Home / Companies / GitHub / Blog / Post Details
Content Deep Dive

Inside GitHub: How we hardened our SAML implementation

Blog post from GitHub

Post Details
Company
Date Published
Author
Greg Ose, Taylor Reis
Word Count
4,044
Company Posts That Month
24
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitHub has revisited its approach to integrating SAML (Security Assertion Markup Language) for enterprise authentication, originally introduced in 2014, due to its security complexities and vulnerabilities. Initially using a proprietary implementation, GitHub decided to transition to the community-supported ruby-saml library, which is actively maintained and offers improved security responses. To ensure a smooth transition, GitHub conducted rigorous testing, including A/B testing with their open-source tool Scientist, and collaborated with security researchers to address identified vulnerabilities. They also refined their SAML schema to minimize attack surfaces and implemented a dual-parsing strategy that uses both the new and old libraries for enhanced security, thus reducing the risk of new vulnerabilities slipping through. This approach not only improves GitHub's SAML implementation but also serves as a blueprint for managing complex and risky codebases.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Observability 2 1,696 379 123 -20%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.