security1 publisher
Trail of Bits traces SAML's insecurity to the XML signature layer underlying most fielded implementations
SAML's security rests on XML signature validation, and most fielded implementations hand that job to libxmlsec. Trail of Bits says that dependency is the reason to deprecate the protocol and move SSO to OpenID Connect.
Publishers:blog.trailofbits.com
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+30
- Incentives60
- Confidence55