‹ BackHN Continuity

Thread

SAML: A fractal of bad design

353 points · 190 comments · aray07

  1. ocdtrekkie · · focus · HN ↗
    Eh, if you don't have SAML support, I can find a product that does. Not a problem. \o/

    (Or to be more clear, it is mostly unacceptable for an enterprise product to have opinionated decisions about what authentication it works with. You either work with what we use or you are not viable as a product for our need. It's kinda simple. I would expect someone whose authentication was OIDC-based to be similarly dismissive if you told them you only would do SAML.)

    1. tomjen3 · · focus · HN ↗
      You use Entra. Entra can do jwt’s.

      Saml is just not reasonable in our modern security environment.

      1. ocdtrekkie · · focus · HN ↗
        Entra is just allowing the Chinese government in your environment. Why bother with authentication at all?

        <a href="https:&#x2F;&#x2F;www.war.gov&#x2F;News&#x2F;News-Stories&#x2F;Article&#x2F;Article&#x2F;4288992&#x2F;pentagon-halts-chinese-coders-affecting-dod-cloud-systems&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.war.gov&#x2F;News&#x2F;News-Stories&#x2F;Article&#x2F;Article&#x2F;428899... (Microsoft has solely discontinued this practice for the DoD tier. Commercial, GCC, and GCC High are still impacted because foreign labor is cheaper than the risk to your security.)

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.