HNHacker News
TopNewBestAskShowJobs

adeinega

12 karma · joined July 22, 2024

submissionscomments
adeinega··on A Gentle Introduction to SAML
The beauty of this spec is that it defines a set of basic components to build multilateral federations between various types of entities (without a need to rely on Web PKI + of course, the types of these entities are limited by the imagination only). Regardless of what's going to happen and what isn't going to happen to existing SAML multilateral federations, I think this this specification might begin to be adopted for various other use cases.

It's worth mentioning, the spec was also written by people who aren't new to anything from that, they were already deeply involved in SAML multilateral federations.

adeinega··on A Gentle Introduction to SAML
I'd love to read about that more if you can share links explaining those details.

Whatever you've described sounds more like internal problems / challenges of their own implementations than anything else... especially the OpenID Connect as a delegated authentication protocol itself.

adeinega··on A Gentle Introduction to SAML
https://docs.aws.amazon.com/cognito/latest/developerguide/ex... tells me they support these IDPs 1. Facebook 2. Login with Amazon 3. Google 4. Sign in with Apple 5. Open ID Connect providers, and finally 6. SAML identity providers

If we look a bit closer, we notice that the first four use OpenID Connect under the hood. These names are fancy names for OpenID Connect with a little bit of something extra on top from Apple, Google, and so forth.

adeinega··on A Gentle Introduction to SAML
Where do they say that?
adeinega··on A Gentle Introduction to SAML
"SAML isn't a recipient for innovations" or something along this line was once said by Vittorio Bertocci... it's hard to add much to it.

OpenID Connect is a core for many new specs in the space, "OpenID for Verifiable Presentations" and "OpenID for Verifiable Credentials" just to name a few.

Any new company choosing one vs another, I suggest to take into account this aspect.

adeinega··on A Gentle Introduction to SAML
I second this.
adeinega··on A Gentle Introduction to SAML
Login.gov is pretty open about its preferences :)

We strongly recommend choosing OpenID Connect (OIDC) over SAML due to its modern, API-centric design and support for native mobile applications.

https://developers.login.gov/saml/getting-started/

adeinega··on A Gentle Introduction to SAML
I hope there will be some changes on that soon, have a look at https://openid.net/specs/openid-federation-1_0.html.