[Openid-specs-risc] Proposal to add some signals to CAEP
Atul Tulshibagwale
atul.tulshibagwale at crowdstrike.com
Mon Jun 22 18:55:07 UTC 2026
Hi Thi, could you please create an issue
<https://github.com/openid/sharedsignals/issues> in GitHub with this
proposal?
Thanks,
Atul
On Fri, Jun 19, 2026 at 4:18 AM Thi Nguyen-Huu <thi.nh at winmagic.com> wrote:
> Thanks, Atul — glad to take it to the list.
>
>
>
> Quick recap of the proposal: a few signals, the endpoint reporting its own
> state — powered on/off, user logged on/off, screen locked — as a two-way
> change event, same family as device-compliance-change. These are facts the
> endpoint sees first-hand, and should be useful wrt. the decision to
> (continue to) grant access.
>
>
>
> The part I think is worth the group's time is the question that follows.
> When the user steps away and comes back, or logs off and logs on again, can
> a receiver restore access with no prompt — or is revoke-and-reauthenticate
> the only path the model offers today? That answer shapes what the signal is
> actually good for, and it's really a question about SP behavior and UX more
> than about the signal itself. I understand the SP behavior is not in scope
> of CAEP but it's important for UX and should be raised here or somewhere.
>
>
>
> For the 23rd or later, I'd welcome a short slot — a few minutes to frame
> it, then open it up for discussion. Whatever time the chairs can give
> works; the discussion is important for us — it's about getting to "no user
> action" for online access. Happy to write up the event shape in the
> meantime if that's useful.
>
>
>
> Cheers
>
>
>
> *Thi Nguyen-Huu | *CEO
>
>
>
> Tel: +1 905.502.7000 x 3288 | Toll Free: 888.879.5879
> thi.nh at winmagic.com | www.winmagic.com [winmagic.com]
> <https://urldefense.com/v3/__http://www.winmagic.com/__;!!BmdzS3_lV9HdKG8!wmssrtYC_Rc9I5rAT2MFJI-px4jaRIKwqS5usbAmvYw1L8Di4-78MGIPWaQVk1eJUmpatW8k1Li9_5SjYc9wLFFrnPWS$>
>
>
>
> *WinMagic Corp.* | 11-80 Galaxy Blvd.
>
> Toronto, ON | M9W 4Y8 | Canada | www.winmagic.com [winmagic.com]
> <https://urldefense.com/v3/__http://www.winmagic.com/__;!!BmdzS3_lV9HdKG8!wmssrtYC_Rc9I5rAT2MFJI-px4jaRIKwqS5usbAmvYw1L8Di4-78MGIPWaQVk1eJUmpatW8k1Li9_5SjYc9wLFFrnPWS$>
>
> [facebook.com]
> <https://urldefense.com/v3/__http://www.facebook.com/WinMagicInc__;!!BmdzS3_lV9HdKG8!wmssrtYC_Rc9I5rAT2MFJI-px4jaRIKwqS5usbAmvYw1L8Di4-78MGIPWaQVk1eJUmpatW8k1Li9_5SjYc9wLIi1wOeM$>
> [twitter.com]
> <https://urldefense.com/v3/__https://twitter.com/winmagic__;!!BmdzS3_lV9HdKG8!wmssrtYC_Rc9I5rAT2MFJI-px4jaRIKwqS5usbAmvYw1L8Di4-78MGIPWaQVk1eJUmpatW8k1Li9_5SjYc9wLKpFVZIp$>
> [linkedin.com]
> <https://urldefense.com/v3/__http://www.linkedin.com/company/winmagic__;!!BmdzS3_lV9HdKG8!wmssrtYC_Rc9I5rAT2MFJI-px4jaRIKwqS5usbAmvYw1L8Di4-78MGIPWaQVk1eJUmpatW8k1Li9_5SjYc9wLB1s1lIv$>
> [winmagic.com]
> <https://urldefense.com/v3/__https://www.winmagic.com/blog/__;!!BmdzS3_lV9HdKG8!wmssrtYC_Rc9I5rAT2MFJI-px4jaRIKwqS5usbAmvYw1L8Di4-78MGIPWaQVk1eJUmpatW8k1Li9_5SjYc9wLGhLhOoU$>
>
> [image: World Passkey Day]
>
>
>
>
>
> *From:* Atul Tulshibagwale <atul.tulshibagwale at crowdstrike.com>
> *Sent:* Thursday, June 18, 2026 8:12 PM
> *To:* Thi Nguyen-Huu <thi.nh at winmagic.com>
> *Cc:* OpenID RISC List <openid-specs-risc at lists.openid.net>; Alexey
> Yemelyanov <Alexey.Yemelyanov at winmagic.com>; John O’Leary <
> John.OLeary at winmagic.com>; Garry Mccracken <Garry.Mccracken at winmagic.com>
> *Subject:* Re: Proposal to add some signals to CAEP
>
>
>
> CAUTION:This email originated from outside of the organization. Do not
> click links, open attachments or respond unless you recognize the sender
> and know that the content is safe.
>
>
>
> Hi all,
>
> WinMagic is proposing to include this in the agenda for discussion on June
> 23rd. If you have any thoughts on this, it'll be great to get the
> discussion going here on the mailing list.
>
>
>
> Thanks,
>
> Atul
>
>
>
> On Thu, Jun 18, 2026 at 8:12 AM Thi Nguyen-Huu <thi.nh at winmagic.com>
> wrote:
>
> Hi Atul and all,
>
>
>
> I am not sure if this is the right place to send this email to. Please
> help send it to the right place if needed. Or if we need to do something
> more. Thank you.
>
> --
>
> To the OpenID Shared Signals Working Group,
>
>
>
> Our MagicEndpoint is using CAEP for both security and a smoother
> experience for the user. We also took part in the Shared Signals interop at
> Gartner in 2024, so we've worked with these mechanisms in practice.
>
>
>
> I'd like to propose some new signals and ask the group one question about
> user experience.
>
>
>
> The signals are:
>
> - the endpoint is powered on or off
> - the user is logged on or off
> - the screen is locked
> - and possibly more from the endpoint later
>
>
>
> These are simple facts. But if the receiver can see them, some attacks
> stop right away. When a request arrives with a valid token but the endpoint
> is off, it's an attack. Same if the user has logged off.
>
>
>
> The screen lock is the one that adds complexity. A locked device should
> keep receiving email, for example. But a new request that needs the user
> present should be refused.
>
>
>
> These signals work like device-compliance-change — a two-way state change.
> It's a small addition to the existing signal types. But it may carry more
> implications for receivers.
>
>
>
> That leads to my question: when the user returns and logs in again, will
> the session continue without a new sign-in — or even continue where it left
> off? I understand the response is up to the receiver, the SP. I'd value the
> group's thinking.
>
>
>
> I hope the signals and the question are clear. We look forward to your
> feedback and we’ll be happy to draft the event shape.
>
>
>
> Cheers
>
>
>
> *Thi Nguyen-Huu | *CEO
>
>
>
> Tel: +1 905.502.7000 x 3288 | Toll Free: 888.879.5879
> thi.nh at winmagic.com | www.winmagic.com [winmagic.com]
> <https://urldefense.com/v3/__http:/www.winmagic.com/__;!!BmdzS3_lV9HdKG8!y2lV6kfinphDy07xQkaB7WcbFqCaOc-c8ytMg2oZS_D6ZnPZ8yDqRSkFOdBqc1SpqatlzcUgk9duwaU1T617uvY442PV$>
>
>
>
> *WinMagic Corp.* | 11-80 Galaxy Blvd.
>
> Toronto, ON | M9W 4Y8 | Canada | www.winmagic.com [winmagic.com]
> <https://urldefense.com/v3/__http:/www.winmagic.com/__;!!BmdzS3_lV9HdKG8!y2lV6kfinphDy07xQkaB7WcbFqCaOc-c8ytMg2oZS_D6ZnPZ8yDqRSkFOdBqc1SpqatlzcUgk9duwaU1T617uvY442PV$>
>
> [facebook.com]
> <https://urldefense.com/v3/__http:/www.facebook.com/WinMagicInc__;!!BmdzS3_lV9HdKG8!y2lV6kfinphDy07xQkaB7WcbFqCaOc-c8ytMg2oZS_D6ZnPZ8yDqRSkFOdBqc1SpqatlzcUgk9duwaU1T617unjUVXsh$>
> [twitter.com]
> <https://urldefense.com/v3/__https:/twitter.com/winmagic__;!!BmdzS3_lV9HdKG8!y2lV6kfinphDy07xQkaB7WcbFqCaOc-c8ytMg2oZS_D6ZnPZ8yDqRSkFOdBqc1SpqatlzcUgk9duwaU1T617ushnCY_7$>
> [linkedin.com]
> <https://urldefense.com/v3/__http:/www.linkedin.com/company/winmagic__;!!BmdzS3_lV9HdKG8!y2lV6kfinphDy07xQkaB7WcbFqCaOc-c8ytMg2oZS_D6ZnPZ8yDqRSkFOdBqc1SpqatlzcUgk9duwaU1T617ulg9HkET$>
> [winmagic.com]
> <https://urldefense.com/v3/__https:/www.winmagic.com/blog/__;!!BmdzS3_lV9HdKG8!y2lV6kfinphDy07xQkaB7WcbFqCaOc-c8ytMg2oZS_D6ZnPZ8yDqRSkFOdBqc1SpqatlzcUgk9duwaU1T617uoE7AbBS$>
>
> [image: World Passkey Day]
>
>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-risc/attachments/20260622/05c86b49/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image001.png
Type: image/png
Size: 1425 bytes
Desc: not available
URL: <http://lists.openid.net/pipermail/openid-specs-risc/attachments/20260622/05c86b49/attachment-0005.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image002.png
Type: image/png
Size: 1319 bytes
Desc: not available
URL: <http://lists.openid.net/pipermail/openid-specs-risc/attachments/20260622/05c86b49/attachment-0006.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image003.png
Type: image/png
Size: 1408 bytes
Desc: not available
URL: <http://lists.openid.net/pipermail/openid-specs-risc/attachments/20260622/05c86b49/attachment-0007.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image004.png
Type: image/png
Size: 1457 bytes
Desc: not available
URL: <http://lists.openid.net/pipermail/openid-specs-risc/attachments/20260622/05c86b49/attachment-0008.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image005.png
Type: image/png
Size: 194338 bytes
Desc: not available
URL: <http://lists.openid.net/pipermail/openid-specs-risc/attachments/20260622/05c86b49/attachment-0009.png>
More information about the Openid-specs-risc
mailing list