Live data from Hacker News

Ask HN: Is there still a reason to use Okta for SSO? Okta vs. Google SSO

news.ycombinator.com

31–37 of 37 posts

Re: Ask HN: Is there still a reason to use Okta for SSO? Okta vs. Google SSO

#31
post #30
post #20

Earlier quoted context omitted.

When talking about controls are you referring to provisioning? What are some examples for missing controls?

Pretty sure he means audit compliance, proper RBAC, etc

Hmm audit compliance? Google gives you a log of who logged in where, doesn't it? And with "proper RBAC" you mean that you can put somebody into the "Developer" role, hence he gets AWS, GCP, Datadog, right?

Re: Ask HN: Is there still a reason to use Okta for SSO? Okta vs. Google SSO

#32

I don't see why anyone would ever use Google anything for a business critical use. They seem allergic to providing customer support for anything other than advertising.

They are fine as an enterprise vendor. Chill out about Google Reader or whatever.

Re: Ask HN: Is there still a reason to use Okta for SSO? Okta vs. Google SSO

#34
Okta is one of those companies that just dominates their niche. They're good enough and cheap enough that it's a no brainer. They're not going to go out of business and any SAAS that an organization might use will be supported. The upside of saving whatever handful of dollars per user you spend with Okta isn't worth the risk/hassle of switching away from what everyone else uses.

Re: Ask HN: Is there still a reason to use Okta for SSO? Okta vs. Google SSO

#35
post #30

Earlier quoted context omitted.

Pretty sure he means audit compliance, proper RBAC, etc

Hmm audit compliance? Google gives you a log of who logged in where, doesn't it? And with "proper RBAC" you mean that you can put somebody into the "Developer" role, hence he gets AWS, GCP, Datadog, right?

I don't know how extensive Google's logging is - heck, didn't even know they offered Enterprise SSO until a few days ago (every organization I know uses either Okta or M365/AD) :)

Proper RBAC is as granular as necessary, but no more

Proper RBAC also links everything needed by a certain role together

Merely knowing who logged-in where and when, though, is not enough - you also need to know what they did while there (and that they did not do anything they were not supposed to be able to do (which links back to proper RBAC'ing))

CIS, HIPAA, FISMA, SOX, STIG and all the other alphabet soup compliance rules, frameworks, etc are a lot more extensive than just "who logged in where" :)

--------

See NIST's page on RBAC for some of this: https://csrc.nist.gov/Projects/Role-Based-Access-Control

Re: Ask HN: Is there still a reason to use Okta for SSO? Okta vs. Google SSO

#36

Google is unsurprisingly more convenient if you're already using Google workspace.

I'd wager Google is only "more convenient" if you're pretty much exclusively using Google products and/or external services that already allowed personal/work accounts to authenticate via Google

...but even then - while GCP is [probably] the "best" big cloud vendor out there, they have a nasty reputation for being very hard to deal with

Re: Ask HN: Is there still a reason to use Okta for SSO? Okta vs. Google SSO

#37
post #29

If you already have sysadmin skills what's wrong with self-hosting an IdP like Zitadel or Keycloak?

Because self-hosting mission-critical services that are not your business' core competency is almost always stupid As just one example - 20 years ago it made sense for many businesses to self-host email It has not made sense to do that for at least a decade

That is the reason why we also provide a cloud service with zitadel.

But it is important to us to let customers choose what they like more.

Sometime the gained control (and responsibility) when self-hosting might be crucial for the specific use-case.

Post reply on HN