logoalt Hacker News

ocdtrekkietoday at 7:33 PM7 repliesview on HN

Eh, if you don't have SAML support, I can find a product that does. Not a problem. \o/

(Or to be more clear, it is mostly unacceptable for an enterprise product to have opinionated decisions about what authentication it works with. You either work with what we use or you are not viable as a product for our need. It's kinda simple. I would expect someone whose authentication was OIDC-based to be similarly dismissive if you told them you only would do SAML.)


Replies

eximiustoday at 7:54 PM

This is only a reasonable stance at the very surface level.

1. "You either work with what we use" - so whatever organization you represent isn't capable of evaluating and shifting to more secure technologies?

2. "it is mostly unacceptable for an enterprise product to have opinionated decisions about what authentication it works with" - you think companies that care about security should not care about integrating with flawed protocols?

A potential customer making bad choices does not obligate a business to make bad choices for their business.

show 2 replies
jeltztoday at 7:46 PM

That mindset is indicative of security theatre to me. But as security theatre is common in entrprise IT that does not surprise me.

show 2 replies
iamjake648today at 8:10 PM

Realistically, what modern IdP supports SAML but not OIDC though? To me, it seems like more of a case of 'I know and am comfortable with SAML, why learn something new?'.

clhodapptoday at 8:02 PM

Honestly, it's an addressable market versus development cost question... How many clients will you lose if you support OIDC but not SAML? Does the delta justify carrying a SAML implementation? If so, do it. But the post is still correct that SAML is a fractal of bad design either way. And it's good to say this openly, and to run this calculus each time you are considering a new SAML implementation.

badgersnaketoday at 8:27 PM

We took that exact stance, and it’s largely been a success. Most people asking for SAML can actually do OIDC and are happy to do so.

TZubiritoday at 9:01 PM

It's a matter of perspective yes.

If you are a vendor, you should have SAML support unless you are early (and can only support 1 standard), or you are highly opinionated.

If you are a consumer instead, you will only be using one standard, so you HAVE to chose 1 and not the others.

tomjen3today at 7:59 PM

You use Entra. Entra can do jwt’s.

Saml is just not reasonable in our modern security environment.

show 1 reply