AI Weekly Malaysia

Back to items Summaries

SAML: A fractal of bad design

ID
27701
Status
summarized
Published
23 Sep 2026, 2:57 AM
Fetched
24 Sep 2026, 4:22 AM
Provider
Hacker News
Category
dev-community
Original URL
https://blog.trailofbits.com/2026/09/21/saml-a-fractal-of-bad-design/
Source URL
https://hnrss.org/best

Summary

Score
7.0
Created
24 Sep 2026, 4:24 AM
Tags
Audience
developerssaas_founders

What happened

Trail of Bits argues SAML is a 'fractal of bad design' rooted in 2002-era committee-driven XML protocol design, combining four competing XML security protocols into one. The core vulnerability is its reliance on XML signature validation, which is so complex that most implementations simply wrap libxmlsec, a C codebase few audit, making the protocol fragile and overdue for replacement by OpenID Connect (OIDC).

Why it matters

If you build or maintain SaaS that supports enterprise SSO via SAML, this post reinforces that the protocol's XML signature layer is a persistent attack surface you cannot easily reason about. For new products, default to OIDC over SAML where customers allow it; for existing SAML integrations, treat XML signature validation as a high-risk dependency worth isolating and monitoring rather than trusting blindly.

Discussion angle

How many of us have shipped SAML SSO for enterprise customers without ever reading libxmlsec or understanding XML signature wrapping attacks—and what's the realistic migration path to OIDC when customers still demand SAML?

Top