Live data from Hacker News

An admittedly wandering defense of the SSO tax

ssoready.com

21–30 of 99 posts

Re: An admittedly wandering defense of the SSO tax

#21
The reality is much simpler than the article would have you believe. The article goes through all these convoluted explanations about value add but the simple fact of the matter is that SSO is the one differentiator that businesses will guarantee pay for. The other features are often unknown to stakeholders outside of the internal champion and need explanation oftentimes. But SSO, enterprises always need at a certain scale. So it’s incredibly effective because it’s the one feature that every single enterprise that wants to purchase your product cannot do without.

In fact, the exact opposite conclusion of the article is reached if we follow this logic. One of the taglines reads: Buyers want different things. Well, maybe the stakeholder/champion actually using your software might. But often they are not the ones that are making the money decision in an organization. The people who ARE making that decision, however, do not want different things. They probably could care less about different things. They want SSO.

Re: An admittedly wandering defense of the SSO tax

#22
post #3

This car with no seat belts, no airbags, and no ABS is just price discrimination! Strangely, no one seems interested in celebrating the implied discount for not having safety.

This is a solid objection that I hadn't considered before! Why isn't SAML SSO mandated (either literally or my convention)? Practically speaking, as someone who spends all day trying to convince developers to implement SAML SSO, I really wish this were the case :) I think in practice, software vendors correctly assess that relatively few of their prospective customers actually care. If many small / price sensitive co…

>This is a solid objection that I hadn't considered before!

To be quite frank: this strongly suggests that while you put a lot of effort into writing a long article in defense of the SSO tax, you didn't perform more than the most cursory research about why it's a topic of discussion.

This argument is literally above the fold on the two top search results for the term.

>In short: SSO is a core security requirement for any company with more than five employees.

https://sso.tax/

And the other explicitly makes the car-safety analogy:

>Imagine buying a car and the manufacturer asks for an extra payment to unlock 100% of the braking power. Not offering security features if they already exist in your product means a vendor doesn’t care about your security. Our aim is to spotlight vendors who overcharge for security features, in hopes of instigating a change in the industry.

https://ssotax.org/

And to be franker: the word "security" appears exactly once in your entire piece. That's a near-complete avoidance of the actual issue that people are highlighting.

I perfectly understand the rationale behind the pricing model. The point is that "only large enterprises need or care about SSO" is completely wrong-headed and detrimental to the overall security posture of any business customer. That is and should be unacceptable.

Re: An admittedly wandering defense of the SSO tax

#23

As someone who deals with application support, another big reason is SSO is such a support nightmare. No one wanted to touch SSO tickets because of how frustrating they were to deal with. People wouldn't follow the instructions. Microsoft/Google moved something in their portal and we didn't know so instructions were useless. Microsoft/Google would be having issues and we got tickets because they were still working un…

The “human cost” of SSO is definitely the hardest part.

At WorkOS we solved this by shipping the whole config workflow in the form of an admin portal. It checks things like SAML certificate, signatures/assertions, attribute mapping, etc. and a zillion other edge cases across dozens of identity systems.

It’s pretty much “Stripe Checkout" for setting up SAML. Live demo here (click “Configure”) https://explore.workos.com/app/settings

Re: An admittedly wandering defense of the SSO tax

#24
post #8

As someone who deals with application support, another big reason is SSO is such a support nightmare. No one wanted to touch SSO tickets because of how frustrating they were to deal with. People wouldn't follow the instructions. Microsoft/Google moved something in their portal and we didn't know so instructions were useless. Microsoft/Google would be having issues and we got tickets because they were still working un…

This is the real reason there's an SSO tax. It costs to support SSO, the customers who want SSO should pay for that cost.

There are plenty of folks who setup SSO with open source projects without a support contract. Why should they have to pay for it with other software?

Re: An admittedly wandering defense of the SSO tax

#25
post #23

As someone who deals with application support, another big reason is SSO is such a support nightmare. No one wanted to touch SSO tickets because of how frustrating they were to deal with. People wouldn't follow the instructions. Microsoft/Google moved something in their portal and we didn't know so instructions were useless. Microsoft/Google would be having issues and we got tickets because they were still working un…

The “human cost” of SSO is definitely the hardest part. At WorkOS we solved this by shipping the whole config workflow in the form of an admin portal. It checks things like SAML certificate, signatures/assertions, attribute mapping, etc. and a zillion other edge cases across dozens of identity systems. It’s pretty much “Stripe Checkout" for setting up SAML. Live demo here (click “Configure”) https://explore.workos.co…

Oh cool! We have pretty much the same thing

Re: An admittedly wandering defense of the SSO tax

#26
This is a good economics lesson but fails to address the actual issue people have with the SSO tax. It isn't about the concept of price discrimination, but price discrimination when it comes to security. You can charge extra for convenience features or other value-add features, sure, but the choice of login provider is something that should be table stakes for every person and every organization regardless of how big they are or how much they can pay. An even worse example – plenty of apps gate two-factor auth behind a paid tier as well.

Re: An admittedly wandering defense of the SSO tax

#27
This reminds me of when several years ago I was a pretty early enterprise Vault user - I poc'd out a pretty simple implementation with the OSS version that at that time included SSO support with Okta. Management was like "great we don't have to pay for any of this then, let's use OSS then" and I argued that there was zero chance they were going to leave that as a OSS feature, sure enough, some months later they rug pulled it. It was pretty much the only additional feature outside of core functionality we absolutely "needed," everything else was pretty fluff.

Re: An admittedly wandering defense of the SSO tax

#28

Earlier quoted context omitted.

This is a solid objection that I hadn't considered before! Why isn't SAML SSO mandated (either literally or my convention)? Practically speaking, as someone who spends all day trying to convince developers to implement SAML SSO, I really wish this were the case :) I think in practice, software vendors correctly assess that relatively few of their prospective customers actually care. If many small / price sensitive co…

>This is a solid objection that I hadn't considered before! To be quite frank: this strongly suggests that while you put a lot of effort into writing a long article in defense of the SSO tax, you didn't perform more than the most cursory research about why it's a topic of discussion. This argument is literally above the fold on the two top search results for the term. >In short: SSO is a core security requirement for…

Hm, that seems like a misrepresentation of what I'm saying.

I specifically meant that the previous commenter made me think of mandates.

I run a company that makes SAML SSO software. I've thought quite extensively about SAML SSO. See:

https://news.ycombinator.com/item?id=41036982

Addendum: I have a very strongly vested interest in more people using SSO. I literally spend my time trying to convince developers to set it up!

Re: An admittedly wandering defense of the SSO tax

#29
post #26

This is a good economics lesson but fails to address the actual issue people have with the SSO tax. It isn't about the concept of price discrimination, but price discrimination when it comes to security . You can charge extra for convenience features or other value-add features, sure, but the choice of login provider is something that should be table stakes for every person and every organization regardless of how bi…

Sure, but most SaaS support “SSO at home” in lower tiers via either Google idp or GitHub. So yes you’re locked into those vendors which kind of sucks but it’s not necessarily true that you have to give up security without forking over the “SSO tax”

Re: An admittedly wandering defense of the SSO tax

#30

The reality is much simpler than the article would have you believe. The article goes through all these convoluted explanations about value add but the simple fact of the matter is that SSO is the one differentiator that businesses will guarantee pay for. The other features are often unknown to stakeholders outside of the internal champion and need explanation oftentimes. But SSO, enterprises always need at a certain…

I think the friction here is from midsized companies. Where onboarding software that’s purchased is much harder than free software.

I think it might be worth saying “SSO is free, up to n users”.

Also this is pricing for “adequate security”, which rubs a lot of people the wrong way.

But I do agree, competent, organizational wide SSO with SCIM is definitely an enterprise feature.

Post reply on HN