ALEXKRI.NET
Resume Contact
← Back

SAML: A fractal of bad design

Trail of Bits argues SAML isn’t just dated, it’s structurally hard to implement safely: enveloped signatures mean you can’t validate the bytes as received, and XML canonicalization keeps generating parser differentials — Go’s stdlib XML and libxml2 in GitHub Enterprise both got bitten. Their advice is blunt: support OIDC, abandon SAML. Easy to say when enterprise buyers still write SAML into the RFP 😅

Read the source ↗