|
|
|
|
|
by tptacek
251 days ago
|
|
SAML is awful, maybe the worst cryptographic protocol ever devised, and we won't implement it unless we absolutely have to. OIDC is the future. I'm not exaggerating; you can use the search bar and find longer comments from me on SAML and XMLDSIG. You might just as well ask when we're going to implement DNSSEC. |
|
Here is a major vulnerability we disclosed earlier this year:
https://workos.com/blog/samlstorm