4 ms·
Lol, yeah, having SAML means putting XML parsing into critical security points. No thanks.
by bitexploder 2y ago
Lol, yeah, having SAML means putting XML parsing into critical security points. No thanks.
- robmccoll 2y agoEven better: XML signatures, which are very easy to get wrong in both signing and verification.
- bitexploder 2y agoYeah, it is a gross morass of pain and cruft and unclear implementation for devs.
- poincaredisk 2y agoIs it that different from parsing JSON? A honest question, what's the difference? Billion laughs attacks and similar?
- tptacek 2y agoIt's not just XML formatting; it's bizarro stuff like XML canonicalization and comments, and it's in a signature format. It really might be the worst mainstream cryptosystem in the entire industry.
- bitexploder 2y agoYeah, see the other replies in here. It is just a mess of ancient cruft and unclear implementation guidelines.
- Jerrrrrrry 2y agoA computer scientist would say they have identical parsing complexity, so not much. A computer programmer wouldn't even know where to begin, as the chesterton's fence had long been rejustified
- bitexploder 2y agoBut it’s not true in practice. Pure simple XML vs JSON sure. XML you deal with in SAML has tons of extra things like namespaces, canonicalization issues, etc. it is way more complex and has led to many security issues over the years.
- Jerrrrrrry 2y agoI had originally quoted "in theory, it's easy in practice. in practice, its easy in theory" But I thought scientist vs. programmer would be literally analogous and rivet more finches.