
CyberWire Daily
Code comments cause SAML conundrum. [Research Saturday]
Mar 24, 2018 · 19 min · Season 2 · Episode 28
0:00-19:02
Streams straight from the publisher. podnod never proxies or re-hosts episode audio.
Researchers at Duo Security recently unearthed a new vulnerability class that affects SAML-based single sign-on (SSO) systems. This vulnerability can allow an attacker with authenticated access to trick SAML systems into authenticating as a different user without knowledge of the victim user’s password.
Kelby Ludwig is a Senior Application Security Engineer at Duo security, and he takes us through his discoveries.
through his discoveries
duo.com