SAML, the XML-based authentication protocol that birthed the SSO industry, is fundamentally flawed due to XML complexity, canonicalization issues, enveloped signatures, and design ossification, making it vulnerable to…

2 points•radlad•10 days ago•1 comment•

1 comment

anitil9 days ago
What a great title. I never quite understood why XML took over the world and got itself baked in to everything. I guess it kind of did everything well enough compared to whatever came before? Or because it was heavily used in Java-land?

Edit to add: This is also the only time I've seen JWT used in a security comparison and come out on top! (re: not including the signature in the payload)

Read the full thread on Hacker News →

Related stories