‹ BackHN Continuity

Thread

SAML: A fractal of bad design

353 points · 190 comments · aray07

  1. arpinum · · focus · HN ↗
    SAML is even worse than the article describes, problems like needing to check what the signature actually signs. But I'm optimistic about the future, instead of relying on libraries that do a lot, such as general xml parsing, we can support a subset of SAML and only the dialects of the top ~10 providers. Extreme niche providers can be added ad-hoc and only if the deal size makes it worthwhile.
    1. jagged-chisel · · focus · HN ↗
      > … needing to check what the signature actually signs.

      I mean … how else would you check a signature? You have to have the data to validate the signature.

      1. bawolff · · focus · HN ↗
        Normally you sign the whole dicument.

        In SAML you sign a (potentially attacker controlled) subset after normalization. So a lot of saml bugs come down to the attacker adding things that aren't covered by the signature. Sometimes this means appending or prepending stuff, but my favourite is adding comments which can alter the interpretation of the xml document (as it splits text nodes) but doesn't alter the signature.

        1. owenmarshall · · focus · HN ↗
          And this doesn't even get into "which normalization approach!" or "what gets signed (or not)!"

          It's an absolute dumpster fire.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.