Live data from Hacker News

An admittedly wandering defense of the SSO tax

ssoready.com

1–10 of 99 posts

Re: An admittedly wandering defense of the SSO tax

#2
Nice explanation. I'd be interested in hearing from anyone who used to feel negatively about the "SSO tax" and then switched to feeling positive/neutral about it — what changed your mind and why? Vice versa, too. (Not interested in rehashing arguments about why it's good or bad.)

Re: An admittedly wandering defense of the SSO tax

#4
As someone who deals with application support, another big reason is SSO is such a support nightmare. No one wanted to touch SSO tickets because of how frustrating they were to deal with. People wouldn't follow the instructions. Microsoft/Google moved something in their portal and we didn't know so instructions were useless. Microsoft/Google would be having issues and we got tickets because they were still working until tokens expired. Their Admins would turn on 2FA and when their support desk got "Cannot login to $OurProduct", they would just flip it over to us without caring. List goes on and on.

Re: An admittedly wandering defense of the SSO tax

#5
It's a bad system and you should feel bad for using it.

By all means charge enterprises more, but base it on something else, headcount, revenue, non-profit status...whatever.

Every time I hear about a data breach I wonder if someone avoided perfectly reasonable SSO protections because of this tax.

Re: An admittedly wandering defense of the SSO tax

#7
post #3

This car with no seat belts, no airbags, and no ABS is just price discrimination! Strangely, no one seems interested in celebrating the implied discount for not having safety.

This is a solid objection that I hadn't considered before!

Why isn't SAML SSO mandated (either literally or my convention)?

Practically speaking, as someone who spends all day trying to convince developers to implement SAML SSO, I really wish this were the case :)

I think in practice, software vendors correctly assess that relatively few of their prospective customers actually care.

If many small / price sensitive companies really wanted SAML SSO from their vendors -- if there were really meaningful demand -- I imagine we'd see more pricing plans with SAML SSO bundled into entry level tiers.

As for mandates, this is a challenging ethical question. I don't think it's necessarily obvious in all cases that some institution should impose safety regulations upon us.

There's clearly some set of risks we accept, and some set of risks we don't accept. And we all draw the line in different places.

This is pretty obviously true. Not many of us worry about objects randomly falling off buildings. We don't all wear helmets all the time. It's certainly a risk, but do we really care?

I think the revealed preference from many software buyers is basically ... no, they don't care about having the security benefits of SSO.

Re: An admittedly wandering defense of the SSO tax

#8

As someone who deals with application support, another big reason is SSO is such a support nightmare. No one wanted to touch SSO tickets because of how frustrating they were to deal with. People wouldn't follow the instructions. Microsoft/Google moved something in their portal and we didn't know so instructions were useless. Microsoft/Google would be having issues and we got tickets because they were still working un…

This is the real reason there's an SSO tax. It costs to support SSO, the customers who want SSO should pay for that cost.

Re: An admittedly wandering defense of the SSO tax

#9

As someone who deals with application support, another big reason is SSO is such a support nightmare. No one wanted to touch SSO tickets because of how frustrating they were to deal with. People wouldn't follow the instructions. Microsoft/Google moved something in their portal and we didn't know so instructions were useless. Microsoft/Google would be having issues and we got tickets because they were still working un…

I was lead engineer for a startup. By virtue of being the most flexible in my day-to-day, I ran front line for most of the customer support issues.

SSO issues took exponentially longer than nearly every other support issue and accounted for well over 50% of our support efforts.

We didn’t really feel like there was much we could do about it either. Most of it came down to the fact that the user of our application was not the person also able to setup SSO. The result was a massive game of pass the hot potato until we would get fed up and request a call with our customers IT team.

Re: An admittedly wandering defense of the SSO tax

#10

As someone who deals with application support, another big reason is SSO is such a support nightmare. No one wanted to touch SSO tickets because of how frustrating they were to deal with. People wouldn't follow the instructions. Microsoft/Google moved something in their portal and we didn't know so instructions were useless. Microsoft/Google would be having issues and we got tickets because they were still working un…

This it's exactly the issue with SSO and enterprise customers with complex requirements on how their IDP needs to be integrated.
Post reply on HN