← Back to events
ActiveTech

SAML: A Fractal of Bad Design

What happened

SAML, the XML-based authentication protocol that birthed the SSO industry, is fundamentally flawed due to XML complexity, canonicalization issues, enveloped signatures, and design ossification, making it vulnerable to signature wrapping attacks and parser differentials that persist despite decades of awareness. Organizations should migrate to OpenID Connect (OIDC), which avoids these pitfalls through simpler JSON-ba…

Summary assembled by rule from the sources below

Why it's spreading

Timeline

  1. First appeared on Hacker NewsHacker News
  2. Discussion started on LobstersLobsters

Sources

Community