A protocol built on XML signatures
Trail of Bits argues SAML should be deprecated: it is comprehensible on its own terms and rests on a signature-validation layer that has defeated most implementations.
3 minSmart Contract Audits
Trail of Bits has published an argument for retiring SAML, the authentication protocol that still underpins a large share of corporate single sign-on. The case is not that the protocol is misunderstood but that it is collapsing under its own complexity.
The history explains the shape of the problem. SAML emerged from academia, was adopted by corporate IT departments, and became essential when software-as-a-service arrived in the late 2000s and organisations suddenly needed their staff to authenticate to dozens of external web services. The single sign-on industry grew around it.
The structural criticism is precise and the post quotes it directly: what is insidious about SAML is that it is mostly straightforward to understand, and it works — if you assume XML signature validation is reliable. That assumption is where the foundation gives way, because XML signature validation is sufficiently complicated that most fielded implementations end up wrapping it rather than getting it right.
This is a familiar shape to anyone who reads audit reports. The protocol logic is reviewable; the layer it delegates its security decision to is not, and a reviewer signing off on the former has not examined the latter. Complexity in a validation step is not a quality problem, it is an attack surface, and it has been mined steadily by the research community for years.
The recommended direction is OpenID Connect. The practical difficulty is that SAML integrations are not a technology choice inside one organisation but a matrix of bilateral configurations with vendors, each of which has to move — which is why a protocol can be widely understood to be finished and remain in production for another decade.
Retold from Trail of Bits. This is a summary in our own words; follow the link for the original reporting.