Comment on OneLogin: Breach Exposed Ability to Decrypt DataparentComments−vidarh9yThat's true, but the SSO service itself can run on the users computer, so there is no need for the service to be able to decrypt the users data, only for it to be able to persist encrypted data.
Comments
That's true, but the SSO service itself can run on the users computer, so there is no need for the service to be able to decrypt the users data, only for it to be able to persist encrypted data.