‹ BackHN Continuity

Thread

SAML: A fractal of bad design

353 points · 190 comments · aray07

  1. dudeinjapan · · focus · HN ↗
    The issue is not that SAML is XML per se, but rather: (1) auth happens over public internet rather than server-to-server, allowing the user to MITM the message flow and (2) the various XML parsing libs in various languages do not have consistent behavior when it comes to looking up a node by name (i.e. if there are dupes) or finding a child node. MITM can exploit these divergences for auth bypasses, etc.

    A SAML lib needs an extreme amount of XML sanitization, while still handling all the various “in-the-wild” XML format funkiness

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.