‹ BackHN Continuity

Thread

SAML: A fractal of bad design

353 points · 190 comments · aray07

  1. tehnoslow · · focus · HN ↗
    A fair criticism of the article is that it lists SAML's vulnerabilities but doesn't do the same comparison for OIDC. OIDC has its own problems too: JWT algorithm confusion, none algorithm attacks, missing audience checks, and bugs in JOSE libraries
    1. tptacek · · focus · HN ↗
      SAML has audience checks and selectable algorithms. I don't like JWT, but it's no XMLDSIG.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.