Live data from Hacker News

An admittedly wandering defense of the SSO tax

ssoready.com

61–70 of 99 posts

Re: An admittedly wandering defense of the SSO tax

#61
post #10

As someone who deals with application support, another big reason is SSO is such a support nightmare. No one wanted to touch SSO tickets because of how frustrating they were to deal with. People wouldn't follow the instructions. Microsoft/Google moved something in their portal and we didn't know so instructions were useless. Microsoft/Google would be having issues and we got tickets because they were still working un…

This it's exactly the issue with SSO and enterprise customers with complex requirements on how their IDP needs to be integrated.

Meh. Most of them are using off the shelf stuff like Entra ID or Okta. They support complex configs but it's all on the side of the IDP. For the end service it's just SAML.

Re: An admittedly wandering defense of the SSO tax

#62
> Some of us believe that all parties should pay a fair price, the same price for a given product or service. I have some sympathy for that perspective. I myself have felt tempted to describe certain prices as ripoffs, saying something like “a bottle of water should not cost $8” while waiting to board a flight at SFO. It’s very natural for us to say things like that.

Airports are natural, government-administered monopolies, who then typically auction off the rights for firms to sell to a captive audience with little to no competition. This typically results in unfair and wasteful allocation of resources.

Re: An admittedly wandering defense of the SSO tax

#63

Earlier quoted context omitted.

This is a solid objection that I hadn't considered before! Why isn't SAML SSO mandated (either literally or my convention)? Practically speaking, as someone who spends all day trying to convince developers to implement SAML SSO, I really wish this were the case :) I think in practice, software vendors correctly assess that relatively few of their prospective customers actually care. If many small / price sensitive co…

>This is a solid objection that I hadn't considered before! To be quite frank: this strongly suggests that while you put a lot of effort into writing a long article in defense of the SSO tax, you didn't perform more than the most cursory research about why it's a topic of discussion. This argument is literally above the fold on the two top search results for the term. >In short: SSO is a core security requirement for…

>I perfectly understand the rationale behind the pricing model. The point is that "only large enterprises need or care about SSO" is completely wrong-headed and detrimental to the overall security posture of any business customer. That is and should be unacceptable.

I made this comment the last time the SSO Tax question came up: We routinely deploy our platform to large customers for 6 or 7 figure contracts. The number of them who actually deployed SSO (without just asking if we comply with it) is less than 20%.

Re: An admittedly wandering defense of the SSO tax

#64
post #41

Earlier quoted context omitted.

Not really. Especially if both systems are already in place and they just need to turn it on. The swipe system should be a very minor or zero part of the rent, not double.

> Not really. Especially if both systems are already in place and they just need to turn it on. This isn't a valid analogy to SSO. SSO doesn't just cost extra to develop (which in itself is a valid reason for charging more), but it costs extra to maintain - you can find several other comments in this thread alone talking about how difficult it is to support SSO from a technical/customer service perspective. People ar…

This is the same for all features no?

If customers need additional human support for SSO then that can be charged separately.

In my experience most customers can get it working with no hassles or have hassle but their own tech resources figure it out. Few need to get support.

As a feature it is probably less work to implement and maintain than the simplest of product features.

YMMV if you have a complicated integration but if you just want to sign people in and assign them to a group for security it isn't hard.

Maybe we are talking cross purposes? I am talking about SSO with SAML and IdP rather than OAuth.

I suspect the reason for the SSO Tax is it is an predictor of "does this customer have money". Customers with more money to spend and absolutely need SSO to meet their policies will overlap alot.

Re: An admittedly wandering defense of the SSO tax

#65
post #64

Earlier quoted context omitted.

> Not really. Especially if both systems are already in place and they just need to turn it on. This isn't a valid analogy to SSO. SSO doesn't just cost extra to develop (which in itself is a valid reason for charging more), but it costs extra to maintain - you can find several other comments in this thread alone talking about how difficult it is to support SSO from a technical/customer service perspective. People ar…

This is the same for all features no? If customers need additional human support for SSO then that can be charged separately. In my experience most customers can get it working with no hassles or have hassle but their own tech resources figure it out. Few need to get support. As a feature it is probably less work to implement and maintain than the simplest of product features. YMMV if you have a complicated integrati…

> If customers need additional human support for SSO then that can be charged separately.

Aren't the majority of enterprise contracts negotiated with support included? I thought that that was one of the main value adds for medium-to-larged sized companies.

Re: An admittedly wandering defense of the SSO tax

#66
post #64

Earlier quoted context omitted.

This is the same for all features no? If customers need additional human support for SSO then that can be charged separately. In my experience most customers can get it working with no hassles or have hassle but their own tech resources figure it out. Few need to get support. As a feature it is probably less work to implement and maintain than the simplest of product features. YMMV if you have a complicated integrati…

> If customers need additional human support for SSO then that can be charged separately. Aren't the majority of enterprise contracts negotiated with support included? I thought that that was one of the main value adds for medium-to-larged sized companies.

I think so. Even more reason to not need SSO tax ;-)

Re: An admittedly wandering defense of the SSO tax

#67

As someone who deals with application support, another big reason is SSO is such a support nightmare. No one wanted to touch SSO tickets because of how frustrating they were to deal with. People wouldn't follow the instructions. Microsoft/Google moved something in their portal and we didn't know so instructions were useless. Microsoft/Google would be having issues and we got tickets because they were still working un…

Yes! We don't charge for SSO, but thankfully we've only had our largest customers ask for it -- and every time it required significant back-and-forth to get it set up. Basically every time somebody comes in with a new IdP, I have to go stand up my own instance so I can figure out what weird combination of options will make it work, because I'm convinced nobody actually understands SAML.

Re: An admittedly wandering defense of the SSO tax

#68
post #3

This car with no seat belts, no airbags, and no ABS is just price discrimination! Strangely, no one seems interested in celebrating the implied discount for not having safety.

Wasn't it true that for a long time that cheaper cars were just less safe than more expensive cars?

Re: An admittedly wandering defense of the SSO tax

#69

Earlier quoted context omitted.

>This is a solid objection that I hadn't considered before! To be quite frank: this strongly suggests that while you put a lot of effort into writing a long article in defense of the SSO tax, you didn't perform more than the most cursory research about why it's a topic of discussion. This argument is literally above the fold on the two top search results for the term. >In short: SSO is a core security requirement for…

>I perfectly understand the rationale behind the pricing model. The point is that "only large enterprises need or care about SSO" is completely wrong-headed and detrimental to the overall security posture of any business customer. That is and should be unacceptable. I made this comment the last time the SSO Tax question came up: We routinely deploy our platform to large customers for 6 or 7 figure contracts. The numb…

FWIW, I've mentioned elsewhere in the thread, but I'm in healthcare. SSO (and MFA) have only really become hot topics in the past 5 years or so.

In the past? People with enough weight would absolutely blow right past implementing SSO if it was slowing them down or adding to their cost.

These days it's a hard requirement for us: if it's not SSO it doesn't go into the environment. That's becoming the norm across the industry.

This is one of those very, very rare cases where healthcare is probably ahead of the curve relative to a lot of other industries. Consequence of being highly targeted by attacks and insurers starting to get very particular about how the ship is run.

Re: An admittedly wandering defense of the SSO tax

#70
post #26

This is a good economics lesson but fails to address the actual issue people have with the SSO tax. It isn't about the concept of price discrimination, but price discrimination when it comes to security . You can charge extra for convenience features or other value-add features, sure, but the choice of login provider is something that should be table stakes for every person and every organization regardless of how bi…

A customer who wants SSO is signaling that they are using this product in their business operations. I.e. they are making money from it. They aren't just learning it, or using it as a hobby. Therefore the product vendor is going to charge the customer at least some approximation of the value the customer is gaining from the product.

The amount of money and budget that a company has can vary wildly. Just because your company uses SSO doesn't mean you're a Fortune 500.

Of course this mostly means that if your required feature set falls into the "Contact us for pricing" tier then you're going to have to talk to a sales rep (probably several, from different vendors so you have a competitive quote) instead of getting any kind transparent pricing.

Post reply on HN