conv.

All stories
SecurityActive today · day 3

Trail of Bits: SAML is a 'fractal of bad design,' time to deprecate it

Security firm argues the 24-year-old authentication protocol should be retired in favor of OpenID Connect due to design-by-committee complexity.

What to know

  • SAML, created in 2002 by merging four XML security protocols, has become a security liability due to its complexity and XML-based architecture, according to Trail of Bits.
  • A documented pattern of vulnerabilities—from canonicalization flaws (2018) to GitHub Enterprise auth bypasses (2025)—traces back to SAML's foundational design choices.
  • Trail of Bits advocates for deprecating SAML in favor of OpenID Connect (OIDC), a simpler modern alternative.

Trail of Bits Security research firmThomas Ptacek Security researcher (quoted 2023)OASIS Security Services Technical Committee Standards body

Trail of Bits: SAML is a 'fractal of bad design,' time to deprecate it
blog.trailofbits.com

How it unfolded 1 development · click the chart to see its coverage articlesposts

Peak 4 pieces in one hour at Sep 22, 4 PM; 31 pieces over 3 days (2 articles · 7 posts · 22 comments) Sep 21, 7 AM — 1 piece · 1 post — Mastodon 1Sep 21, 8 AM — quietSep 21, 9 AM — quietSep 21, 10 AM — quietSep 21, 11 AM — 1 piece · 1 post — Hacker News 1Sep 21, 12 PM — quietSep 21, 1 PM — quietSep 21, 2 PM — quietSep 21, 3 PM — quietSep 21, 4 PM — quietSep 21, 5 PM — quietSep 21, 6 PM — quietSep 21, 7 PM — quietSep 21, 8 PM — quietSep 21, 9 PM — quietSep 21, 10 PM — quietSep 21, 11 PM — quietSep 22, 12 AM — quietSep 22, 1 AM — quietSep 22, 2 AM — quietSep 22, 3 AM — quietSep 22, 4 AM — quietSep 22, 5 AM — quietSep 22, 6 AM — quietSep 22, 7 AM — quietSep 22, 8 AM — quietSep 22, 9 AM — quietSep 22, 10 AM — quietSep 22, 11 AM — quietSep 22, 12 PM — quietSep 22, 1 PM — quietSep 22, 2 PM — 3 pieces · 2 articles · 1 post — Newswires 2, Hacker News 1Sep 22, 3 PM — 1 piece · 1 post — Mastodon 1Sep 22, 4 PM — 4 pieces · 4 comments — Hacker News 4Sep 22, 5 PM — 2 pieces · 2 comments — Hacker News 2Sep 22, 6 PM — 3 pieces · 1 post · 2 comments — Hacker News 2, Mastodon 1Sep 22, 7 PM — 2 pieces · 2 comments — Hacker News 2Sep 22, 8 PM — quietSep 22, 9 PM — 1 piece · 1 comment — Hacker News 1Sep 22, 10 PM — quietSep 22, 11 PM — 1 piece · 1 comment — Hacker News 1Yesterday, 12 AM — 2 pieces · 2 comments — Hacker News 2Yesterday, 1 AM — 1 piece · 1 post — Mastodon 1Yesterday, 2 AM — 1 piece · 1 comment — Hacker News 1Yesterday, 3 AM — 1 piece · 1 comment — Hacker News 1Yesterday, 4 AM — quietYesterday, 5 AM — quietYesterday, 6 AM — 1 piece · 1 post — Lobsters 1Yesterday, 7 AM — 1 piece · 1 comment — Hacker News 1Yesterday, 8 AM — 1 piece · 1 comment — Hacker News 1Yesterday, 9 AM — 1 piece · 1 comment — Hacker News 1Yesterday, 10 AM — 1 piece · 1 comment — Hacker News 1Yesterday, 11 AM — quietYesterday, 12 PM — 1 piece · 1 comment — Hacker News 1Yesterday, 1 PM — quietYesterday, 2 PM — 1 piece · 1 comment — Hacker News 1Yesterday, 3 PM — quietYesterday, 4 PM — quietYesterday, 5 PM — quietYesterday, 6 PM — quietYesterday, 7 PM — quietYesterday, 8 PM — quietYesterday, 9 PM — quietYesterday, 10 PM — quietYesterday, 11 PM — quietToday, 12 AM — quiet 1
Sep 22yesterdaynow · 1:01 AM ET
  1. 1

    Trail of Bits publishes argument for SAML deprecation

    Security firm Trail of Bits publishes an analysis titled 'SAML: A Fractal of Bad Design' arguing that SAML is 'being crushed under the weight of its own complexity' and should be deprecated in favor of OpenID Connect (OIDC). The post examines SAML's design-by-committee origins, its progression through academic and corporate environments, and the security vulnerabilities that have resulted from its XML-based architecture.

    “SAML is being crushed under the weight of its own complexity. It's time to deprecate it and move on to modern alternatives like OpenID Connect (OIDC).”
    — Trail of Bits
    1. first by HN Best, 1d ago · also HN Frontpage

    • It's called design by committee. It's when you get everyone in a room and nobody can make a tradeoff because it would hurt someone else's pet use case, so you don't actually design anything at all, just build a framework within which a design can exist.Anyone who has used Wireguard and OpenVPN will spot the difference. OpenVPN is the…

      pocksuppetHacker News1d agoview on Hacker News ↗
    2 more of the top 3 · 26 posts in this stretch
    • trailofbits@infosec.exchange

      SAML was created in 2002 by merging four rival XML security protocols into one spec. That design still generates vulnerabilities: a canonicalization flaw via XML comments in 2018, XML round-trip bugs in Go's stdlib in 2020, a GitHub Enterprise SAML auth bypass in 2025, and more. Matt Schwager breaks down 5 design flaws behind the pattern and makes…

      trailofbits@infosec.exchangeMastodon2d agoview on Mastodon ↗
    • Re: canonicalization: design things to not need it, so don't bother with it. Relying parties need to received the blob of whatever (XML, JSON, DER, PB -- don't care or decode till the signature is validated), validate the signature over the exact blob you've received, then decode. This means you need the signing key's algorithm to be identifiable…

      cryptonectorHacker News1d agoview on Hacker News ↗
    all of them →
  2. background

    OASIS creates SAML by merging four XML security protocols — The Organization for the Advancement of Structured Information Standards (OASIS) Security Services Technical Committee creates SAML as an XML-based markup language for security assertions, combining four separate XML-based security protocols into a single specification.

What people are saying 21 voices from 2 sites · best of 26 · verbatim