Why do you use SAML instead of OIDC?
52
12
3
160
I can’t wait for something better than OIDC to be introduced. - Poor user experience - Poor developer experience: “just use a library to hide all the complexity” doesn’t work, you have to understand the underlying protocol to ensure the library is used correctly
1
7
- Having a SSO authentication form as a web page instead of a special OS window facilitates various phishing attempts
1
6
Replying to @ckarras @quorralyne
hardware authenticators like Yubikey/FaceID/TouchID solve the phishing problem with OIDC at least, but I'm expecting we're going to see some interesting OS-facilitated login flows in the near future

Jul 22, 2022 · 5:16 PM UTC