‹ BackHN Continuity

Thread

SAML: A fractal of bad design

353 points · 190 comments · aray07

  1. cameronh90 · · focus · HN ↗
    SAML sucks, but it still has a bunch of features for its specific narrow enterprise SSO use-case that OIDC lacks - most notably IdP-initiated flow. OIDC is a constellation of specs with inconsistent support across products, whereas the commonly-implemented subset of SAML is more-or-less stable in its mediocrity.

    OIDC will eventually displace SAML, but if you're selling to enterprises you should really support both. Both will pale compared to the amount of time you spend dealing with SCIM inconsistencies between IdPs anyway.

    1. maxwellg · · focus · HN ↗
      OIDC doesn't support IDP initiated flows for a reason - they're vulnerable to a class of attacks known as Login CSRF. An attacker can trick a victim into submitting an IdP-initiated authentication response linked to the attacker's account/session into the victim's browser profile on the SP. Think - Eve tricks Bob into signing in to Eve's PayPal account instead of Bob's. Bob, none the wiser, links his bank account. Eve now has access to Bob's funds.

      IdPs that need to support an "IdP-initiated" user experience (like a portal or dashboard where users click an app icon) should instead have that icon link to a specific landing page on the SP that safely kicks off a standard, SP-initiated OIDC flow. IdP -> (SP -> IdP -> SP). Look at Okta's "Initiate Login URI" for an example of this.

      1. bawolff · · focus · HN ↗
        I feel like there is an easy solution to login csrf with IdP initiated flows. The SP just gives a pop up saying - you are logging into X as user Y. Continue?
        1. throwaway7356 · · focus · HN ↗
          The has been proven again and again to not work. See for example HTTPS certificate warnings for which now there is a standard to ask browsers to not show a popup just saying "The server might not be the correct one. Continue?"

          It's an easy solution, but it doesn't work at all.

          1. bawolff · · focus · HN ↗
            I don't really think that is comparable.

            For starters, users generally do not understand what a cert validation error means. They do understand what it means to browse to a website.

            The cert validation error is in the way of the user's intended action. This popup would not be.

            Fundamentally such a pop up is not a security warning. It does not indicate that something is unsafe. That makes a world of difference.

            I think a better comparison would be when you exit an app, and the app prompts you if you want to save. That has generally worked well.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.