Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah, it'd much appreciated if the author explained that a bit more in the "why is saml insecure?" section


He literally does just that in the very next section; “Why is signing computed values dangerous?”


Really the only complaint I have about the article is this separate heading was unnecessary, and signaled to people who read fast with a short attention span might take that short section as “author assumed knowledge not in evidence”/“I’m not the intended audience”.


I assume he was being sarcastic




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: