Live data from Hacker News

Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

github.com

71–80 of 101 posts

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#71
post #64

Congrats on launching! SAML is going to be around forever (even though the stadnard is no longer being updated[0]) so it's good for folks to have more options. 0: https://lists.oasis-open.org/archives/security-services/2023...

Even the website certificate has expired apparently.

net::ERR_CERT_DATE_INVALID

Subject: lists.oasis-open.org

Issuer: Sectigo RSA Domain Validation Secure Server CA

Expires on: Jul 8, 2024

Current date: Jul 31, 2024

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#72
For info, the documentation for the project https://ssoready.com/docs seems down:

502 ERROR The request could not be satisfied. CloudFront wasn't able to connect to the origin. We can't connect to the server for this app or website at this time. There might be too much traffic or a configuration error. Try again later, or contact the app or website owner. If you provide content to customers through CloudFront, you can find steps to troubleshoot and help prevent this error by reviewing the CloudFront documentation. Generated by cloudfront (CloudFront)

cf. http://www.site-shot.com/Lu-cUE7TEe-S-wJCrBEAAg or https://archive.is/wip/FhNfD

Otherwise the project looks really well done and by nice people.

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#73
post #28
post #9

I can only wish you good luck. I mean it, best of luck to you all. We wrote our own IdP back in the day. It was a cool project, Single Sign On, Single Sign OUT, User provisioning, just all sorts of stuff. And it worked! It's amazing when it works, it's just like magic. You giggle when it works. We did all sorts of integrations. To random Service Providers, integrating with other IdPs, etc. Some were really cool. Grea…

Saying > And it worked! It's amazing when it works, it's just like magic. You giggle when it works. And then this > It was never "painless". Ever. It was always pulling teeth. Even with a caveat in between, is misleading. I get you’re probably trying to generate revenue, and more power to you. I’d re-work that phrasing next time.

You’re responding to a comment not the op? The commenter isn’t trying to make money just sharing an experience

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#74

Earlier quoted context omitted.

> Add to that the very often the people you're integrating with have no concept of SAML, its workflows, its payloads, etc., much less the capabilities of their own stack in regards to SAML. So you get to train them (and learn about their system) at the same time. This is true of a great many protocols, unfortunately. I've seen this with IPSec, HL7v2, … CSV . IPSec was perhaps the most … scarring. Always sort of feeli…

SAML and IPsec both make my eye twitch, and I too have struggled where the person on the other end has no idea. One of my favourites was the time I was trying to figure out a SAML integration with a client, and before the person on the client's "SSO team" could figure it out, I installed a demo of their SSO solution, integrated with my own dev AD, and found the checkbox. Yay enterprise! The Q in enterprise is for qua…

Yeah, I’ve done this too. On the one hand, it’s crazy annoying. On the other hand, at least they _had_ a docker image I could use.

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#75
post #26

Why saml instead of OIDC?

In my experience, SAML seems to be a more universally used option.

SAML is the older protocol. It would be a design smell to see a new RP using it exclusively (people still implement SAML because enterprise customers have SAML IdPs).

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#76
post #72

For info, the documentation for the project https://ssoready.com/docs seems down: 502 ERROR The request could not be satisfied. CloudFront wasn't able to connect to the origin. We can't connect to the server for this app or website at this time. There might be too much traffic or a configuration error. Try again later, or contact the app or website owner. If you provide content to customers through CloudFront, you ca…

Thank you for letting us know!

Are you still unable to use https://ssoready.com/docs?

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#77

This looks very cool! Having implemented SAML before, it was definitely a pain and your tooling looks painless! That said, the pricing worries me a bit. This is a tool we'd have to build on top of . Which means that if it disappears later because you went out of business (or just changed your pricing in some way that hosed us), we'd have a whole big, unexpected engineering project to rewrite our SSO. And given that y…

Ya with the last decade of experience I'm never building on top of a vc backed open source project. These things are mutually exclusive IMO. I'm not saying you can't build a solid business around open source. I mean red hat did it, but that is the model you have to go for. Not VC money at seed stage.

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#78
post #44
post #38

Kudos on releasing open source, and on launching an easy-to-use service. Side thought: If this takes off as a popular quality implementation, an additional effect might might be that it's easier for vendors of other services to integrate with users of your software. Maybe there's some way you can profit from that savings or reduced sales friction. (I've had to implement several F500 SSO integrations from scratch, bec…

> Question: For the free hosted SSO, how well are you going to be able to secure that, so that your customers aren't compromised through you? Yeah, this is super important. No short answer here, it's just about doing the work and getting it right. We're working with Oneleet for our SOC2 stuff (which we all know is largely theater) but also pretty thorough pentesting. I can email you their findings. The reality is we'…

> SOC2 stuff (which we all know is largely theater)

SOC2 is only theatre if you (a) you already have good practice, and (b) can demonstrate that you have good practice. If your practice isn't good enough (like the whole notion of security controls is a foreign concept), and sure there's a lot of boilerplate to work through -- but the whole point of a SOC2 Type 2 report is that you only have to demonstrate once to the auditor, rather than to each customer each time.

Having to get internal security sign-off for a non-audited SaaS vendor -- really, life's just too short for that most of the time, and if there's choice of two more or less equivalent providers we go with the certified one every time.

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#79
post #9

I can only wish you good luck. I mean it, best of luck to you all. We wrote our own IdP back in the day. It was a cool project, Single Sign On, Single Sign OUT, User provisioning, just all sorts of stuff. And it worked! It's amazing when it works, it's just like magic. You giggle when it works. We did all sorts of integrations. To random Service Providers, integrating with other IdPs, etc. Some were really cool. Grea…

So it’s like managing your own e-mail server.

SPF, DMARC, DKIM is setup correctly. Domain name A/AAA/TXT/MX records all setup and propagated throughout the world. Mail server tested with external tools like mail-tester.com

But there is a whole new world of “other mail servers” now. Some mail servers are okay. Delivery works fine. Some mail servers have odd policies and implement strict block lists and maintain their own rep of each domain/sender.

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#80

This looks very cool! Having implemented SAML before, it was definitely a pain and your tooling looks painless! That said, the pricing worries me a bit. This is a tool we'd have to build on top of . Which means that if it disappears later because you went out of business (or just changed your pricing in some way that hosed us), we'd have a whole big, unexpected engineering project to rewrite our SSO. And given that y…

Ya with the last decade of experience I'm never building on top of a vc backed open source project. These things are mutually exclusive IMO. I'm not saying you can't build a solid business around open source. I mean red hat did it, but that is the model you have to go for. Not VC money at seed stage.

Out of curiosity, who else did it besides RedHat ( who are building Linux distros AFAIK ) ?

How do you expect people to bootstrap an infra SaaS? I just don’t see how you can seriously attempt something like an Auth0 competitor startup without any money. I mean it’s nice to not take VC money but you are going to be broke for a long long time - and you still have the same failure rate as with VC.

So you need to be super masochistic to work for nothing for years with a 99% of everything will evaporate at any point - and at the same time somehow convince companies to build on your stack - not only build on it but make it the gatekeeper and front door of everything. I can tell you that you will have an extremely hard time to get any customers for this, regardless of how great the tech is.

Maybe you don’t need it at seed stage - but unless you are fantastically rich already you need some investment to get beyond seed stage IMHO.

Post reply on HN