‹ BackHN Continuity

Thread

SAML: A fractal of bad design

353 points · 190 comments · aray07

  1. ocdtrekkie · · focus · HN ↗
    Eh, if you don't have SAML support, I can find a product that does. Not a problem. \o/

    (Or to be more clear, it is mostly unacceptable for an enterprise product to have opinionated decisions about what authentication it works with. You either work with what we use or you are not viable as a product for our need. It's kinda simple. I would expect someone whose authentication was OIDC-based to be similarly dismissive if you told them you only would do SAML.)

    1. iamjake648 · · focus · HN ↗
      Realistically, what modern IdP supports SAML but not OIDC though? To me, it seems like more of a case of 'I know and am comfortable with SAML, why learn something new?'.
      1. ocdtrekkie · · focus · HN ↗
        Everything can stack onto everything else, sure. Most people's SAML IdPs are... synced from their LDAP. =) But in particular SAML provides an SSO experience where signing in once in the browser will allow you to go to various integrated sites and apps without signing in again. That flow is not dissimilar from OIDC but it is separate. So I can have 10 apps with SAML and 1 with OIDC, and the OIDC one is gonna be an odd duck.

        And a key aspect that modern setups often forget: Every single different UI your users see makes them easier to phish. One of the reasons Entra is so easily phishable is Microsoft uses like 500 different domains for their cloud platform, so the one in the mix they don't actually own isn't obvious to the average user.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.