usnistgov / 800-63-3

Home to public development of NIST Special Publication 800-63-3: Digital Authentication Guidelines
https://pages.nist.gov/800-63-3/
Other
702 stars 102 forks source link

State requirement in positive terms #1919

Closed jimfenton closed 4 years ago

jimfenton commented 5 years ago

(Submitted by MITRE)

In 800-63C, Section 4.2, fourth paragraph:

"A subscriber’s information SHALL NOT be transmitted between IdP and RP for any purpose other than those described in Section 5.2, even when those parties are whitelisted." is inconsistent with what Section 5.2 discusses - that of revealing what the subscriber has done to others. This sentence and the reference does not provide guidance for what the IdP can transmit. Digital identity? Attributes? FAL? In addition, there is a mismatch between this statement's noun: "information" and Section 5.2's: "activities".

Suggestion: Consider rephrasing this sentence in the positive, stating either the type of information or the purposes allowed.