Security researchers argue SAML authentication protocol should be retired for OpenID Connect
A security industry blog post traces SAML's origins as a 2002 OASIS committee standard built on XML, arguing it powered the early single sign-on industry but has since become overly complex and fragile. The piece, citing security researcher Thomas Ptacek, contends SAML's reliance on XML signature validation makes real-world implementations difficult to secure, and calls for organizations to move to newer alternatives like OpenID Connect (OIDC).