SAML, the XML-based authentication protocol that birthed the SSO industry, is fundamentally flawed due to XML complexity, canonicalization issues, enveloped signatures, and design ossification, making it vulnerable to…
1 comment
anitil9 days ago
What a great title. I never quite understood why XML took over the world and got itself baked in to everything. I guess it kind of did everything well enough compared to whatever came before? Or because it was heavily used in Java-land?
Edit to add: This is also the only time I've seen JWT used in a security comparison and come out on top! (re: not including the signature in the payload)
Read the full thread on Hacker News →
Related stories
- SAML: A fractal of bad designblog.trailofbits.comHacker News · 348 points · 8 days ago
- SAML: A fractal of bad designblog.trailofbits.comLobsters · 34 points · 8 days ago
- Hacker News · 1 points · 5 days ago
- Lobsters · 10 points · about 3 years ago
- How to Sync a Design System with Claude Designnitayneeman.comHacker News · 1 points · about 18 hours ago
- Lobsters · 5 points · almost 6 years ago