Trail of Bits Blog
Follow
SAML: A fractal of bad design
The Security Assertion Markup Language (SAML) authentication protocol, born from academia and corporate IT, is now outdated. SAML was developed in 2002 by a committee to enable single sign-on (SSO) for the growing number of web services. It is built upon XML, a complex markup language, which contributes to its inherent security weaknesses and implementation difficulties. The protocol's design involved merging multiple existing specifications, resulting in a "kitchen-sink" approach. Despite its widespread adoption by major SSO providers, SAML has faced significant security vulnerabilities.XML signature wrapping and other related attacks have plagued SAML implementations for years, demonstrating its fragility. The complexity of XML itself, with its numerous features, introduces a large attack surface. Canonicalization, a process to normalize XML for consistent signature verification, has been a source of numerous security flaws. Enveloped signatures, where the signature is embedded within the data it signs, also create implementation challenges and vulnerabilities.Furthermore, SAML's design includes many features rarely used in modern implementations, adding unnecessary complexity. The protocol has also ossified, failing to adapt to modern internet infrastructure like HTTPS, which handles encryption and trust at the transport layer. Unlike OpenID Connect (OIDC), which evolved organically to address specific needs, SAML was largely designed upfront, lacking the agility of newer protocols. These factors point to SAML being a "fractal of bad design" that should be deprecated in favor of modern alternatives like OIDC.