Sign in

Matthew Slowe

@fooflington.infosec.exchange.ap.brid.gy
32 followers 5 following 45 posts

𝚆𝚊𝚔𝚎𝚄𝚙: 𝚕𝚍𝚛 𝚛𝟶, 𝟶𝚡𝚌𝟶𝚏𝚏𝚎𝚎; 𝚋𝚕 𝚍𝚛𝚒𝚗𝚔; 𝚖𝚘𝚟 𝚙𝚌,𝚕𝚛; /* 𝚅𝚒𝚎𝚠𝚜 𝚊𝚛𝚎 𝚖𝚒𝚗𝚎 𝚗𝚘𝚝 𝚖𝚢 𝚎𝚖𝚙𝚕𝚘𝚢𝚎𝚛'𝚜. */ Working in IT […] 🌉 bridged from ⁂ infosec.exchange/@fooflington, follow @ap.brid.gy to interact

PostsRepliesMedia
Reposted by Matthew Slowe
Tim J @timtfj.mastodon.social.ap.brid.gy · 14h
Bring back þe letter þ. How can you þrow out þe only rune in your alphabet? Also bring back ð. But ðis time, except in very common words like þe which look nice þe oðer way round, don't treat ðem as interchangeable. Use ð for þe voiced one and þ for þe unvoiced one, like ðey do in Icelandic […]
mastodon.social
Original post on mastodon.social
111072
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 01/10/2026
Looking over the Amstel at Berlagebrug #amstel #amsterdam
000
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 30/09/2026
The Ringvaart at night #Amsterdam #nightphotography #canal #cityscape #ringvaart
Night view of a calm, straight canal reflecting streetlights. On the right side, a row of tall brick townhouses with lit windows lines the canal, with cars parked along the cobblestone bank and a small white and red boat moored in the foreground. On the left, a grassy park with trees and lampposts. Lights from buildings and cranes in the distance reflect in the dark water under a deep blue night sky.
010
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 30/09/2026
Sunset over Antwerp (on the train from London to Amsterdam yesterday) #sunset #antwerp #eurostar #crossborderrail
011
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 27/09/2026
A toadstool, spotted in the #Kent #Downs near #Challock #fungi #mushroom
Low-angle close-up of three large brown-capped mushrooms with thick stems growing in long green grass in a sunny field. The closest mushroom is in sharp focus, showing its yellow sponge underside, with trees and blue sky in the background.
001
Reposted by Matthew Slowe
Hacker Memes @i0null.infosec.exchange.ap.brid.gy · 14/09/2026
let this be your only doom-scroll this week
screenshot of the doom video game on imposed on an antiqued paper-scroll.
21241
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 17/09/2026
This week we took child1 to university. I was not prepared for the emotional turmoil this would provoke. It's not dissimilar to grief. Sharing here because if it can hit me randomly in the middle of the day, it might hit you or someone you know/work with. Check in with your friends/colleagues […]
infosec.exchange
Original post on infosec.exchange
111
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 09/09/2026
Half way up Beinn na Cro, in the Red Cuillins on the Isle of Skye looking south over Loch Slapin. In the distance is the Sleat Peninsula and, farther away, is the Isles of Rùm and Eigg. #scotland #highlands #skye #cuillins #torrin #strathaird #isleofskye
A wide aerial view of a sea inlet winding through green hills and low mountains under a dramatic cloudy sky. The water curves into the distance, with patches of shoreline, wetlands, and a small road tracing the landscape.
000
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 07/09/2026
RE: social.jpoesen.com/@jpoesen/1172292… I just don't understand how anyone in a position of power can conclude this is an ethical thing to do. Whether or not it's legal (and it arguably isn't), it's not ethical. #lg #privacy #ethics
social.jpoesen.com
002
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 02/09/2026
RE: infosec.exchange/@bontchev/11720238… This has _never_ happened to me
000
Reposted by Matthew Slowe
John Altringham @johnaltringham.mastodon.online.ap.brid.gy · 01/09/2026
Rubha Hunish, the northern tip of Skye. Synthetic walnut ink - behaves like the real thing but light stable and acid-free. The ink is still wet but I've been kicked back into the world. 75 x 20 cm. #Scotland #Skye #art #landscape #sketching
75cm wide ink sketch in walnut ink (warm brown) of a long coastal cliff from a narrow peninsula beneath it. The cliff of columnar basalt recedes to the distant horizon on both sides of the sketch.
0212
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 11/08/2026
I've been looking for a set of "smart scales" that can push data into my phone's local Health system (eg Apple Health or Google Health) without needing a cloud account … ie I don't want the data to leave my device. I don't mind the data traversing a third-party app so long as it stays local […]
infosec.exchange
Original post on infosec.exchange
142
Reposted by Matthew Slowe
Quixoticgeek @quixoticgeek.v.st.ap.brid.gy · 06/08/2026
The latest party political broadcast from Count Binface is an absolute banger. youtu.be/ujHphnnDaGg?
103
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 27/07/2026
Well today's #xkcd certainly maxes out the legacy-geek-o-meter xkcd.com/3277
xkcd.com
Forth
021
Reposted by Matthew Slowe
Coleen Walter @coleenwalter.mastodon.social.ap.brid.gy · 23/07/2026
This tortoise navigated rocks and other obstacles meant to keep him out of the Montezuma quail’s food. Nevertheless nothing will stand in the way of this tortoise getting snacks. Some of us may sympathize with the quail because we may have had roommates or […] [Original post on mastodon.social]
011
Reposted by Matthew Slowe
Tom Gauld @tomgauld.bsky.social · 26/07/2026
My latest books cartoon for @theguardian.com
Panel 1
Caption: With the windows open in the summer heat, a breeze blows through the punctuation factory, scattering newly-minted marks across the countryside.

Image: a small factory with windows open and punctuation marks coming out 

Panel 2
Caption: Confused locals find their conversations peppered with unexpected pauses and unwanted emphasis.

Image: Two people talking as punctuation marks float around them One says

This, is “very odd”

The other replies 

…(Indeed)*


Panel 3
Caption: Naturalists note that the effect is not limited to human communication. 

Image: A duck on a pond surrounded by punctuation marks says
Qu’ack?

Panel 4
Caption: Fortunately, a cloud of exclamation points drift into a district council meeting which proceeds with unusual efficiency 

Image: Councillors talk in a cloud of exclamation points
Something must be done!!  !
Close the windows! !!
Install air conditioning! !!
Immediately!!! !
281274423
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 21/07/2026
Today's bugbear(s): 1. Specifications which define a thing which can have more than one value but don't define how the ordering of that value should be interpreted 2. Software that doesn't understand "short form" IPv4 CIDR addresses (eg. `172.16/12`)
100
Reposted by Matthew Slowe
Maartje @maartje.dev · 20/07/2026
I looove failed digitalisation enshittification. If a hotel has staff pushing me to the self check in… then fails recognising I have a company contract, the employee working out a reservation number to then end on it recognising it was pre-paid by company to just result in a (btw way faster) […]
blahaj.social
Original post on blahaj.social
142
Reposted by Matthew Slowe
Gary @witewulf.cyberplace.social.ap.brid.gy · 15/07/2026
RE: infosec.exchange/@josephcox/1169243… 🫩 <- this is my surprised face
infosec.exchange
001
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 10/07/2026
RE: en.osm.town/@thibaultmol/1167990057… There's something awfully pleasing about this "remix" of the #BBCnews countdown with #trains
en.osm.town
000
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 10/06/2026
In one of the #TNC26 talks (part of the Rebooting the Old Reliables session) one of the speakers mentioned an article about "Rewilding the internet". It's been around for a few years but is a fascinating and inspiring read… www.noemamag.com/we-need-to-rewild-… #rewilding […]
infosec.exchange
Original post on infosec.exchange
003
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 30/04/2026
copy.fail Local Privilege Escalation in every Linux kernel since 2017 Hopefully no one is sitting on a low-privilege RCE... #linux #security #rce #lpe #cve #CVE202631431
copy.fail
Copy Fail — 732 Bytes to Root
CVE-2026-31431. 100% Reliable Linux LPE — no race, no per-distro offsets, page-cache write that bypasses on-disk file-integrity tools and crosses containers. Found by Xint Code.
012
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 16/04/2026
RE: ec.social-network.europa.eu/@EUComm… Encouraging (and providing accessibly ways for) students to experience other cultures and ways of teaching & learning is a fantastic tool for broadening horizons and improving understanding & tolerance. It was a travesty […]
infosec.exchange
Original post on infosec.exchange
002
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 31/03/2026
Latest #firefox #ESR (v149.0) appears to have stopped reporting the HTTP error code when something goes wrong… in this case for a 403. It used to include the HTTP code and some useful words. In this error, it looks like the connection just didn't work […] [Original post on infosec.exchange]
Screenshot of Firefox saying:

Looks like there's a problem with this site
Firefox can't connect to the server at ip.mafoo.org.uk
What can you do about it?
The site could be temporarily unavailable or too busy. Try again in a few
moments.

Below is the Inspector showing the request returned a 403
229
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 29/03/2026
My search has, thus far, been fruitless so I am asking here as a last ditch attempt … I am looking for a self-hostable web based application to be an inventory of the (real, rather than e-) #books in the house. It should be able to accept a list of #ISBNs as input for importing items and look […]
infosec.exchange
Original post on infosec.exchange
3111
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 02/03/2026
This deserves a slow-clap for Apple… > An update to macOS 26.3 is overdue. You can install it now or it will be installed automatically Yesterday, 20:06 #fail #macos #apple #slowclap
A screenshot from macOS reading: An update to macOS 26.3 is overdue. You can install it now or it will be installed automatically Yesterday, 20:06.
008
Reposted by Matthew Slowe
Jim Killock @jim.killock.org.uk · 05/01/2026
What we should be doing - starting with the CyberSecurity Bill debate tomorrow - is defining how we get out of this dependence and extreme risk from US Big tech. The answers exist.
103
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 06/11/2025
I am getting increasingly irritated by #Booking_dot_com weaselling their way into search tools and, by default, spinning up a second tab with "hotels in the place you're going". It's underhand and they just need to stop. Like this pre-enabled "Explore […] [Original post on infosec.exchange]
001
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 03/11/2025
Saw this on #LinkedIn
two panel cartoon
1. Person holding up a red capped mushroom and the AI declares its safe

2. person in bed very ill with the AI saying "you're right, it's poisonous, would you lie to learn more abou poisonous mushrooms?"
064
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 15/09/2025
When the news site's #adblocker detector openly admits that the site's #ads are "intrusive", you have to wonder what thought processes got us here… I'll carry on using the "Reader view" bypass for as long as it works, thanks.
Screengrab from a local news website reading:

This story is only available to subscribers
+ Premium websites with no intrusive ads
+ Access to all articles & exclusive content
+ Weekly digital editions of all KM Papers
003
Reposted by Matthew Slowe
Robert Stribley @stribs.bsky.social · 27/04/2025
Love this. In his “I Agree” installation Dima Yarovinsky-Yahel took the content from terms of service statements for companies like Facebook, Snapchat, Instagram, Tinder and printed them out on A4 paper with a standard font size for legal contracts to demonstrate the length of these agreements.
Alt-Txt: Two people stand before multi-color strips of paper with text on them that stretch down an entire wall and onto the floor. The title of the installation "I Agree" appear in all caps on the wall, too.
2330961282
Reposted by Matthew Slowe
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 01/06/2025
New blog post by a colleague: Will quantum computing topple SAML? trustandidentity.jiscinvolve.org/wp… #saml #sso #pqc #quantumcomputing #oidc #jisc #infosec #iam #aim
trustandidentity.jiscinvolve.org
Will quantum computing topple SAML?
The Majorana 1. Photo by John Brecher for Microsoft The UK federation is arguably one of the largest SAML federations in the Research and Education sector, with over 1200 member organisations spanning Higher Education (HE) and Further Education (FE), and with significant representation from the research and commercial sectors. We are a trust broker. A level playing field. We help people securely access services, and enable services to make informed decisions about access and authorization. We have operated in the international community for 20 years. We work for the benefit of our customers by integrating with over 70 other national federations to increase our worldwide reach to 6,000 identity providers and over 3,500 services. There is a lot of evidence that multi-lateral SAML federations are in good health: * The UK federation continues to register new SAML services * Our helpdesk receives excellent customer service feedback for its support to Jisc members and customers * Data from federations which produce statistics on number of authentications (such as the Dutch federation SURFnet) show an increase year-on-year * In April 2025 five new national federations joined the eduGAIN (SAML) inter-federation service. How, then, should we respond to the increasingly insistent claims that “SAML is dead”? These claims are often given with little evidence, and certainly have no timescale attached. However, we know that there is significant development effort happening with other federated identity protocols such as OpenID Connect, OpenID Federation and the Federated Credential Management browser API. More importantly, recent guidance from the UK’s National Cyber Security Centre gives a clear timescale for migrating systems to use quantum-resistant cryptography. They’re not the experts on SAML federation, of course, so they don’t provide a pathway for us to follow, and we have to define our own. Will quantum computing topple SAML? ### **Some evidence for SAML decline** * Web developers are typically not familiar with federated authentication, nor the design patterns and architecture associated with multi-lateral SAML federations. We already see a slowdown of new registrations to the UK federation, but is that trend going to continue, or would information and advice about the benefits of SAML federations reverse that? * Scalable mechanisms to release personal data do not exist and IdP operators are risk averse to ad hoc solutions. This frustrates the promise of the rich authorization framework that SAML federations can support. * There are many infrastructure and community proxies which provide functionality that cannot be provided by the national multilateral SAML federations, such as protocol translation services and group membership. The AARC Blueprint architecture shows the maturity of the proxy space and indicates the features that cannot be easily deployed in a pure SAML federation. * The SAML technical committee was closed in 2023 so new developments to the protocol are very unlikely. Even before the committee was formally closed, the pace of standardisation was slowing, with the last specification dating to 2019, and low uptake of the newer specifications. * SAML does not easily support use cases like single page application frameworks or mobile applications, and doesn’t have REST APIs for authentication flows * New technologies like Verifiable Credentials are being built on top of OIDC not SAML. * If a vulnerability in the SAML protocol were discovered, there would be no standards-based response. However, we could develop ad hoc or community solutions which are really the basis for any formal standards-based response, so this is really a lack of formality than an existential issue. And also note that recent vulnerabilities have been in SAML implementations or deployments; it’s not the protocol which has been critically vulnerable. * Making or maintaining secure SAML implementations is likely to get harder as people with relevant skill sets (for example, XML, XSLT and XML Digital Signatures) leave the sector and new developers just want to use and work with JSON and JOSE. None of these factors suggests a specific end date for SAML although taken together they indicate a gradual decline in relevance and low capacity to change. We could take the position that the UK federation has found a niche and should continue to occupy it. ### **NCSC timeline for migration to post-quantum cryptography** The game-changer is guidance published in March 2025 by the UK’s National Cyber Security Centre, which provides a timeline to migrate safely to post-quantum cryptography (PQC). Should we be concerned with PQC? A recent research paper states that “the security and privacy of XML-based frameworks such as SAML is threatened by the development of increasingly powerful quantum computers. In fact, future attackers with access to scalable quantum computers will be able to break the currently used cryptographic building blocks and thus undermine the security of the SAML SSO to illegally access sensitive private information”. For our purposes, the NCSC timeline is: * By 2028, we must define migration goals and build an initial migration plan * By 2031, we must carry out the earliest, highest-priority PQC migration activities * By 2035, we must complete migration to PQC of all systems One of the main goals for us as a national infrastructure provider is to stay on top of the game and to minimize the disruption to our members. From an infrastructure point of view, the goals for making the UK federation technical infrastructure quantum-resistant lie on a spectrum between: * Ensuring SAML in use in the UK federation is quantum-resistant, and * Migrating away from SAML to something that is quantum-resistant. Since internet identity is an ecosystem, it’s likely that a hybrid solution will emerge, and that the UK federation will have to investigate a number of scenarios to define our goals. Once we have defined the goals, their delivery and implementation will be a colossal piece of work for the UK federation as an infrastructure provider. To illustrate the scale of what a migration goal should encompass, consider that on 22 April 2025 there were 2192 software deployments registered in the UK federation. Of these, 1442 run Shibboleth, 319 use OpenAthens, 82 run SimpleSAMLphp, and the remaining 349 are a long tail of other software stacks. Ensuring these software deployments migrate and remain interoperable is a considerable behind-the-scenes piece of work, which would need to be scaled out worldwide to the 8,000 other deployments across eduGAIN. It will need significant technical expertise, good communication with stakeholders and adroit management. #### **How do we ensure SAML in the UK federation is quantum-resistant?** In August 2024, NIST standardised the first PQC algorithms after several years of scrutiny, but that is not the end of the story. These algorithms have to be incorporated into protocols. The algorithms must also be implemented in hardware and software, and then into the applications stacks. This work is happening right now, although as William Gibson’s saying goes: the future is already here, it’s just not evenly distributed. For example, Java is the primary implementation language in the UK federation, and Java 24 now implements the ML-DSA digital signature algorithm, but the long tail of implementations in the UK federation are not all Java code. Research and Education SAML federations rely on cryptography in these 3 ways: * All network traffic happens over https, so there is TLS protection of endpoints. * We sign XML metadata with our federation’s key to ensure integrity and authenticity. We verify other federations’ metadata with their keys. These keys are typically 4096-bit RSA keys. * Federation members sign and encrypt XML messages to other federation members, which verify and decrypt the messages. These keys are typically 2048-bit RSA keys. Preparation for migration to PQC in TLS has been underway for some time, for example the IETF’s TLS working group is standardising hybrid key exchange in TLS 1.3. Federations do not need to lead the way here, although we must understand good practice and roll it out to our community. The primary job for federations will be to understand how to protect the integrity and authenticity of XML metadata. We also need to work with SAML software implementers to determine whether it’s possible to sign and encrypt XML messages. This is going to be a challenge. The cryptographic identifiers we use today were standardised in the W3C namespace over 15 years ago. It is unclear to the UK federation team whether the W3C is updating its specifications in light of PQC, so one of the first steps will be to engage with the W3C. And as we’ve seen before, standardisation of algorithms is just one step on the migration path. There are a lot of pieces of the puzzle to fit together. ### **Conclusion** Making SAML quantum resistant has many interdependent elements which make hardening SAML a complex and risky endeavour. However, as we’ve seen in previous Trust and Identity blog post, if we wanted to migrate away from SAML then there’s no clear technology choice for what to migrate to. Even if there were, we would find similar migration challenges. The practical aspects of migration are formidable whether we choose to migrate away from SAML or we choose to harden SAML. Over the next year, the UK federation team will continue to investigate this area and define our migration goals. We will endeavour to communicate our progress to UK federation members, and we anticipate more blog posts over the coming months.
010
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 01/06/2025
New blog post by a colleague: Will quantum computing topple SAML? trustandidentity.jiscinvolve.org/wp… #saml #sso #pqc #quantumcomputing #oidc #jisc #infosec #iam #aim
trustandidentity.jiscinvolve.org
Will quantum computing topple SAML?
The Majorana 1. Photo by John Brecher for Microsoft The UK federation is arguably one of the largest SAML federations in the Research and Education sector, with over 1200 member organisations spanning Higher Education (HE) and Further Education (FE), and with significant representation from the research and commercial sectors. We are a trust broker. A level playing field. We help people securely access services, and enable services to make informed decisions about access and authorization. We have operated in the international community for 20 years. We work for the benefit of our customers by integrating with over 70 other national federations to increase our worldwide reach to 6,000 identity providers and over 3,500 services. There is a lot of evidence that multi-lateral SAML federations are in good health: * The UK federation continues to register new SAML services * Our helpdesk receives excellent customer service feedback for its support to Jisc members and customers * Data from federations which produce statistics on number of authentications (such as the Dutch federation SURFnet) show an increase year-on-year * In April 2025 five new national federations joined the eduGAIN (SAML) inter-federation service. How, then, should we respond to the increasingly insistent claims that “SAML is dead”? These claims are often given with little evidence, and certainly have no timescale attached. However, we know that there is significant development effort happening with other federated identity protocols such as OpenID Connect, OpenID Federation and the Federated Credential Management browser API. More importantly, recent guidance from the UK’s National Cyber Security Centre gives a clear timescale for migrating systems to use quantum-resistant cryptography. They’re not the experts on SAML federation, of course, so they don’t provide a pathway for us to follow, and we have to define our own. Will quantum computing topple SAML? ### **Some evidence for SAML decline** * Web developers are typically not familiar with federated authentication, nor the design patterns and architecture associated with multi-lateral SAML federations. We already see a slowdown of new registrations to the UK federation, but is that trend going to continue, or would information and advice about the benefits of SAML federations reverse that? * Scalable mechanisms to release personal data do not exist and IdP operators are risk averse to ad hoc solutions. This frustrates the promise of the rich authorization framework that SAML federations can support. * There are many infrastructure and community proxies which provide functionality that cannot be provided by the national multilateral SAML federations, such as protocol translation services and group membership. The AARC Blueprint architecture shows the maturity of the proxy space and indicates the features that cannot be easily deployed in a pure SAML federation. * The SAML technical committee was closed in 2023 so new developments to the protocol are very unlikely. Even before the committee was formally closed, the pace of standardisation was slowing, with the last specification dating to 2019, and low uptake of the newer specifications. * SAML does not easily support use cases like single page application frameworks or mobile applications, and doesn’t have REST APIs for authentication flows * New technologies like Verifiable Credentials are being built on top of OIDC not SAML. * If a vulnerability in the SAML protocol were discovered, there would be no standards-based response. However, we could develop ad hoc or community solutions which are really the basis for any formal standards-based response, so this is really a lack of formality than an existential issue. And also note that recent vulnerabilities have been in SAML implementations or deployments; it’s not the protocol which has been critically vulnerable. * Making or maintaining secure SAML implementations is likely to get harder as people with relevant skill sets (for example, XML, XSLT and XML Digital Signatures) leave the sector and new developers just want to use and work with JSON and JOSE. None of these factors suggests a specific end date for SAML although taken together they indicate a gradual decline in relevance and low capacity to change. We could take the position that the UK federation has found a niche and should continue to occupy it. ### **NCSC timeline for migration to post-quantum cryptography** The game-changer is guidance published in March 2025 by the UK’s National Cyber Security Centre, which provides a timeline to migrate safely to post-quantum cryptography (PQC). Should we be concerned with PQC? A recent research paper states that “the security and privacy of XML-based frameworks such as SAML is threatened by the development of increasingly powerful quantum computers. In fact, future attackers with access to scalable quantum computers will be able to break the currently used cryptographic building blocks and thus undermine the security of the SAML SSO to illegally access sensitive private information”. For our purposes, the NCSC timeline is: * By 2028, we must define migration goals and build an initial migration plan * By 2031, we must carry out the earliest, highest-priority PQC migration activities * By 2035, we must complete migration to PQC of all systems One of the main goals for us as a national infrastructure provider is to stay on top of the game and to minimize the disruption to our members. From an infrastructure point of view, the goals for making the UK federation technical infrastructure quantum-resistant lie on a spectrum between: * Ensuring SAML in use in the UK federation is quantum-resistant, and * Migrating away from SAML to something that is quantum-resistant. Since internet identity is an ecosystem, it’s likely that a hybrid solution will emerge, and that the UK federation will have to investigate a number of scenarios to define our goals. Once we have defined the goals, their delivery and implementation will be a colossal piece of work for the UK federation as an infrastructure provider. To illustrate the scale of what a migration goal should encompass, consider that on 22 April 2025 there were 2192 software deployments registered in the UK federation. Of these, 1442 run Shibboleth, 319 use OpenAthens, 82 run SimpleSAMLphp, and the remaining 349 are a long tail of other software stacks. Ensuring these software deployments migrate and remain interoperable is a considerable behind-the-scenes piece of work, which would need to be scaled out worldwide to the 8,000 other deployments across eduGAIN. It will need significant technical expertise, good communication with stakeholders and adroit management. #### **How do we ensure SAML in the UK federation is quantum-resistant?** In August 2024, NIST standardised the first PQC algorithms after several years of scrutiny, but that is not the end of the story. These algorithms have to be incorporated into protocols. The algorithms must also be implemented in hardware and software, and then into the applications stacks. This work is happening right now, although as William Gibson’s saying goes: the future is already here, it’s just not evenly distributed. For example, Java is the primary implementation language in the UK federation, and Java 24 now implements the ML-DSA digital signature algorithm, but the long tail of implementations in the UK federation are not all Java code. Research and Education SAML federations rely on cryptography in these 3 ways: * All network traffic happens over https, so there is TLS protection of endpoints. * We sign XML metadata with our federation’s key to ensure integrity and authenticity. We verify other federations’ metadata with their keys. These keys are typically 4096-bit RSA keys. * Federation members sign and encrypt XML messages to other federation members, which verify and decrypt the messages. These keys are typically 2048-bit RSA keys. Preparation for migration to PQC in TLS has been underway for some time, for example the IETF’s TLS working group is standardising hybrid key exchange in TLS 1.3. Federations do not need to lead the way here, although we must understand good practice and roll it out to our community. The primary job for federations will be to understand how to protect the integrity and authenticity of XML metadata. We also need to work with SAML software implementers to determine whether it’s possible to sign and encrypt XML messages. This is going to be a challenge. The cryptographic identifiers we use today were standardised in the W3C namespace over 15 years ago. It is unclear to the UK federation team whether the W3C is updating its specifications in light of PQC, so one of the first steps will be to engage with the W3C. And as we’ve seen before, standardisation of algorithms is just one step on the migration path. There are a lot of pieces of the puzzle to fit together. ### **Conclusion** Making SAML quantum resistant has many interdependent elements which make hardening SAML a complex and risky endeavour. However, as we’ve seen in previous Trust and Identity blog post, if we wanted to migrate away from SAML then there’s no clear technology choice for what to migrate to. Even if there were, we would find similar migration challenges. The practical aspects of migration are formidable whether we choose to migrate away from SAML or we choose to harden SAML. Over the next year, the UK federation team will continue to investigate this area and define our migration goals. We will endeavour to communicate our progress to UK federation members, and we anticipate more blog posts over the coming months.
010
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 15/05/2025
#Wifi on a #train is like the internet in 1994 with a 14k modem #southeasternrailway #uk
110
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 24/04/2025
I'm lost for words... that's… #windows #microsoft #greenwashing
A screenshot from Windows Control panel stating that:

"Windows Update is committed to helping reduce carbon emissions."
000
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 16/04/2025
It seems that #Paris has gained a new embassy to house a delegation of #Orcs from #Mordor Spotted at the bottom of the steps at Rue du Mont Cenis, #Montmartre #lotr #middleearth
A set of brown road signs in a built-up area of Paris. The sign in question reads "Ambassade du Mordor" and has a iconographic representation of an Orc.
002
Matthew Slowe @fooflington.infosec.exchange.ap.brid.gy · 08/03/2025
Being able to #block people is a personal #wellbeing enabler (via www.jimbenton.com) #fediverse #mastodon
A four pane cartoon showing a person getting frustrated with a laptop

The dialog reads:

Person: Some of these people really bug me
Someone off stage: Just use the block feature. You'll feel much better.
Person: You're right I DO feel much better.

The final pane shows a large breeze-block crushing the laptop
003