‹ BackHN Continuity

Thread

SAML: A fractal of bad design

353 points · 190 comments · aray07

  1. bigquama · · focus · HN ↗
    I have to know. Is this a play on the ever-so-popular <a href="https:&#x2F;&#x2F;eev.ee&#x2F;blog&#x2F;2012&#x2F;04&#x2F;09&#x2F;php-a-fractal-of-bad-design&#x2F;" rel="nofollow">https:&#x2F;&#x2F;eev.ee&#x2F;blog&#x2F;2012&#x2F;04&#x2F;09&#x2F;php-a-fractal-of-bad-design&#x2F;
    1. schwag09 · · focus · HN ↗
      Yes it is, good catch. It&#x27;s even linked under the text &quot;especially at the time&quot; in the post. I probably should have referenced it more prominently, but I thought it was a fun Easter egg under a more subtle link.

      As the post mentions, I worked on the DAG (an on-prem IdP implementation) for many years, which was based on simpleSAMLphp. So &quot;PHP: a fractal of bad design&quot; was our other north star after the SAML specs for avoiding critical security issues. I spent many hours poring over that blog post trying my best to avoid PHP bugs.

      Here was a fun one that occurred due to PHP&#x27;s wonky in_array behavior: <a href="https:&#x2F;&#x2F;simplesamlphp.org&#x2F;security&#x2F;201710-01" rel="nofollow">https:&#x2F;&#x2F;simplesamlphp.org&#x2F;security&#x2F;201710-01

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.