Trail of Bits urges SAML deprecation, OIDC migration
Trail of Bits published an architectural critique detailing why SAML's reliance on XML canonicalization and enveloped signatures creates intractable security vulnerabilities like signature wrapping attacks. The firm urges organizations and identity providers to retire the 25-year-old protocol and migrate to OpenID Connect.
SAML is enterprise security's ultimate sunk-cost fallacy, surviving on legacy inertia despite decades of unfixable XML parser differentials and signature vulnerabilities.
- –Enveloped signatures are structurally flawed because inserting signatures into the payload being signed makes canonicalization and signature verification deeply fragile.
- –OpenID Connect (OIDC) fixes the foundation by using detached signatures and delegating transport encryption to standard HTTPS rather than creating complex XML abstractions.
- –Cloud-native companies like Tailscale and Fly.io prove modern vendors can successfully hold the line on OIDC-only authentication without caving to enterprise SAML demands.
- –While service providers can adopt OIDC relatively quickly, identity providers face a grueling multi-year migration roadmap across entrenched enterprise customer bases.
DISCOVERED
1h ago
2026-09-22
PUBLISHED
3h ago
2026-09-22
RELEVANCE
AUTHOR
aray07