Skip to content
Tech News
← Back to articles

Security researchers argue SAML authentication protocol should be retired for OpenID Connect

read original more articles
GoKawiil Brief

A security industry blog post traces SAML's origins as a 2002 OASIS committee standard built on XML, arguing it powered the early single sign-on industry but has since become overly complex and fragile. The piece, citing security researcher Thomas Ptacek, contends SAML's reliance on XML signature validation makes real-world implementations difficult to secure, and calls for organizations to move to newer alternatives like OpenID Connect (OIDC).

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

If widely shared, this critique could accelerate enterprise IT departments' migration away from SAML toward OIDC, a shift that vendors of identity and SSO products may need to prioritize. The argument suggests that legacy protocols burdened by complex cryptographic validation, like XML signature checking, pose ongoing security risks that are hard to fully mitigate through implementation fixes alone.

Key Takeaways

Source: blog.trailofbits.com — Matt Schwager, 2026-09-22

Published there as: “SAML: A Fractal of Bad Design”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.