‹ BackHN Continuity

Thread

SAML: A fractal of bad design

353 points · 190 comments · aray07

  1. bawolff · · focus · HN ↗
    My favourite SAML horror story, is that it used to be, that by default the main c implementation of xmlsig would not just check the sig with the public key specified but would also:

    - check it against an hmac using a password specified in the attacker controlled document.

    - check the signature using web pki (so the attacker could sign the saml document with their TLS key for their own personal domain and it would always be considered valid)

    I honestly dont know how sites with saml arent getting hacked all the time. The only thing worse than the absolute terrible standards are the absolute terrible implementations.

    1. taybin · · focus · HN ↗
      Didn’t JWT have a similar thing, where you could specify the algorithm to use and that included “null”?
      1. bawolff · · focus · HN ↗
        Yes. JWT also had a bug where some implementations would use the pubkey as an hmac password if you switched the algorithm which is similarly bad.

        Specifying the algorithm in the attacker controlled document is a bad design imo.

        Still i feel like SAML is much worse. JWT has a few rough edges, but SAML its like everything.

        1. patmorgan23 · · focus · HN ↗
          Yeah, the standard should have just specified like a sha256 HMAC, when that becomes broken in 20 years we can just do a JWT2 (or invent some new successor standard)
          1. bawolff · · focus · HN ↗
            given that md5-hmac isn't even broken despite md5 being broken, it seems unlikely sha256-hmac will fall in 20 years.

            that said, algorithm agility isn't the primary issue, its whether you want symmetric (hmac) or asymmetric (digital signature). Both have advantages and disadvantages so there is no per-se right answer, it depends on context.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.