HeadlinesBriefing favicon HeadlinesBriefing.com

SAML: A Fractal of Bad Design

Hacker News •
×

Born out of academia and raised in corporate IT departments, the Security Assertion Markup Language (SAML) authentication protocol continues to be a staple in these organizations. However, it’s time for it to retire. With the rise of software-as-a-service (SaaS) companies in the late aughts, IT departments needed a way for users to authenticate to many new web services. SAML and the burgeoning single sign-on (SSO) industry fulfilled this need. However, SAML is being crushed under the weight of its own complexity. It’s time to deprecate it and move on to modern alternatives like OpenID Connect (OIDC).

SAML 101: What’s insidious about SAML is that it really is mostly straightforward to understand, but it’s built on a foundation of sand, bone dust, and ash; it works … if you assume XML signature validation is reliable. But XML signature validation is deeply cursed, and is so complicated that most fielded SAML implementations are wrapping libxmlsec, a gnarly C codebase nobody reads.— Thomas Ptacek, 2023

SAML was created in 2002 by the Organization for the Advancement of Structured Information Standards (OASIS) Security Services Technical Committee (SSTC). XML, despite having some redeeming qualities, is quite complex compared to newer alternatives like JSON. Further, a committee of subcommittees having meetings is a recipe for “kitchen-sink” protocol design. And sure enough, we’ve now jammed four (!) XML-based security protocols into one: Security Services Markup Language (S2ML) from Netegrity, AuthXML from Securant, XML Trust Assertion Service Specification (X-TASS) from VeriSign, and Information Technology Markup Language (ITML) from Jamcracker.

However, the desire for such a protocol was undeniable. As the internet shifted from Web 1.0 to Web 2.0, users and organizations needed an easy way to authenticate to many new web services. Academia was the biggest driver: Central Authentication Service (CAS) in 2002 at Yale, Shibboleth IdP in 2003 by Internet2, ADFS in 2003 by Microsoft, and simpleSAMLphp around 2007 by Uninett. All these authentication projects eventually supported SAML. Once this base layer was established, the commercial industry took it and ran toward a multibillion dollar industry. The SSO, identity, and authentication provider industry also started up: Ping Identity (2002), OneLogin (2009), Okta (2009), and Duo Security (2010). These companies were essentially built on the SAML protocol with the exception of Duo, who would introduce their first SSO product in 2015, which is where I come into the story. I worked on Duo’s first on-premises Access Gateway product (DAG), which was built on simpleSAMLphp and, obviously, the SAML protocol. It’s where I became intimately familiar with the SAML protocol and spent many years of my life digesting its lengthy specifications. I was there when Kelby Ludwig found the XML comment by...