‹ BackHN Continuity

Thread

SAML: A fractal of bad design

353 points · 190 comments · aray07

  1. ocdtrekkie · · focus · HN ↗
    Eh, if you don't have SAML support, I can find a product that does. Not a problem. \o/

    (Or to be more clear, it is mostly unacceptable for an enterprise product to have opinionated decisions about what authentication it works with. You either work with what we use or you are not viable as a product for our need. It's kinda simple. I would expect someone whose authentication was OIDC-based to be similarly dismissive if you told them you only would do SAML.)

    1. jeltz · · focus · HN ↗
      That mindset is indicative of security theatre to me. But as security theatre is common in entrprise IT that does not surprise me.
      1. jeroenhd · · focus · HN ↗
        Security is part of the story (beats keep track of different usernames+passwords for every tool), but convenience is also a major factor.

        Pretty much everything supports SAML. If you decide not to support one of the standard protocols for SSO, you'll lose out on customers. Your tool has to bring in a lot of benefit (and have no competition) to warrant upending a company's entire auth system for.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.