  • 8. [ 8 ] How Does Tracking Happen Third-Party Cookies IP Addresses Browser Fingerprinting Link Decoration Bounce Tracking
  • 9. [ 9 ] HTTP cookies (also called web cookies, Internet cookies, browser cookies, or simply cookies) are small blocks of data created by a web server while a user is browsing a website and placed on the user's computer or other device by the user’s web browser. • First-Party Cookies • Accessible only by the domain that created it • Third-Party Cookies • Accessible to any site at any domain Cookies
  • 10. [ 10 ] IP Addresses Used to identify machines and/or services • Tracking mitigations for Browser Fingerprinting often impact IP address information • Often used to make authorization decisions in: • Libraries • Enterprise Resource Planning (ERP) systems
  • 11. [ 11 ] Browser Fingerprinting Information collected about the software and hardware of a remote computing device for the purpose of identification Includes capture of information such as • Browser used • Fonts used • Add-ons used • Browser security configuration • IP address • …
  • 12. [ 12 ] Link Decoration A method of adding extra information to the URL. Also known as “navigation-based tracking” Used for: • Query strings • Some authentication tokens (i.e., “Front-channel”) • Tracking information https://2023alaannual.eventscribe.net/myplan.asp?mode=sessions&afp=MkMxM Tc3MTo2MTUyNjc2MDpNc1N1SDVYYg
  • 13. [ 13 ] Bounce Tracking Used by trackers to get around third-party limitations, also known as redirect tracking ● Website A sends the browser to the tracker to get a first-party cookie. ○ The tracker then sends the browser on to the user's destination with additional information stored in the browser that will allow the tracker to ’follow’ the user around the web. ● The end-user does not see this transition; they only see Website A and then the destination page.
  • 14. [ 14 ] Many applications and services need to work through the browser to support SSO/federated login (and other library services), and yet these and tracking tools use the same features and are indistinguishable from the browser’s perspective.
  • 15. [ 15 ] Sites use features like cookies for more than just authentication and authorization • Storing user preferences • Session information across frames • Demographic info for targeted advertising / content It’s About More Than Just Authentication
  • 17. [ 17 ] Implications to Remember • Authentication that uses SAML will continue to work as designed for at least the next 1-3 years. • (except, the ability to globally log out of all SAML sessions) • WAYF IdP Discovery services will continue to work. • (previous organizations will likely be forgotten (e.g., SeamlessAcccess). • Services that share information between third-parties in frames (e.g., Teams, ILS/LMS) will have mixed results. • Other features that enable tracking (IP addresses, browser fingerprinting) are already breaking, depending on which browser is being used. • WAYFless linking (link decoration) may be affected depending on implementation.
  • 18. [ 18 ] Timelines • Apple’s timeline: • n/a (Apple started blocking third-party cookies by default in 2017 as part of Intelligent Tracking Protection) • With Safari 17, they are also removing known link decoration trackers in Private Browsing Mode. • Mozilla’s timeline: • n/a (Mozilla also blocks third-party cookies by default as of June 2022 with Total Cookie Protection) • Google’s timeline: • https://privacysandbox.com/timeline • “As developers adopt these APIs, we now intend to begin phasing out third-party cookies in Chrome in the second half of 2024.”
  • 20. [ 20 ] What is happening Right Now? • Seamless Access developers are meeting regularly with browser vendors ○ Other library vendors are in that group as well • Discussions w/ Mozilla, Google re: creating a test environment • Discussions with FedID CG, FIDO Alliance, others on forming a W3C Working Group to standardize FedCM
  • 21. [ 21 ] Want to Learn More? To be a part of developing the solution (or at least lurk and learn) • Federated Identity Community Group • https://www.w3.org/community/fed-id/ • Private Advertising Technology Community Group • https://www.w3.org/community/patcg/ • REFEDS Browser Changes and Federation WG • https://wiki.refeds.org/display/GROUPS/Browser+Changes+ and+Federation
  • 23. AI & Machine Learning in Scholarly Publishing: Services, Data, and Ethics October 3, 2023 Washington, DC IN PERSON Week of February 12, 2024 Baltimore, MD
  • 25. Link to these slides