Security researchers argue SAML authentication protocol should be retired for OpenID Connect
A security industry blog post traces SAML's origins as a 2002 OASIS committee standard built on XML, arguing it powered the early single sign-on industry but has since become overly complex and fragile. The piece, citing security researcher Thomas Ptacek, contends SAML's reliance on XML signature validation makes real-world implementations difficult to secure, and calls for organizations to move to newer alternatives like OpenID Connect (OIDC).
GoKawiil's interpretation of the reporting above, not reported fact.
If widely shared, this critique could accelerate enterprise IT departments' migration away from SAML toward OIDC, a shift that vendors of identity and SSO products may need to prioritize. The argument suggests that legacy protocols burdened by complex cryptographic validation, like XML signature checking, pose ongoing security risks that are hard to fully mitigate through implementation fixes alone.
- SAML, created in 2002 by an OASIS committee, underpins much of today's enterprise single sign-on infrastructure.
- Critics say SAML's dependence on complex XML signature validation creates persistent security risks in real-world deployments.
- The post advocates replacing SAML with newer, simpler protocols such as OpenID Connect.
Source: blog.trailofbits.com — Matt Schwager, 2026-09-22
Published there as: “SAML: A Fractal of Bad Design”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.