Live data from Hacker News

Okta Personal

oktapersonal.com

41–50 of 53 posts

Re: Okta Personal

#42
post #36

This must be a joke or a hoax. The ChatGPT blurb made me question it, but the whois data sealed the deal. It's registered on GoDaddy with a private registrant. https://www.godaddy.com/whois/results.aspx?domain=oktaperson...

https://support.okta.com/help/s/okta-personal/about-okta-per...

Specifically the following page links to oktapersonal.com: https://support.okta.com/help/s/okta-personal/using-okta-per...

Re: Okta Personal

#44
post #39

Earlier quoted context omitted.

As a former IT admin who administered Okta it’s pretty feature rich and I thought the UX was pretty good compared to Microsoft

I use Okta and Microsoft’s Intune/MFA/SSO and I’m not sure which is better. Neither is that great I think. The think that’s annoying to me is the price is $2-11/user/month for sso. That’s crazy considering orgs have thousands of employees that need this and previous self-hosted solutions from CA and others were $50-100k for unlimited accounts. And this seems like an odd place per user and it costs similar amounts to…

What's more annoying is that every sass product on the planet puts sso behind their most expensive "ask us the price" tier.

Microsoft should be including sso in their baseline/free products and all enterprise and wanna-be-enterprise software should put it in its base tier.

Logon security shouldn't be tucked behind a paywall or held hostage as a bonus quadruple the price feature, because breaches have wide reaching consequences past just the company attacked going down.

Re: Okta Personal

#45

as suspicious as the domain may look, it does link out to personal.okta.com for account creation. the privacy policy is also a link to okta.com. despite the chatgpt reference, it appears to be a legitimate marketing domain for okta.

Why even have oktapersonal.com? personal.okta.com is almost the same number of characters - just an extra period. Is it purely for SEO purposes? Is it because a company can be named “personal”, and so personal.okta.com would be taken by an enterprise customer? Naming conventions like this really trigger my phishy senses.

It drives me nuts that the web went away from this kind of "use a subdomain to prove ownership" to "register a cute .com that looks like phishing."

It's made trust so much harder to establish, and completely ruined any sort of ability to educate others on how to read urls.

Even local governments have moved to citystate.gov instead of city.state.gov.

Re: Okta Personal

#47
post #17

I’ve used Okta for work and I don’t love it. Does anyone love it? I buy it but it seems really expensive and not a fantastic UX. It’s weird how expensive and complicated this is and I’m surprised there aren’t more competitors because the cost should be rather low.

I use auth0 and like it, and I dread the day that Okta decides to "harmonize" the experience by replacing it all.

Re: Okta Personal

#48
post #44
post #39

Earlier quoted context omitted.

I use Okta and Microsoft’s Intune/MFA/SSO and I’m not sure which is better. Neither is that great I think. The think that’s annoying to me is the price is $2-11/user/month for sso. That’s crazy considering orgs have thousands of employees that need this and previous self-hosted solutions from CA and others were $50-100k for unlimited accounts. And this seems like an odd place per user and it costs similar amounts to…

What's more annoying is that every sass product on the planet puts sso behind their most expensive "ask us the price" tier. Microsoft should be including sso in their baseline/free products and all enterprise and wanna-be-enterprise software should put it in its base tier. Logon security shouldn't be tucked behind a paywall or held hostage as a bonus quadruple the price feature, because breaches have wide reaching co…

I fully agree with you about the SSO tax.

I would like to add that configuring Azure AD as an SSO provider is available to any tenant free. Some of the functionality like Conditional Access does require paid licensing.

I’m aware of a number of businesses that are very happily using Keycloak in production. Not everyone can, although there is RH SSO if you need the support contract.

Then there’s Gluu, Authelia, and many others depending on your needs.

Sadly even with basic security we can’t seem to fully trust our own vendors to have our interests at heart.

Re: Okta Personal

#49
post #36

This must be a joke or a hoax. The ChatGPT blurb made me question it, but the whois data sealed the deal. It's registered on GoDaddy with a private registrant. https://www.godaddy.com/whois/results.aspx?domain=oktaperson...

This is not unusual even for very large companies anymore. Somehow GoDaddy actually gets this sort of business from companies that -should- know better than to do business with GoDaddy.

More than a few on the Fortune 500, for example.

Re: Okta Personal

#50
post #44

Earlier quoted context omitted.

What's more annoying is that every sass product on the planet puts sso behind their most expensive "ask us the price" tier. Microsoft should be including sso in their baseline/free products and all enterprise and wanna-be-enterprise software should put it in its base tier. Logon security shouldn't be tucked behind a paywall or held hostage as a bonus quadruple the price feature, because breaches have wide reaching co…

I fully agree with you about the SSO tax. I would like to add that configuring Azure AD as an SSO provider is available to any tenant free. Some of the functionality like Conditional Access does require paid licensing. I’m aware of a number of businesses that are very happily using Keycloak in production. Not everyone can, although there is RH SSO if you need the support contract. Then there’s Gluu, Authelia, and man…

SSO without conditional access is almost worse. It's like Microsoft knows it COULD stop attackers from entering the account, but wont unless you pay them more. To give them credit, at least MFAuthenticator apps are free (and now basically forced.)
Post reply on HN