Skip to main content

Search complete. 94 mentions across 42 episodes found for "SAML".

Sep 15, 2026

Andy RahnHOST
26:56
Yeah.
Charles ThomasGUEST
26:56
And the first iteration of the artifact that I built for our CEO for her emails was a full-fledged email management software with like SAML 2.0 integration and like a Kanban board and like all this crazy stuff.
Charles ThomasGUEST
27:13
And she looked at it and she's like, "I don't know how to use this.
Charles ThomasGUEST
27:16
This is too complex for me." And I swooped in and I said, "Look, man, this is...
Paul Klein IVHOST
39:47
Like the logged in web is where agentic identity needs to be solved, but there isn't a protocol that we can bolt on top of.
Paul Klein IVHOST
39:53
There's like SSO and, and SAML and like OAuth that kind of can help here, but it seems like agents are going to try and access services on behalf of people.
Paul Klein IVHOST
40:02
And maybe, once again, this goes back to how you and I have different views here or different beliefs.
Paul Klein IVHOST
40:06
Like I might believe that I think my agent should be a delegate of me because I probably have like a limited scope of access.
Ernie PrescottHOST
6:52
Its entire existence is dedicated to verifying who you are.
JoséeHOST
6:55
And it does that using modern web protocols, right? OIBC, SAMLNL, OAuth 2.0.
JoséeHOST
7:00
But what do those actually do in plain English? Because we throw around acronyms like OAuth, but architects need to really understand the mechanism.
Ernie PrescottHOST
7:07
Think of it like a bouncer at a highly secure club.
Marc LaliberteHOST
23:09
Um, so basically they pointed to their third party marketing email provider, Brevo, as the source of the issue, and Brevo later put out a statement with some additional information on what happened.
Marc LaliberteHOST
23:20
They said attackers exploited a flaw in how they handle SAML single sign-on to gain access to 138 different accounts, 6 of which were used to send phishing emails, and 43 of which had their contacts harvested out of it.
Marc LaliberteHOST
23:35
And basically how the attackers got in is they created their own Brevo account and set up single sign-on to a SAML identity provider.
Marc LaliberteHOST
23:43
They then invited legitimate Brevo users in other accounts into their tenant.
Marc LaliberteHOST
23:50
If those Brevo users accepted the invite, the, uh, the attacker could use SAML single sign-on from their IDP that they controlled to log in as that other user.
Marc LaliberteHOST
24:01
Where the issue was is that should have let them log in as that user in their tenant, the attacker's tenant.
Marc LaliberteHOST
24:07
But due to some scoping issues, it allowed them to log in as that user in any tenant that that user had access to.
speaker_0NARRATOR
2:59
And finally, for today.
speaker_0NARRATOR
3:01
Citrix Netscaler ADC and Gateway are facing CVE-2026-19490, a critical SAML authentication bypass scored CVSS 9.3 that can be triggered by a single unauthenticated request.
speaker_0NARRATOR
3:16
Security researchers say the impact varies by configuration, ranging from a pre-authentication crash to an internal network proxy, and in some cases, root on the appliance if management credentials are exposed.
speaker_0NARRATOR
3:30
Defenders are being urged to patch to 13.1.63.2.1 or 14.1.73.3.2 or later, or migrate off end-of-life branches and test each affected virtual server separately.
JoséeHOST
9:43
Yeah.
Ernie PrescottHOST
9:43
It doesn't understand modern OAuth or SAML tokens.
Ernie PrescottHOST
9:46
It doesn't even know what a web browser is.
Ernie PrescottHOST
9:49
It is hard-coded into its very binary to demand classic Active Directory schema, LD AP queries to look up user roles, and Kerberos or NTLM for authentication.

12 MINS LATER

Ernie PrescottHOST
21:53
Which is fantastic for security.
JoséeHOST
21:55
Mm.
Ernie PrescottHOST
21:55
But once the cloud identity provider verifies the user, it issues a modern session token like a SAML assertion or an OIDC token back to the gateway, and the legacy application still has no idea what to do with the SAML assertion.
JoséeHOST
22:08
Right.
Zach TerryHOST
8:46
It allows for really easy onboarding and offboarding.
Zach TerryHOST
8:50
So you can even use single sign-on and SAML or SCIM for automated user provisioning.
Zach TerryHOST
8:57
you can just essentially define who in your organization has access to cloud.
Zach TerryHOST
9:00
I mean, it's very much like a platform, right? You're adding people to have seats and then you're managing their usage, which is also really important because it gives you the ability to monitor that variable cost, that consumption, that usage across the entire team.
Lalit ChodaHOST
0:41
We've got someone who is a CEO at ExoniusX.
Lalit ChodaHOST
0:45
And then finally, someone that co-founded SAML many years ago.
Amir OfekGUEST
0:50
Just a small correction.
Amir OfekGUEST
0:51
I'm just going to duck now.
Eve MalerGUEST
1:13
I go? Hi, everybody.
Eve MalerGUEST
1:16
Eve Mailer.
Eve MalerGUEST
1:17
I guess the bookends of my identity career include helping to create SAML 26 years ago, Like, I want to say I'm sorry, but no.
Eve MalerGUEST
1:27
And most recently, I was the CTO of ForgeRock, and now I am a strategic advisor at VenFactory.
Andrew ChanthaphoneGUEST
21:44
To me, it says, if you're new to identity or even you're in the space, the fundamentals is the first part of it that a lot of people don't have is the fundamentals of identity.
Andrew ChanthaphoneGUEST
21:53
What is the different authorization models out there? What are the different authentication models out there? What, what are, what, what is SSO? What is SAML, right? What is OIDC? To be able to understand the lingo and talk to talk is your first part of it, because then once you understand what the actual join or move reliever or onboarding transfers offboarding process is.
Andrew ChanthaphoneGUEST
22:14
And to be able to explain to somebody easily, I joke about this, but I always tell my people is explain to you as if you're a two or six grader what this is, right? The better you can do that, the more that you know it in your head.
Andrew ChanthaphoneGUEST
22:26
And I always tell that to my mentees or people who offer, who pay for my services to get mentored is that's the first thing I do is I have them take the fundamentals.
David GoldschlagPANELIST
7:05
And if more agents can authenticate themselves in a standardized way, and the credentials that I need to issue are more standardized credentials, it means it's less work to support a bigger variety of things, okay? So I think that that's really critical.
David GoldschlagPANELIST
7:20
But I think at the end of the day, this business of converting from one identity to one access credential to different ones, that one, the world's just a messy place, okay, right? And that's just my job, okay, right? And so I think we do need to recognize that even in a world of SAML, okay, for instance, for users, you still need identity systems like ENTRE or OKTO or PING, because they're the ones that manage the policies and the real work, right, of deciding what to do, determining posture and risk, right, making an access decision, issuing a credential, that is still sort of above those standards, okay? So that's how I think about standards.
David GoldschlagPANELIST
8:03
Yeah, yeah, okay.
Niv GoldenbergPANELIST
8:05
I want to add to that and I think that the standards are really an alignment in terms of a framework for us as an industry and the way that we need to look and to make decisions.

32 more episodes mention SAML.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.