4 ms·
You just made the case for higher pricing. If it’s that valuable then it’s worth the price to secure it. It’s not that sso costs money to implement it’s that
by mattrp 7y ago
You just made the case for higher pricing. If it’s that valuable then it’s worth the price to secure it. It’s not that sso costs money to implement it’s that the price is tied to value of the data and the organization security needs.
Edit: I do agree with you that a lot of enterprise pricing can feel like the vendor simply figured out a % of your ebitda and decided it sounded good to them. But in the examples in the article, most enterprise pricing was fairly well documented / published. If you want to really get into some of the bad actors don’t look at the list from the article, look at the enterprise platforms that are easily into the hundreds of thousands per month... I won’t name names but if your an enterprise IT manager you know who they are.
- eropple 7y agoNo, I made the case that it's a public good to hold that the trivial effort necessary to provide better security can't in good conscience be an upsell. Making it harder to assume a good security posture is bad citizenship and should--frankly, must--be opposed. People are harmed when companies think "security" is an optional feature, and that's not acceptable from either a vendor or an end implementor.
- mattrp 7y agoTo be honest, I find it very difficult to argue against the point you're making. I think it is somewhat logical to have SSO be the demarcation between individuals and enterprise, but if I rewind a decade or so, I imagine the line then was HTTPS (which today is totally ridiculous -- everything is/should be HTTPS). If I could go one step further, I think it's completely wrong for SaaS to blunt force security policies on user's accounts (i.e. ACME would like the ability to read/write to your Google profile). I think enterprises should be able to enforce their policies on the SaaS provider rather than the other way around. And to build for that...I think is going to be a little more complex than a typical user/pass. Maybe everything should be a little more expensive?
- eropple 7y agoThere's a whole tier between "individual" and "enterprise", though, and it's called "small business" and they probably have a lot more of your (and my) stuff than we'd be comfortable having YOLOed around. ;) Enterprises forcing their policies is pretty easy if they're an SP to your directory, FWIW. I've had great success with Okta for this, but I've written SPs that talk to arbitrary OIDC providers and it works pretty well too.
- sokoloff 7y agoPretend that the lower featured, discounted tier doesn’t exist and that “enterprise” is the lowest tier. Does that make anything any better for the world?
- eropple 7y agoYeah I'm not answering that because nobody is actually "discounting" that lower-featured tier, that's a dodge. The base tiers are not discounted. They're the actual price for those features. And that's completely fine. You can have an enterprise tier with more features! What I am saying--and I understand that you understand this but for your question to have any rhetorical impact must misapprehend it--is that they must not be security-based features as it is full-stop unethical to charge a toll for basic security.
- sokoloff 7y agoThey’re the actual price for those features only because of the subsidy provided by selling SSO to enterprise customers, IMO. It’s like arguing that economy airline seating sucks and shouldn’t be allowed to be different than business class. Economy is subsidized by first and business. If you legislate away the difference, it’s not the case that everyone now gets a business class seat at the economy ticket price but much more likely that the other equilibrium emerges where only business class service and pricing is offered.
- eropple 7y agoOoh, analogies. Try this one on for size: "no, you're not allowed to take seat belts away from economy passengers." This shit is baseline. And if it continues to not be, it's time to get legislators involved. Because that's what we all want, I'm sure.