Trail of BitsTuesday · September 22, 2026FREE

SAML: A fractal of bad design

samlauthenticationoidcsecuritystandards

Trail of Bits published a post titled "SAML: A fractal of bad design," arguing that the Security Assertion Markup Language authentication protocol should be deprecated and replaced by modern alternatives such as OpenID Connect (OIDC). The post says SAML was created in 2002 by the Organization for the Advancement of Structured Information Standards (OASIS) Security Services Technical Committee (SSTC), and describes its origin as design-by-committee, quoting a SAML history source stating that four XML-based specifications were contributed to the SSTC: Security Services Markup Language (S2ML) from Netegrity, AuthXML from Securant, XML Trust Assertion Service Specification (X-TASS) from VeriSign, and Information Technology Markup Language (ITML) from Jamcracker. The post quotes Thomas Ptacek's 2023 remark that SAML "works … if you assume XML signature validation is reliable," but that XML signature validation is deeply cursed and complicated, with most fielded SAML implementations wrapping libxmlsec, described as a gnarly C codebase nobody reads. It attributes SAML's adoption to the shift from Web 1.0 to Web 2.0 and the rise of SaaS companies in the late aughts, when IT departments needed users to authenticate to many new web services. The post lists related authentication efforts: Central Authentication Service (CAS) in 2002 at Yale, Shibboleth IdP in 2003 by Internet2, a consortium of research universities, ADFS in 2003 by Microsoft, and simpleSAMLphp.

// why it matters

The post argues developers should move from SAML to newer protocols like OIDC, citing SAML's complexity and its reliance on XML signature validation.

Sources

Primary · Trail of Bits
▸ Read original at blog.trailofbits.com

Like this? Get the next digest.