SAML: A fractal of bad design
Summary
Matt Schwager critiques SAML as a fractal of bad design, tracing its XML-based foundations, canonicalization and enveloped signature issues, and argues for its deprecation in favor of OpenID Connect (OIDC). The post recounts SAML's origins, the lineage of XSW attacks, and a practical path for SPs and IdPs to migrate to modern authentication methods.