Why do you use SAML instead of OIDC?
52
12
3
160
Because Facebook authentication is forbidden for financial application, Facebook use OIDC, so OIDC is forbidden. I had this argument few years ago.
2
5
GIF
Wait... what? You don't have to use social auth at all.
1
2
Same protocol, same risk (sic). And moreover OAuth2 is not secure because it require TLS. Happy to have fought all this false assertions , but we still have SAML when connecting to old SaaS.
2
1
that's...wrong and also just a weird thing to say. There's also FAPI which is a secure profile of OAuth and OpenID Connect.

Jul 22, 2022 · 5:06 PM UTC

1
1
Replying to @aaronpk @quorralyne
I agree, completely wrong, but so easy to to use for avoiding to move forward.
1