Live data from Hacker News

AWS Single Sign-On

aws.amazon.com

11–20 of 119 posts

Re: AWS Single Sign-On

#11
post #8
post #7

I tested this out just yesterday. It was fairly easy to set up - enable SSO, create a Directory Service, add a management EC2 instance, and you're pretty much up and running. You've got to set up your own Active Directory using Directory Services, which is $288USD/month minimum for two domain controllers. In order to have MFA for logging into the console (non-negotiable in my opinion), you have to configure your own…

Hmm how did you calculate the DC to be $288 for total of two? I believe you can use AD connector to connect to on-premise AD.

$288 comes from here: https://aws.amazon.com/directoryservice/pricing/

It looks like AD Connector is much less: https://aws.amazon.com/directoryservice/other-directories-pr...

Re: AWS Single Sign-On

#12
Wonder if and when we’ll see decent Excel/Word replacements from Amazon, perhaps coupled with a thin Linux distro. At that point you’d be able to completely do away with Microsoft in many organisations, and Amazon could simply gobble up those dollars. They’ve got enough money they could make it work.

Re: AWS Single Sign-On

#13

Wonder if and when we’ll see decent Excel/Word replacements from Amazon, perhaps coupled with a thin Linux distro. At that point you’d be able to completely do away with Microsoft in many organisations, and Amazon could simply gobble up those dollars. They’ve got enough money they could make it work.

Never. Can't happen. See, while it is true that 80% of the people only use 20% of the features but it is not the same 20%! The only viable Excel replacement would need to have the exact same functionality pile.

Re: AWS Single Sign-On

#14
While this will undoubtedly make a lot of people's lives easier, I'm a bit hesitant to use SAML just yet.

SAML is still relatively new, isn't very widely used (AFAICT), and I'm not sure how much security research has been done on the topic thus far.

To illustrate, just a few weeks ago there was "a new attack vector discovered that ... enables an attacker to create a ... forged SAML 'authentication object', and authenticate across every service that uses SAML 2.0 protocol ..." [0].

> In a golden SAML attack, attackers can gain access to any application that supports SAML authentication (e.g. Azure, AWS, vSphere, etc.) with any privileges they desire and be any user on the targeted application (even one that is non-existent in the application in some cases).

Vulnerabilities like this one really do give up the proverbial "keys to the kingdom" and provide an attacker with pretty much everything they need to really ruin your day.

Now, this particular attack isn't real practical as it requires things like the "token-signing private key". You don't need domain admin although you do need access to the ADFS account and if an attacker has access to that, well, you're probably already screwed (or well on your way). The point is that SAML is still shiny and new and there will almost certainly be additional flaws found in the future -- flaws which may very well compromise you completely.

It's certainly a nice solution to a big problem and, as I said, will make a lot of people's lives easier. I'm just not yet ready to trust it 100%.

Edit: To prevent a dozen more "2005!?" comments, I mentioned this in a reply:

> True, but it's still relatively new to most people, similar to how IPv6 has been around for a few decades but is still "new" to many.

The spec has been around for a while. Common deployments -- outside of AWS, MS, RH, etc., haven't (unless I've just been unaware of them).

[0]: https://www.cyberark.com/threat-research-blog/golden-saml-ne...

Re: AWS Single Sign-On

#15

While this will undoubtedly make a lot of people's lives easier, I'm a bit hesitant to use SAML just yet. SAML is still relatively new, isn't very widely used (AFAICT), and I'm not sure how much security research has been done on the topic thus far. To illustrate, just a few weeks ago there was "a new attack vector discovered that ... enables an attacker to create a ... forged SAML 'authentication object', and authen…

You might want to double check those facts. There are probably billions of SAML users.

Any significant O365 implementation is using SAML. Any SaaS that allows enterprise login is using SAML. If you do business with Spectrum, you are using SAML when you login. If you interact with most government agencies, you are using SAML.

That’s not to say that it does not have risk, but adoption is not an issue!

Re: AWS Single Sign-On

#16

While this will undoubtedly make a lot of people's lives easier, I'm a bit hesitant to use SAML just yet. SAML is still relatively new, isn't very widely used (AFAICT), and I'm not sure how much security research has been done on the topic thus far. To illustrate, just a few weeks ago there was "a new attack vector discovered that ... enables an attacker to create a ... forged SAML 'authentication object', and authen…

While there are a thousand reasons to hate SAML, your concerns are not accurate.

1. I guess "relatively new" is a vague term, but SAML v2.0 (the current version) was standardised in March 2005 - it's now 12.5 years old, I don't call that new.

2. SAML is very widely used in certain segments. Every SSO product supports SAML, including cloud vendors like Azure, Google and now AWS, and also specialist vendors like Okta and OneLogin. Within the dreaded "enterprise" space, SAML is absolutely the #1 SSO technology in play.

3. The golden SAML attack is a load of crap. It basically says "If you can get the private keys of an identity provider, then you can impersonate that identity provider". Yes, SAML relies on the confidentiality of the signing keys. That "attack" is the equivalent of saying Linux security is broken because if you have the root password you can modify any file.

Re: AWS Single Sign-On

#17

While this will undoubtedly make a lot of people's lives easier, I'm a bit hesitant to use SAML just yet. SAML is still relatively new, isn't very widely used (AFAICT), and I'm not sure how much security research has been done on the topic thus far. To illustrate, just a few weeks ago there was "a new attack vector discovered that ... enables an attacker to create a ... forged SAML 'authentication object', and authen…

SAML 2.0 was finalized in 2005, right? Not saying that means it doesn't have attack vectors, but "relatively new"?

Re: AWS Single Sign-On

#18

While this will undoubtedly make a lot of people's lives easier, I'm a bit hesitant to use SAML just yet. SAML is still relatively new, isn't very widely used (AFAICT), and I'm not sure how much security research has been done on the topic thus far. To illustrate, just a few weeks ago there was "a new attack vector discovered that ... enables an attacker to create a ... forged SAML 'authentication object', and authen…

New? 2.0 was ratified in 2005. It's very widely adopted in enterprises. All the big SSO vendors (onelogin, okta, auth0) suppprt it.

Re: AWS Single Sign-On

#19
post #16

While this will undoubtedly make a lot of people's lives easier, I'm a bit hesitant to use SAML just yet. SAML is still relatively new, isn't very widely used (AFAICT), and I'm not sure how much security research has been done on the topic thus far. To illustrate, just a few weeks ago there was "a new attack vector discovered that ... enables an attacker to create a ... forged SAML 'authentication object', and authen…

While there are a thousand reasons to hate SAML, your concerns are not accurate. 1. I guess "relatively new" is a vague term, but SAML v2.0 (the current version) was standardised in March 2005 - it's now 12.5 years old, I don't call that new . 2. SAML is very widely used in certain segments. Every SSO product supports SAML, including cloud vendors like Azure, Google and now AWS, and also specialist vendors like Okta…

> I guess "relatively new" is a vague term, but SAML v2.0 (the current version) was standardised in March 2005 - it's now 12.5 years old, I don't call that new.

True, but it's still relatively new to most people, similar to how IPv6 has been around for a few decades but is still "new" to many.

> SAML is very widely used in certain segments.

Perhaps but it's only been in the last few years that I've been hearing about it, mostly WRT the cloud vendors (AWS, specifically).

> The golden SAML attack is a load of crap.

Yeah, I think I mentioned it isn't very practical. To me, though, this seems like just the unexpected kind of thing that, some day down the road, is going to come back and bite you in the ass. That is, some major issue in some piece of infrastructure that is overlooked, forgotten about, or taken for granted (e.g. heartbleed or similar), that suddenly causes everybody to drop everything and react immediately to fix it.

Post reply on HN