SAML: A Fractal of Bad Design

·Hacker News··

SAML, the XML-based authentication protocol that birthed the SSO industry, is fundamentally flawed due to XML complexity, canonicalization issues, enveloped signatures, and design ossification, making it vulnerable to signature wrapping attacks and parser differentials that persist despite decades of awareness. Organizations should migrate to OpenID Connect (OIDC), which avoids these pitfalls through simpler JSON-based design, detached signatures, and agile evolution.

Read full article →

Related Articles

Claude Opus 5.5
km144 · Hacker News · 3h ago
I asked Meta’s Muse for its filesystem and it sent me 6.8GB
Aeroi · Hacker News · 4h ago
AMD's random number generator can't generate a 0?
BruceEel · Hacker News · 11h ago
There's a high chance of devices being sold with GrapheneOS preinstalled in 2027
Cider9986 · Hacker News · 3h ago
NASA’s Mars Sample Return mission is dead
Muhammad523 · Hacker News · 1d ago