SAML: Why the 20-Year-Old Auth Protocol Needs to Die

Original: SAML: A fractal of bad design

Why This Matters

SAML underpins enterprise SSO for millions of users; its structural flaws mean authentication risk is industry-wide.

Security firm Trail of Bits argues that SAML, the XML-based authentication protocol created by OASIS committee in 2002, is broken by design. Built on top of deeply flawed XML signature validation and wrapped around a gnarly C codebase, SAML's complexity has made it a persistent source of vulnerabilities across enterprise SSO deployments. The firm calls for migration to OpenID Connect (OIDC).

Trail of Bits researcher Matt Schwager has published a detailed takedown of SAML (Security Assertion Markup Language), the protocol still powering enterprise single sign-on at companies worldwide. The core argument: SAML isn't just buggy in places — its fundamental architecture is unsound.

SAML was born in 2002 when OASIS jammed four separate XML-based security protocols together — S2ML, AuthXML, X-TASS, and ITML — into one spec via committee. The result was predictably bloated. Universities were early adopters (Yale's CAS, Internet2's Shibboleth), and when SaaS exploded in the late 2000s, commercial identity providers like Ping Identity (2002), Okta (2009), and OneLogin (2009) built entire businesses on top of it.

The deeper problem, as security researcher Thomas Ptacek put it in 2023: 'SAML is built on a foundation of sand, bone dust, and ash; it works… if you assume XML signature validation is reliable.' It isn't. XML canonicalization, enveloped signatures, and the sheer surface area of the spec have produced a category of vulnerabilities that keep recurring in real-world implementations. Most deployments quietly wrap libxmlsec, a C library that few people audit closely.

Schwager traces how the security research community has been slowly dismantling SAML's credibility over time, and argues that ossification — the protocol being too entrenched to fix properly — makes patching futile. His conclusion: deprecate SAML and move to OIDC.

Source

blog.trailofbits.com — Read original →