CIBA - Clarify privacy issues with login_hint_token and discovery service

Issue #97 resolved
Dave Tonge created an issue

John brought up the point that for CIBA use cases, the user would have to give the RP an identifier to pass to the discovery service. Therefore its unlikely to bring any privacy benefits to CIBA from using an encrypted login_hint_token from a discovery service.

We should update the draft to reflect this.

Comments (8)

  1. Bjorn Hjelm

    John brought up the point that for CIBA use cases, the user would have to give the RP an identifier to pass to the discovery service. Therefore its unlikely to bring any privacy benefits to CIBA from using an encrypted login_hint_token from a discovery service.

    We should update the draft to reflect this.

  2. Log in to comment