‹ BackHN Continuity

Thread

SAML: A fractal of bad design

353 points · 190 comments · aray07

  1. jmbwell · · focus · HN ↗
    It’s such a product of “Ooh! Markup languages! What can we use a markup language to solve!” When authentication is just not a document or data stream that needs marked-up.

    The article rightly connects this to XML, which was indeed the hammer to everything’s nail at the time

    I think we aren’t done with this problem yet, though. OIDC makes a lot of assumptions in service to Google and others. And tailscale as mentioned, despite “holding the line,” already reveals the cracks when things like GitHub accounts have to be treated differently from others.

    What we are missing is a provider-independent way to do this. I should be able to create an account and log in just about anywhere using a backend I control. It can be done, but not with what we have today

    1. martijnvds · · focus · HN ↗
      That's what the original OpenID (from back in the LiveJournal days) was supposed to be right?

      "Host your own identity"

      1. xp84 · · focus · HN ↗
        Yeah, it never really got off the ground though because incentives weren’t aligned. Everyone wants you to sign up on their site for data hoarding reasons, not to use an identity from elsewhere.
        1. stephbook · · focus · HN ↗
          When I first learned about OIDC, I thought.. I can log in to Google and Apple using MY identity? Sweet.

          Turns out, you can support Google and Apple accounts in your app, not the other way around. Well..

          (Still a win though, especially if you need to gate your app with a login.)

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.