Skip to content
Artwork for CyberWire Daily
CyberWire Daily · Mar 24, 2018 · 19 min

Code comments cause SAML conundrum. [Research Saturday]

Researchers at Duo Security recently unearthed a new vulnerability class that affects SAML-based single sign-on (SSO) systems. This vulnerability can allow an attacker with authenticated access to trick SAML systems into authenticating as a different user without knowledge of the victim user’s password. Kelby Ludwig is a Senior Application Security Engineer at Duo security, and he takes us through his discoveries. Learn more about your ad choices. Visit megaphone.fm/adchoices

0:00-19:02

transcript

No transcript — this publisher did not publish one.

show notes

Researchers at Duo Security recently unearthed a new vulnerability class that affects SAML-based single sign-on (SSO) systems. This vulnerability can allow an attacker with authenticated access to trick SAML systems into authenticating as a different user without knowledge of the victim user’s password.

Kelby Ludwig is a Senior Application Security Engineer at Duo security, and he takes us through his discoveries. 

Learn more about your ad choices. Visit megaphone.fm/adchoices

links2