logoalt Hacker News

stousettoday at 9:44 PM1 replyview on HN

I saw multiple implementations that looked for a signature, verified it, then just trusted the document as a whole rather than only the part that was signed. So as long as you had any signed SAML doc, you could provide an attention of your choosing and just bundle the signed one somewhere arbitrary inside of it.


Replies

tptacektoday at 9:47 PM

It really probably is the worst security specification ever written.

show 2 replies