On Breaking SAML

Cantor, Scott cantor.2 at osu.edu
Fri Aug 10 10:33:11 EDT 2012


On 8/10/12 9:58 AM, "Ian Young" <ian at iay.org.uk> wrote:
>
>This isn't news, but the formal publication of the wrapping attack that
>was dealt with in Shibboleth and other software in July of last year.[1]
>
>Publication cycles for papers in this area can be pretty extended, but
>these particular researchers have been in touch with various people
>involved with implementations for some time.

And continue to be, although most of their work these days has been in
dismantling XML Encryption.

I will note, since this is the dev list, that our biggest source of
problems in this area has been bugs in the XML parsers we use, and we've
been very disappointed with their refusal to, well, care. Sign of the
times, I guess. I definitely would not have used Xerces if I were starting
the project today, although I'm not sure on the Java side what good
alternatives exist.

It's one thing to get something wrong, particularly where specs are vague,
but it's another to be deliberately obstinate about fixing obvious flaws.

-- Scott



More information about the dev mailing list