Back
Trail of Bits: SAML is a fractal of bad design — time to move to OIDC
SiTech AI Team2 წთ. საკითხავი

Trail of Bits: SAML is a fractal of bad design — time to move to OIDC

A new Trail of Bits analysis argues that SAML is being crushed under the weight of its own complexity and should be deprecated in favour of OpenID Connect. The post examines 25 years of history and five design flaws it calls fatal.

An analysis on the Trail of Bits blog argues that SAML (Security Assertion Markup Language) is being crushed under the weight of its own complexity and should give way to OpenID Connect (OIDC). The post follows the protocol from its committee origins in 2002 to the flaws still found in the field today.

A committee product that everyone adopted

SAML was created in 2002 by the OASIS Security Services Technical Committee, which merged four competing XML security protocols into one specification. Academia drove the early uptake — Yale's CAS, Internet2's Shibboleth IdP and Microsoft's ADFS — and commercial identity providers followed: Ping Identity (2002), OneLogin and Okta (2009), Duo Security (2010).

JWT and SAML signature formats compared

Cracks in the armour

The core problem is XML signature wrapping (XSW). Trail of Bits calls the 2012 USENIX paper "On Breaking SAML: Be Whoever You Want to Be" the godfather of the field: it moved theory into practice and produced an automated test for the flaw. More than a decade later XSW still turns up — including parser-differential bypasses described by GitHub and PortSwigger's 2025 research "SAML roulette" and "The Fragile Lock". SAML also inherits every classic XML bug class: XXE, entity expansion and DTD retrieval as SSRF.

XML canonicalization

Five flaws the author calls fatal

The post names five: building on XML, far more complex than JSON; canonicalization, where the SP and IdP must agree on a byte-exact representation or signatures fail — the root of the 2018 XML comment bypass and of most modern round-trip attacks; enveloped signatures, where the signature sits inside the data it signs; kitchen-sink design, since a real-world SAML exchange avoids roughly 90% of the specification; and ossification.

Ossification is the heaviest. OIDC assumes HTTP and a connected topology, while SAML is transport-independent and was shaped by an era of VPNs and network segmentation; Google's BeyondCorp model and zero-trust, both from 2014, inverted that assumption. SAML also missed the mobile, SPA and IoT waves, while OIDC grew organically through RFCs from OIDC 1.0 (2014) to PKCE for single-page apps (2026).

All roads lead to OIDC

For service providers the advice is blunt: support OIDC, abandon SAML; Thomas Ptacek notes that Fly.io and Tailscale have held the line. Identity providers face a longer road — a deprecation plan, no new SAML onboarding, equivalent OIDC configurations for existing customers and a sunset date. After a roughly 25-year run, the post concludes, SAML deserves thanks, but it is time to move on.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.