TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

SAML's signature problem: It's not you, it's XML

8 pointsby rdegges20 days ago

1 comment

rdegges20 days ago
The way XML digital signatures work is so weird. This routinely comes up year-after-year. When I was working at Okta this also resulted in a number of annoying breaches, including this one: <a href="https:&#x2F;&#x2F;developer.okta.com&#x2F;blog&#x2F;2018&#x2F;02&#x2F;27&#x2F;a-breakdown-of-the-new-saml-authentication-bypass-vulnerability" rel="nofollow">https:&#x2F;&#x2F;developer.okta.com&#x2F;blog&#x2F;2018&#x2F;02&#x2F;27&#x2F;a-breakdown-of-th...</a>