Live data from Hacker News

An admittedly wandering defense of the SSO tax

ssoready.com

11–20 of 99 posts

Re: An admittedly wandering defense of the SSO tax

#12

It's a bad system and you should feel bad for using it. By all means charge enterprises more, but base it on something else, headcount, revenue, non-profit status...whatever. Every time I hear about a data breach I wonder if someone avoided perfectly reasonable SSO protections because of this tax.

If you have enterprise pricing, have substantial enterprise features. That’s it.

Re: An admittedly wandering defense of the SSO tax

#13

It's a bad system and you should feel bad for using it. By all means charge enterprises more, but base it on something else, headcount, revenue, non-profit status...whatever. Every time I hear about a data breach I wonder if someone avoided perfectly reasonable SSO protections because of this tax.

[deleted]

Re: An admittedly wandering defense of the SSO tax

#14
post #8

As someone who deals with application support, another big reason is SSO is such a support nightmare. No one wanted to touch SSO tickets because of how frustrating they were to deal with. People wouldn't follow the instructions. Microsoft/Google moved something in their portal and we didn't know so instructions were useless. Microsoft/Google would be having issues and we got tickets because they were still working un…

This is the real reason there's an SSO tax. It costs to support SSO, the customers who want SSO should pay for that cost.

I would agree that this cost-plus pricing structure applies in some cases. Some companies definitely want to constrain the universe of SSO users.

But this will usually show up in pricing structures with SSO as a relatively inexpensive add-on feature -- not as part of an indivisible bundle.

Seemingly we want to talk about both of these things as "the SSO tax" but I think we can agree that they're pretty different scenarios.

Re: An admittedly wandering defense of the SSO tax

#15
post #6

I get that there's some correlation between hacker culture and piracy and free as in gratis. But lately I've seen a flood of flat out complaining about things costing money. As software devs we should be for software having a price tag, not against it

The complaint isn't about anything costing money. It is about making SSO an enterprise feature which pushes the price up alot. At the same time SSO is good for security. So it is like an office space charging double for swipe cards instead of a number lock.

I think what annoys people is the reason why: a way to make more money from enterprises, and that they could make that money some other way.

Re: An admittedly wandering defense of the SSO tax

#16
post #8

As someone who deals with application support, another big reason is SSO is such a support nightmare. No one wanted to touch SSO tickets because of how frustrating they were to deal with. People wouldn't follow the instructions. Microsoft/Google moved something in their portal and we didn't know so instructions were useless. Microsoft/Google would be having issues and we got tickets because they were still working un…

This is the real reason there's an SSO tax. It costs to support SSO, the customers who want SSO should pay for that cost.

I thought some company had free SSO for Google and 365 only and advanced SSO on the enterprise tier. I don't remember which company though, so maybe I made this up.

Re: An admittedly wandering defense of the SSO tax

#17
post #3

This car with no seat belts, no airbags, and no ABS is just price discrimination! Strangely, no one seems interested in celebrating the implied discount for not having safety.

This is a solid objection that I hadn't considered before! Why isn't SAML SSO mandated (either literally or my convention)? Practically speaking, as someone who spends all day trying to convince developers to implement SAML SSO, I really wish this were the case :) I think in practice, software vendors correctly assess that relatively few of their prospective customers actually care. If many small / price sensitive co…

I also don't want to mandate anything but as an industry we have to find some way to do better on security. Free SSO and 2FA with very strong nudges seems like a good path.

Re: An admittedly wandering defense of the SSO tax

#18
post #3

This car with no seat belts, no airbags, and no ABS is just price discrimination! Strangely, no one seems interested in celebrating the implied discount for not having safety.

This is a solid objection that I hadn't considered before! Why isn't SAML SSO mandated (either literally or my convention)? Practically speaking, as someone who spends all day trying to convince developers to implement SAML SSO, I really wish this were the case :) I think in practice, software vendors correctly assess that relatively few of their prospective customers actually care. If many small / price sensitive co…

On a lot of issues (passwords, SQL injection, automated deployments), buyers originally didn't care much about security, but the security community slowly but surely managed to shift norms and get doing the right thing to become normalized. I think that could happen on SSO too, if not for the fact that it's so effective as a price discriminator, which in turn I think makes it less likely to happen absent some kind of regulation. (Developers at small companies might not care, or they might want to do the right thing but be unable to justify it to the boss; meanwhile, SSO is usually a non-negotiable requirement for enterprises. I think that's a bigger factor than apathy or "price sensitivity" (enterprises are often extremely price-sensitive) in why it's such a good discriminator.)

I favor regulation on this, even though it's probably not necessary in every case, simply because I don't see any other way to break this equilibrium.

Re: An admittedly wandering defense of the SSO tax

#19
My job involves working with customers to test out products - has for years, and for several jobs. None of my products have ever charged extra for SSO, and most require it, so I get to deal with it all the time.

For the past 5+ years, the part of configuration that takes the longest - by far - is always SSO. I cannot imagine the amount of added support calls, time, and frustration brought about by it, so I can completely understand why some companies gate it behind more expensive tiers.

Re: An admittedly wandering defense of the SSO tax

#20
post #15
post #6

I get that there's some correlation between hacker culture and piracy and free as in gratis. But lately I've seen a flood of flat out complaining about things costing money. As software devs we should be for software having a price tag, not against it

The complaint isn't about anything costing money. It is about making SSO an enterprise feature which pushes the price up alot. At the same time SSO is good for security. So it is like an office space charging double for swipe cards instead of a number lock. I think what annoys people is the reason why: a way to make more money from enterprises, and that they could make that money some other way.

> So it is like an office space charging double for swipe cards instead of a number lock.

If the landlord had to hire a bunch of extra support people, with expertise outside their normal domain, just to support swipe cards then this would make sense, no?

I can imagine a lot of products where accompany literally could not afford to provide support for SSO issues to a basic tier customer with 100 employees

Post reply on HN