Live data from Hacker News

An admittedly wandering defense of the SSO tax

ssoready.com

51–60 of 99 posts

Re: An admittedly wandering defense of the SSO tax

#51

Earlier quoted context omitted.

>This is a solid objection that I hadn't considered before! To be quite frank: this strongly suggests that while you put a lot of effort into writing a long article in defense of the SSO tax, you didn't perform more than the most cursory research about why it's a topic of discussion. This argument is literally above the fold on the two top search results for the term. >In short: SSO is a core security requirement for…

>>In short: SSO is a core security requirement for any company with more than five employees. This is from a random website with no credentials that makes no arguments to back up its claim. It's meaningless. >>Imagine buying a car and the manufacturer asks for an extra payment to unlock 100% of the braking power. And this is a fatally flawed analogy that renders it useless. The situations of "hardware shipped that ca…

>This is from a random website with no credentials that makes no arguments to back up its claim. It's meaningless.

Appeal to authority. Meaningless.

All I was pointing out with those links is that literally Googling the term "SSO tax" and clicking the first link at least hints at some of the reasoning behind people making an issue of this. The fact that TFA doesn't address any of the actual concerns people have in any meaningful way makes it of incredibly limited usefulness in the overall discussion.

> The situations of "hardware shipped that can't be unlocked until user pays" and "paying additional to support a feature that takes a lot of effort to develop, and actively takes more effort from the vendor to support" aren't remotely comparable.

Then charge for the support. The issue is that the only way to purchase a core security feature is bundled in with other features that the user doesn't necessarily want or need, very often at several multiples of the price for the features they do want.

>That doesn't sound very believable to me - small businesses are both disproportionately smaller targets, and also have much less complex IT systems with fewer logins to manage.

This is working from the faulty assumption that potential customers only exist in a binary between the nebulous "enterprise" and "small business with barely any IT competency."

I live in the enterprise healthcare world. It's routine for us to consider software purchases at the departmental level to fill a specific need for a particular team. We have hard requirements for SSO. Some of it's driven by internal policy, some of it's driven by auditors increasingly demanding MFA everywhere.

I have personally killed deals over this exact issue on a more routine basis than I'd like. Department head thinks cost is going to be Y. Cost is actually 5-10Y because the only way to purchase SSO support is via an "enterprise" bundle with additional features they don't need and an inflated minimum seat-count buy. We'd happily pay some middle ground for SSO support, but the option to buy it doesn't exist.

The issue is not charging for things that have support costs; it's forcing a customer into drastically higher pricing tiers under the assumption that running SSO is a signal that a potential customer has a super sophisticated environment and bottomless pockets. That was the world of 15 years ago, sure, but it's not today.

The reality is we live in a world where there are increasingly strict security requirements in many industries and any business paying, e.g., $6/user/month for Microsoft 365 has SSO available as an option.

Re: An admittedly wandering defense of the SSO tax

#52

The reality is much simpler than the article would have you believe. The article goes through all these convoluted explanations about value add but the simple fact of the matter is that SSO is the one differentiator that businesses will guarantee pay for. The other features are often unknown to stakeholders outside of the internal champion and need explanation oftentimes. But SSO, enterprises always need at a certain…

I'm in the healthcare world. SSO is a hard requirement for us. There have been many, many times where we've considered an application where we could justify the spend at, e.g., the departmental level for the limited user base that needed it, but where SSO being bundled into higher price tiers combined with minimum user counts took a potential solution from "very easy discretionary spend" to "not happening, full stop.…

Curious: Are SaaS sales unrepentant on pricing in these cases? I would think with a bit of spice on your side in procurement you could probably negotiate enterprise for a small premium over the middle tier. Knowing enough software sales people when given the choice between “Teams + $5/user/head” and “no sale at all” suddenly options open up. But maybe the people I know don’t support too much SSO stuff…

Re: An admittedly wandering defense of the SSO tax

#53

Earlier quoted context omitted.

This is a solid objection that I hadn't considered before! Why isn't SAML SSO mandated (either literally or my convention)? Practically speaking, as someone who spends all day trying to convince developers to implement SAML SSO, I really wish this were the case :) I think in practice, software vendors correctly assess that relatively few of their prospective customers actually care. If many small / price sensitive co…

> Why isn't SAML SSO mandated SAML isn't exactly the best choice here. It's very SOAP-y; that's like being in 2005 and mandating everyone use SOAP+RPC for interopability.

[deleted]

Re: An admittedly wandering defense of the SSO tax

#54

This argument is basically wrong because it supposes companies don't have market power when they do. "Market power" doesn't mean monopoly. It takes at least four and more often at least a dozen viable competitors before you have enough that there isn't an implicit cartel, and there are altogether too many markets where this is the case. Nearly all specialty or line of business software, for example. These markets com…

I can identify basically three criticisms of my argument in your post. (1) That I assume companies never have market power. (2) That I suppose "market power" implies monopoly (3) That my example was cherry-picked. 1. I did no such thing. I explicitly acknowledged market power several times. 2. Again, not correct. I explicitly mentioned oligopoly (assuming that 'imperfect competition' wouldn't land). 3. Of course it w…

> I did no such thing. I explicitly acknowledged market power several times.

Your premise is that if market power exists then market power is the problem rather than price discrimination. The issue is that price discrimination isn't possible without market power. Its presence implies that the company both is capable of and is overcharging the people coerced into the higher price tier.

> That I suppose "market power" implies monopoly

This is not an argument you make explicitly, but it's something readers commonly assume and my point is to highlight that companies successfully engaged in price discrimination can and do have market power even if they don't have a full monopoly.

> Of course it was. I acknowledged as much! I quite literally said the example doesn't generalize. The example serves to illustrate a 'there exists' claim. I felt a concrete example would be easier to follow than some kind of generalized model.

And I'm providing the 'there exists' claim for the alternative, to demonstrate that price discrimination can be (and often is) detrimental to customers without providing any countervailing benefit to any of them.

> The obvious observation we can make is that such competitive dynamics imply that no one would make any profit!

Profit doesn't really work that way. For example, if a company takes investment and uses it to buy a building to operate out of, the money not paid as rent to a landlord is added to the investor's profit, but if the company takes less investment and instead pays rent, the same money is counted as operating costs. Likewise, if you develop software needed before you can start operating and you take investment to pay for it, the net returns are called profit, but if you take a bank loan to pay for it then the interest on the loan is counted as operating costs again. The interest rate you'd pay the bank would even be proportional to the risk you'd fail, unless you post collateral, for which you'd need an investor.

So a company that didn't take any investment and operated entirely by renting everything, taking loans and using off-the-shelf software instead of developing anything in-house wouldn't be expected to make any profits in a perfectly competitive market -- and there would also be no investors to pay any profits to. Profit in companies that take investment would still be present and equal the cost (time value) of the assets bought with the money, but in a perfectly competitive market this would exactly equal the risk-adjusted market rate of return in the overall capital markets.

The distinction in uncompetitive markets is that profit exceeds that amount. (Or at least can; a market can be uncompetitive and then the companies become inefficient from lack of competitive pressure and waste the money they extract from customers instead of returning it to investors.)

It's true that "perfectly" competitive markets don't exist in the same sense that perfect anything doesn't exist, but this is splitting hairs. A gold coin might be .999 gold and you can say that it isn't perfect but you can still distinguish it from a wooden nickel.

Re: An admittedly wandering defense of the SSO tax

#55
post #26

This is a good economics lesson but fails to address the actual issue people have with the SSO tax. It isn't about the concept of price discrimination, but price discrimination when it comes to security . You can charge extra for convenience features or other value-add features, sure, but the choice of login provider is something that should be table stakes for every person and every organization regardless of how bi…

There's no moral valence to price discrimination on enterprise security features.

Re: An admittedly wandering defense of the SSO tax

#56
post #3

This car with no seat belts, no airbags, and no ABS is just price discrimination! Strangely, no one seems interested in celebrating the implied discount for not having safety.

It is in fact reasonable to charge more for vehicles suitable for commercial fleets and applications than for commuter vehicles.

Re: An admittedly wandering defense of the SSO tax

#57
No problem at all with the concept of price discrimination. The economics make sense. In any scenario where unit costs are low, but development costs are high, the ideal situation is where everyone gets the benefit of having the product at a price they are willing to pay. Maximizes total value to all parties.

The problem with the SSO tax is that it wedges itself into the pre-existing cracks in most organizations. Security practitioners are already in conflict with other departments. What happens when a department head has pitched a new SaaS as being 1x price, but then it becomes 2x price after the security team's requirements are added? It is not seen as the [application is expensive], it seen as [security team's requirements have doubled the price]. Conversely a price discrimination strategy which locks specific user facing features behind a specific tiers means that the same person championing the software, would also advocate for the appropriate payment tier.

Price discrimination is a valid strategy. Responding to organizations who are actively making the security practitioners job more difficult is also valid.

Re: An admittedly wandering defense of the SSO tax

#58

As someone who deals with application support, another big reason is SSO is such a support nightmare. No one wanted to touch SSO tickets because of how frustrating they were to deal with. People wouldn't follow the instructions. Microsoft/Google moved something in their portal and we didn't know so instructions were useless. Microsoft/Google would be having issues and we got tickets because they were still working un…

I was lead engineer for a startup. By virtue of being the most flexible in my day-to-day, I ran front line for most of the customer support issues. SSO issues took exponentially longer than nearly every other support issue and accounted for well over 50% of our support efforts. We didn’t really feel like there was much we could do about it either. Most of it came down to the fact that the user of our application was…

Yeah but does that require any expertise to solve? It’s a bunch of meaningless arcana, for which the other party pays well. Seems like a fair deal. Someday you might get big enough where it’s minions talking to minions, or so big that people simply accept no customer service as the status quo.

Re: An admittedly wandering defense of the SSO tax

#59
post #26

This is a good economics lesson but fails to address the actual issue people have with the SSO tax. It isn't about the concept of price discrimination, but price discrimination when it comes to security . You can charge extra for convenience features or other value-add features, sure, but the choice of login provider is something that should be table stakes for every person and every organization regardless of how bi…

A customer who wants SSO is signaling that they are using this product in their business operations. I.e. they are making money from it. They aren't just learning it, or using it as a hobby. Therefore the product vendor is going to charge the customer at least some approximation of the value the customer is gaining from the product.

Re: An admittedly wandering defense of the SSO tax

#60

I was responsible for IT in a hypergrowth scale-up and I don’t like this article, it misrepresents the problem. The problem is, when you are big enough to set up SSO like Okta, you have to upgrade nearly all of your subscriptions in a short time to make use of it, suddenly resulting in a huge increase in the budget. So, let’s say the business goes from X to 2X in revenue and from X to almost 2X in staff (let’s assume…

Let’s not forget that the whole reason your company needs to upgrade all its subscriptions for SSO is so it can get a soc2 and offer its own high-priced enterprise plan (which is probably gated by SSO).
Post reply on HN