Live data from Hacker News

Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

github.com

41–50 of 101 posts

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#44
post #38

Kudos on releasing open source, and on launching an easy-to-use service. Side thought: If this takes off as a popular quality implementation, an additional effect might might be that it's easier for vendors of other services to integrate with users of your software. Maybe there's some way you can profit from that savings or reduced sales friction. (I've had to implement several F500 SSO integrations from scratch, bec…

> Question: For the free hosted SSO, how well are you going to be able to secure that, so that your customers aren't compromised through you?

Yeah, this is super important. No short answer here, it's just about doing the work and getting it right.

We're working with Oneleet for our SOC2 stuff (which we all know is largely theater) but also pretty thorough pentesting. I can email you their findings.

The reality is we're one of those companies that need to get this stuff right.

> Question: Will the free tier SSO have uptime guarantees, since it'll be a single point of failure for all your customers? For startups that decide they'd like it hosted for them, but need an SLA, do you expect to be able to provide that at a price doable by startups?

Our plan is to work out agreements on a case-by-case basis. It'd depend on exactly what you need. We take guarantees pretty seriously, so we're careful about what we promise.

We're not a services business. We don't want to make money off of "premium support". There is a modest price tag if you want an SLA.

> (Will a cloud provider pick up those customers using your software?)

Would you mind rephrasing?

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#45
post #26

Why saml instead of OIDC?

In my experience, SAML seems to be a more universally used option.

Your app isn't ready to support 'enterprise' until you can do both - you'll need to use this product + roll your own OIDC or find another service like this for OIDC. Customers will expect you to be agnostic and bring whichever they prefer.

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#46

What happens if my enterprise custies need support because they can't log in and I need support? GitHub Issue? email?

My personal phone number and email is in the sidebar of app.ssoready.com for this exact reason.

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#47

Congrats on the launch! How does this compare to BoxyHQ's SAML Jackson [1]? [1]: https://github.com/boxyhq/jackson

We think BoxyHQ does a nice job.

We prefer our approach for basically two reasons:

1. BoxyHQ wants you to do SAML-over-OAuth. We support this -- especially for NextAuth compatibility. But we don't think it's always helpful.

2. We think our service is easier to use. We most commonly hear complaints from users/customers about complexity, so we try really hard to make SAML obvious and simple. Ultimately, it's up to you whether we meet that bar.

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#48
post #44
post #38

Kudos on releasing open source, and on launching an easy-to-use service. Side thought: If this takes off as a popular quality implementation, an additional effect might might be that it's easier for vendors of other services to integrate with users of your software. Maybe there's some way you can profit from that savings or reduced sales friction. (I've had to implement several F500 SSO integrations from scratch, bec…

> Question: For the free hosted SSO, how well are you going to be able to secure that, so that your customers aren't compromised through you? Yeah, this is super important. No short answer here, it's just about doing the work and getting it right. We're working with Oneleet for our SOC2 stuff (which we all know is largely theater) but also pretty thorough pentesting. I can email you their findings. The reality is we'…

Thanks. Regarding "Will a cloud provider pick up those customers using your software?", I was wondering whether there might be a situation in which there was a category of service customers you'd like to have, but that a cloud provider hosts your software without you otherwise involved.

https://en.wikipedia.org/wiki/Elasticsearch#Licensing_change...

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#49

This looks very cool! Having implemented SAML before, it was definitely a pain and your tooling looks painless! That said, the pricing worries me a bit. This is a tool we'd have to build on top of . Which means that if it disappears later because you went out of business (or just changed your pricing in some way that hosed us), we'd have a whole big, unexpected engineering project to rewrite our SSO. And given that y…

The SSO tax[1] already exists. It sucks: Gating security features, best practices and automation when someone is already your customer is terrible. But it's the status quo, and in that status quo people that need SAML in their company probably should pay at least half as much as they pay for this single feature in a single one of their SaaS apps.

[1]: https://sso.tax/

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#50
post #48
post #44

Earlier quoted context omitted.

> Question: For the free hosted SSO, how well are you going to be able to secure that, so that your customers aren't compromised through you? Yeah, this is super important. No short answer here, it's just about doing the work and getting it right. We're working with Oneleet for our SOC2 stuff (which we all know is largely theater) but also pretty thorough pentesting. I can email you their findings. The reality is we'…

Thanks. Regarding "Will a cloud provider pick up those customers using your software?", I was wondering whether there might be a situation in which there was a category of service customers you'd like to have, but that a cloud provider hosts your software without you otherwise involved. https://en.wikipedia.org/wiki/Elasticsearch#Licensing_change...

I think the reality is that the category of software we're open-sourcing isn't very big. We're gonna make our money doing other things, not all of which will be open-source.
Post reply on HN