SSO improves convenience and centralizes access, but the 2025 University of Pennsylvania breach shows how a compromised PennKey account can expose many internal systems and large amounts of data. Strong passwords, phishing-resistant MFA, and tighter control over identity provider assets, certificates, OAuth secrets, and delegated permissions are essential to secure SSO. #UniversityofPennsylvania #PennKey #FIDO2 #WebAuthn #passkeys #SAML #OIDC
Keypoints
- SSO can improve convenience while concentrating risk in one login.
- The Penn breach reportedly used a PennKey SSO account to access multiple internal systems.
- Strong passwords should follow NIST guidance and avoid weak legacy rules.
- MFA should be enforced everywhere, with phishing-resistant options preferred.
- IdP admin accounts, signing keys, OAuth secrets, and consent grants must be tightly protected.