SAML is even worse than the article describes, problems like needing to check what the signature actually signs. But I'm optimistic about the future, instead of relying on libraries that do a lot, such as general xml parsing, we can support a subset of SAML and only the dialects of the top ~10 providers. Extreme niche providers can be added ad-hoc and only if the deal size makes it worthwhile.
In a JWT this is simple, the signature checks the entire sig and data sections. In XML signatures it checks whatever it says it checks, a list of URIs, which may also be transformed.
So it is possible to have an XML signature that points to an element that does not include some important piece of data.
arpinum · · focus · HN ↗
jagged-chisel · · focus · HN ↗
I mean … how else would you check a signature? You have to have the data to validate the signature.
arpinum · · focus · HN ↗
So it is possible to have an XML signature that points to an element that does not include some important piece of data.
bawolff · · focus · HN ↗