+− THE DAILY DIFFdev & AI news
REVERT

SAML, under the hood: the signature inside the letter

SAML logs you into almost every work app, and its signature lives inside the XML it signs.

SAML logs you into almost every work app, and its signature lives inside the XML it signs. Under the hood: the login dance between app, browser and identity provider, what an assertion looks like, why canonicalization has to agree on every byte, and why the same bug class keeps coming back from 2012 to 2025. Prompted by Trail of Bits' "SAML: A fractal of bad design" (312 points on Hacker News).

Read the written edition (English) ↗

What this video covers

  • SAML: the login that signs itself from the inside
  • 2002: four XML formats, one committee, a whole industry
  • The login dance: app → identity provider → back through your browser
  • The assertion: the signature lives inside what it signs
  • Canonicalization: agree on every byte, or nobody logs in

Transcript

SAML: the login that signs itself from the inside

0:00 Saml is the XML that logs you into almost every work app you own, and its signature lives inside the document it signs, like a notary stapling his stamp inside the envelope he's sealing. Ten years after a committee wrote it, researchers tested fourteen Saml frameworks. Eleven fell. And this week a Trail of Bits post calling it a fractal of bad design hit the front page of Hacker News. In three minutes: how the login dance works, where the signature hides,

0:27 and why the fix everyone agrees on is a different protocol. This is The Daily Diff, under the hood.

2002: four XML formats, one committee, a whole industry

0:34 Two thousand two. A security committee at Oasis merges four vendor XML formats into one. Universities adopt it first, then Okta builds a company on it, the fastest a committee document ever turned into revenue. You open the app.

The login dance: app → identity provider → back through your browser

0:46 It has no idea who you are, so it bounces your browser to the identity provider, say your company's Okta. You log in there. Okta hands your browser a signed XML document that says who you are, and the browser posts it back.

The assertion: the signature lives inside what it signs

0:59 That document is the assertion. It names the user, and the signature sits inside it, pointing back at the assertion by its ID. And the whole thing rides through your browser, which is to say, through the user. To check it, the app

Canonicalization: agree on every byte, or nobody logs in

1:11 rebuilds the exact bytes that were signed. It cuts the signature back out, normalizes the whitespace and the attribute order, and hashes the result. That's canonicalization, and if the two sides disagree by a single byte, nobody logs in. A JSON web token does it differently. Header, payload and signature sit side by side with dots in between. Nothing to cut out first.

2012: the checker and the reader look at different elements

1:32 Here's the crack. The code that checks the signature and the code that reads the username are often two different pieces. In twenty twelve, a paper called On Breaking Saml showed you could move the signed assertion where the reader ignores it, and put a second one where it looks. Salesforce and Shibboleth were among the eleven that fell for it. In twenty eighteen, Duo showed that a comment inside a username could make some

2018 and 2025: two parsers, two different answers

1:55 libraries read only half the name, while the signature still checked out. In twenty twenty-five, GitHub found two XML parsers inside ruby Saml disagreeing about the same document. Same bug, new decade. Trail of Bits calls it a fractal, because every level you zoom into has the

Why it keeps breaking: a fractal of bad design

2:12 same flaw. It's built on XML, the signature is enveloped, and real logins use maybe a tenth of the spec. And the top reply on Hacker News comes from the buyer. If you don't have Saml support, I can find a product that does. Both are true, which is the problem. So, Monday. Ship OpenID Connect first, Fly and Tailscale sell to

Monday: OIDC first, a maintained library, strict shapes

2:31 enterprises without Saml at all. If a customer forces it, use a maintained library, keep it patched, and reject messages that don't look like what Okta or Google send. Never write your own signature check.

Verdict, under the hood: REVERT

2:43 Verdict, under the hood. Revert. Almost twenty-five years, one bug class that never dies, and the fix everyone agrees on is a different protocol. Last Saturday I took apart passkeys, so tell me what to open up next in the comments. And that's the diff for today. I'm Niko from Axrisi. Merge responsibly.

Sources

  1. Trail of Bits, "SAML: A fractal of bad design" (Matt Schwager, Sep 21, 2026)blog.trailofbits.com
  2. Hacker News threadnews.ycombinator.com
  3. Somorovsky et al., "On Breaking SAML: Be Whoever You Want to Be", USENIX Security 2012www.usenix.org
  4. Duo Labs, SAML vulnerabilities affecting multiple implementations (2018): https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations · CERT VU#475445www.kb.cert.org
  5. GitHub Security Lab, "Sign in as anyone: Bypassing SAML SSO authentication with parser differentials" (Mar 12, 2025)github.blog

Related videos