‹ BackHN Continuity

Thread

SAML: A fractal of bad design

353 points · 190 comments · aray07

  1. miguelspizza · · focus · HN ↗
    SAML is bad, but OAuth and OIDC are showing major cracks with identity and agents. Go to any major company right now and ask them how they are dealing with authenticating agents/what an agent identity even is.

    The XSW part of the article was new to me though and kinda shocking

    1. jeroenhd · · focus · HN ↗
      RFC8628 has been out for eight years, OAuth isn't standing in the way of bots anymore.

      OAuth/OIDC is a problem if you're trying to shove a bot-shaped peg into a browser-shaped hole, but we don't need a new protocol to solve that.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.