{"id":26870,"date":"2021-07-11T22:40:20","date_gmt":"2021-07-12T02:40:20","guid":{"rendered":"https:\/\/www.canarie.ca\/?page_id=26870"},"modified":"2022-07-19T08:51:47","modified_gmt":"2022-07-19T12:51:47","slug":"procedure-douverture-directe-de-seance","status":"publish","type":"page","link":"https:\/\/www.canarie.ca\/fr\/procedure-douverture-directe-de-seance\/","title":{"rendered":"Recommandations concernant le probl\u00e8me soulev\u00e9 par la proc\u00e9dure d\u2019ouverture directe de s\u00e9ance (DSO) de SheerID"},"content":{"rendered":"\n<h1 class=\"wp-block-heading\">SheerID \u201cDirect Sign On (DSO)\u201d Issue Mitigation Recommendations<\/h1>\n\n<div style=\"height:55px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n<p><strong>While SheerID have said that they did not store user credentials gathered during their DSO activities, nor were there any indications of breach, per standard cybersecurity protocols CANARIE recommends that you\u00a0reset any user\u2019s credentials who has accessed the SheerID service. <\/strong><\/p>\n\n<p>As those credentials might have been used on sites directly authenticated on the institutional Identity Management System (IdM), as well as on federated internal resources authenticated by your Identity Provider (IdP) software, you would examine both the logs of the services authenticated directly on the IdM and the logs of the IdP over the affected dates.<\/p>\n\n<p>Colleagues of the University of Trento shared some useful information to confirm if the bot used by SheerID has made any attempt to access your authentication systems:<\/p>\n\n<p><strong>The user-agent declared by the bot is:<\/strong><\/p>\n\n<pre class=\"wp-block-code\"><code>\"Mozilla\/5.0+(X11;+Linux+x86_64)+AppleWebKit\/537.36+(KHTML\\,+like+Gecko)+HeadlessChrome\/89.0.4389.82+Safari\/537.36\"<\/code><\/pre>\n\n<p>The source IP addresses used by the bot are two and apparently used in round-robin:<\/p>\n\n<ul class=\"wp-block-list\"><li>34.199.186.214<\/li><li>35.153.89.227<\/li><\/ul>\n\n<p>The first login attempt was made with an incorrect user, probably to verify the response from the authentication system. The user is \u00ab\u00a0invalid_user\u00a0\u00bb.<\/p>\n\n<p>By using the user-agent above to track the sessions opened by the bot, you should be able to check for accessed accounts. In the event of a positive response, we recommend that you:<\/p>\n\n<ul class=\"wp-block-list\"><li>Tell the users about the incident.<\/li><li>Reset the password of the compromised accounts.<\/li><\/ul>\n\n<section class=\"section section--text-columns no-background\">\n    <div class=\"grid-container\">\n      <div class=\"grid-x grid-padding-x\">\n        <div class=\"cell\">\n          <div style=\"text-align: center;\">\n            <div class=\"large highlighted-text hand-text-center\">\n              <p style=\"text-align: left;\">CANARIE recommends all CAF participants implement Multi-Factor Authentication (MFA).<\/p>\n            <\/div>\n            <\/div>\n    \t\t\t<\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/section>\n\n<p>Effective measures to block bots from accessing systems: <\/p>\n\n<ul class=\"wp-block-list\"><li>Block suspicious user-agents, such as the one used by SheerID which contained the indication of a headless client (HeadlessChrome) in its identification string:<\/li><\/ul>\n\n<pre class=\"wp-block-code\"><code>\"Mozilla\/5.0+(X11;+Linux+x86_64)+AppleWebKit\/537.36+(KHTML\\,+like+Gecko)+HeadlessChrome\/89.0.4389.82+Safari\/537.36\"<\/code><\/pre>\n\n<ul class=\"wp-block-list\"><li>Use anti-bot tools such as CAPTCHA and the likes in the login pages of the Identity Provider and services accessible via direct authentication on your Identity Management System.<\/li><li>Advise your users to always check the address bar before using their institutional credentials and do not enter them if the domain does not correspond to their organization.<\/li><\/ul>\n\n<h3 class=\"wp-block-heading\"><strong>Support<\/strong><\/h3>\n\n<p>Our team is here to support you. Please contact us at <a href=\"mailto:tickets@canarie.ca\" rel=\"nofollow\">tickets@canarie.ca<\/a> for assistance.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>SheerID \u201cDirect Sign On (DSO)\u201d Issue Mitigation Recommendations While SheerID have said that they did not store user credentials gathered [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":0,"parent":0,"menu_order":132,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-26870","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Recommandations concernant le probl\u00e8me soulev\u00e9 par la proc\u00e9dure d\u2019ouverture directe de s\u00e9ance (DSO) de SheerID - CANARIE<\/title>\n<meta name=\"robots\" content=\"noindex, nofollow\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Recommandations concernant le probl\u00e8me soulev\u00e9 par la proc\u00e9dure d\u2019ouverture directe de s\u00e9ance (DSO) de SheerID - CANARIE\" \/>\n<meta property=\"og:description\" content=\"SheerID \u201cDirect Sign On (DSO)\u201d Issue Mitigation Recommendations While SheerID have said that they did not store user credentials gathered [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.canarie.ca\/fr\/procedure-douverture-directe-de-seance\/\" \/>\n<meta property=\"og:site_name\" content=\"CANARIE\" \/>\n<meta property=\"article:modified_time\" content=\"2022-07-19T12:51:47+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.canarie.ca\\\/fr\\\/procedure-douverture-directe-de-seance\\\/\",\"url\":\"https:\\\/\\\/www.canarie.ca\\\/fr\\\/procedure-douverture-directe-de-seance\\\/\",\"name\":\"Recommandations concernant le probl\u00e8me soulev\u00e9 par la proc\u00e9dure d\u2019ouverture directe de s\u00e9ance (DSO) de SheerID - CANARIE\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.canarie.ca\\\/#website\"},\"datePublished\":\"2021-07-12T02:40:20+00:00\",\"dateModified\":\"2022-07-19T12:51:47+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.canarie.ca\\\/fr\\\/procedure-douverture-directe-de-seance\\\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.canarie.ca\\\/fr\\\/procedure-douverture-directe-de-seance\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.canarie.ca\\\/fr\\\/procedure-douverture-directe-de-seance\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/www.canarie.ca\\\/fr\\\/homepage\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Recommandations concernant le probl\u00e8me soulev\u00e9 par la proc\u00e9dure d\u2019ouverture directe de s\u00e9ance (DSO) de SheerID\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.canarie.ca\\\/#website\",\"url\":\"https:\\\/\\\/www.canarie.ca\\\/\",\"name\":\"CANARIE\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.canarie.ca\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Recommandations concernant le probl\u00e8me soulev\u00e9 par la proc\u00e9dure d\u2019ouverture directe de s\u00e9ance (DSO) de SheerID - CANARIE","robots":{"index":"noindex","follow":"nofollow"},"og_locale":"fr_FR","og_type":"article","og_title":"Recommandations concernant le probl\u00e8me soulev\u00e9 par la proc\u00e9dure d\u2019ouverture directe de s\u00e9ance (DSO) de SheerID - CANARIE","og_description":"SheerID \u201cDirect Sign On (DSO)\u201d Issue Mitigation Recommendations While SheerID have said that they did not store user credentials gathered [&hellip;]","og_url":"https:\/\/www.canarie.ca\/fr\/procedure-douverture-directe-de-seance\/","og_site_name":"CANARIE","article_modified_time":"2022-07-19T12:51:47+00:00","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.canarie.ca\/fr\/procedure-douverture-directe-de-seance\/","url":"https:\/\/www.canarie.ca\/fr\/procedure-douverture-directe-de-seance\/","name":"Recommandations concernant le probl\u00e8me soulev\u00e9 par la proc\u00e9dure d\u2019ouverture directe de s\u00e9ance (DSO) de SheerID - CANARIE","isPartOf":{"@id":"https:\/\/www.canarie.ca\/#website"},"datePublished":"2021-07-12T02:40:20+00:00","dateModified":"2022-07-19T12:51:47+00:00","breadcrumb":{"@id":"https:\/\/www.canarie.ca\/fr\/procedure-douverture-directe-de-seance\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.canarie.ca\/fr\/procedure-douverture-directe-de-seance\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.canarie.ca\/fr\/procedure-douverture-directe-de-seance\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.canarie.ca\/fr\/homepage\/"},{"@type":"ListItem","position":2,"name":"Recommandations concernant le probl\u00e8me soulev\u00e9 par la proc\u00e9dure d\u2019ouverture directe de s\u00e9ance (DSO) de SheerID"}]},{"@type":"WebSite","@id":"https:\/\/www.canarie.ca\/#website","url":"https:\/\/www.canarie.ca\/","name":"CANARIE","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.canarie.ca\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"}]}},"_links":{"self":[{"href":"https:\/\/www.canarie.ca\/fr\/wp-json\/wp\/v2\/pages\/26870","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.canarie.ca\/fr\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.canarie.ca\/fr\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.canarie.ca\/fr\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/www.canarie.ca\/fr\/wp-json\/wp\/v2\/comments?post=26870"}],"version-history":[{"count":0,"href":"https:\/\/www.canarie.ca\/fr\/wp-json\/wp\/v2\/pages\/26870\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.canarie.ca\/fr\/wp-json\/wp\/v2\/media?parent=26870"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}