A software engineer discovered 580 CVEs across 16 deployments at 4am after building a custom infrastructure stack with homegrown orchestration, container registry, identity provider, and CI/CD pipeline. Using Software Bill of Materials generation and the Provenance vulnerability scanning platform, a critical flaw in a transitive dependency was automatically detected and flagged, triggering an alert that woke the engineer to address the issue.
SAML, an XML-based authentication protocol created in 2002 by committee, became the foundation of the single sign-on industry but is now considered overly complex and insecure due to flawed XML signature validation. The article traces SAML's origins in academia and corporate IT, its widespread adoption by companies like Okta and Ping Identity, and argues for its deprecation in favor of modern alternatives like OpenID Connect.
SAML, created in 2002 by OASIS as an XML-based authentication protocol, became foundational to the single sign-on industry but is now criticized for excessive complexity built on unreliable XML signature validation. The article argues SAML should be deprecated in favor of modern alternatives like OpenID Connect, tracing its origins in academic institutions and corporate IT adoption through the 2000s and beyond.