8 ms·
This is a great change! One request: I wish that SAML was not an enterprise feature. SAML ought be a basic security feature like 2FA—it's especially valuable fo
by thramp 6y ago
This is a great change! One request: I wish that SAML was not an enterprise feature. SAML ought be a basic security feature like 2FA—it's especially valuable for open source teams who might use a mixture of services, and an easily accessible and cheap SSO solution would go a long way in raising the security bar for all teams, not just open source teams.
- vermorel 6y agoAgreed. SAML even makes sense for solo dev.
- harha 6y agocould you elaborate further with use-cases?
- tiffanyh 6y agoNot having to create separate usernames and passwords with yet another service (GitHub)
- m01 6y agoWith GitHub (cloud version) specifically it doesn't (currently) work that way, you still need a "normal" GitHub username and password, and you do the organisational SAML login in regular intervals when trying to access that org's resources. I'm not aware of this being a widespread way of doing SAML, but I guess it supports certain use-cases (like keeping a GitHub identity despite switching jobs/OSS projects). sources: * https://help.github.com/en/github/setting-up-and-managing-organizations-and-teams/about-identity-and-access-management-with-saml-single-sign-on https://help.github.com/en/github/setting-up-and-managing-or... * https://help.github.com/en/github/authenticating-to-github/about-authentication-with-saml-single-sign-on https://help.github.com/en/github/authenticating-to-github/a... [edit: formatting]
- eastbayjake 6y agoAs a business customer of a SaaS product, being able to revoke any employee's access to the SaaS tool if they are terminated. (Imagine how hard this would be for e.g. the SaaS tool your company uses to view financial reporting if it required every user at your company to create their own username/password. If you wanted to prevent someone from "going rogue" during termination, you would need to have an admin remove their account access prior to termination -- and do it on every SaaS product that person used. With SSO you revoke their access and everything gets locked out. Source: Watching an alcoholic CTO get fired by the board and taking the startup's hosted Mongo database hostage
- jfkebwjsbx 6y agoI agree, but I think the GP was asking about use cases for a solo dev.
- eastbayjake 6y agoGood clarification! If you're a solo dev who wants to sell your side project to any company >500 people, SAML integration is tablestakes. If you're a solo dev who needs to secure your hobby project on the public internet, it's like bringing a Space Shuttle engine to a knife fight.
- jholman 6y agoIf I was in a knife fight, and my buddy showed up and just hit the guy I was fighting with a SSME, I would be totally impressed and also grateful.
- nogabebop23 6y agoSo you care a lot about this, but not $4/month care?
- JMTQp8lwXL 6y agoStuff like SAML is kind of the only leverage freemium SaaS has for rationalizing charging enterprise customers.
- atonse 6y agoNot true. There are other things (like audit logs, invoice/PO payments, better support) that enterprises will still want.
- ryanisnan 6y agoYeah but considering SAML is one of the primary asks of enterprise, it kind of makes it a big selling point.
- Spivak 6y agoAnd people keep saying that it's a security feature but that's not why large orgs pay for it. It's a "I'll pay you to not have to manually manage account access to all these different services.
- Corrado 6y agoYes, I'm pretty happy with the new pricing but my employer will probably have to go with the Enterprise plan to get access to the "Audit Log" and HIPAA compliance. :frown:
- JMTQp8lwXL 6y agoIf it's possible for GH to run a profitable business while offering SAML integration for free, I am 100% supportive of the suggestion. It's hard to say exactly how many enterprises pay specifically or exclusively for this reason, as opposed to other enterprise features, like audit trails.
- vptr 6y agoAgree. I sell simple sass product myself and offer SAML to everyone. I view security as a basic right, not something to be used to extract more money for. Charging for additional features is ok, charging for keeping your account more secure is just plain wrong.
- hirako2000 6y agoBut saml is for integration (SSO). Github provides 2fa for free. What enterprise is paying is the convenience, not security itself.
- tptacek 6y agoSSO is a security feature, not a convenience. It happens to be a security feature that comes bundled with some extra convenience, but it's not the only one like that; so are password managers.
- deleted 6y ago[deleted]
- alberth 6y ago+1 Even the ability to just “login with gmail” for non-enterprise accounts would be huge
- Saaster 6y agoSAML (and 2FA to a lesser extent) comes with some serious support burdens on the companies offering it. There's a long tail of more or less broken SAML implementations on both the service and identity provider sides, provisioning issues, configuration issues, "Sally can't login on Tuesdays" issues, duplicated slightly-inconsistent data in IdP and Service side records issues... If you as a SaaS provider outsource your SAML integration to a third party provider like Okta or Auth0, the auth provider pricing is immediately on a "call us" tier, with a per-federation pricing in the low four figures for each company connecting via SAML. Let me just state that again, to have company X connect to my SaaS via SAML, I as the SaaS provider have to pay my auth provider $X,000 per year for the privilege, not counting the base enterprise tier pricing for the auth.
- derefr 6y agoSounds like SAML needs the same "everyone gets together to make a FOSS implementation that knows about the weird quirks of all the implementations it interacts with" approach that e.g. the Samba project was founded upon.
- Saaster 6y agoI agree. There's a million SAML for Java/Python/Node.js/Foo libraries out there, all with a long list of issues and known cases that don't work correctly, security issues etc. but it's the wrong model in my opinion. Instead of directly bolting SAML into your app, I think a FOSS implementation of an independently running service is the way to go. You run the battle tested open source service (locally / in your cloud), it accepts the SAML assertions and mints something sane like JWTs which can easily be consumed by the service providers, isolating the entire thing from your core app and allowing it be used with any stack. E.g. essentially an open source locally deployed Okta. Doesn't even need to do any user management, just focus on rock solid interoperability and forward all decision making to the actual app server.
- chrisweekly 6y ago+1 Wish I had more upvotes to give. This should exist.
- tobinfricke 6y agoI'd never heard of SAML before. Is it like a more complicated version of OAuth?
- jaywalk 6y agoBasically, yes. Give me a choice between SAML and OIDC, and I'll choose OIDC every single time.
- kube-system 6y agoSAML has been around longer and handles AuthN and AuthZ OAuth only does AuthZ. I've always found OAuth more complicated because you have to combine it with other technologies to get AuthN
- gknoy 6y agoFor those like me who had never heard these abbreviations: AuthN: Authentication (who you are) AuthZ: Authorization (what you are allowed to do)
- thinkharderdev 6y agoOpenID Connect is the standardized AuthN process built on top of OAuth. It’s “on top of” but in practice it’s a simplification if OAuth for the specific purpose of AuttN
- kube-system 6y agoI know, I just personally find it to be a fragmented and confusing set of standards. And a lot of people say OAuth when they mean OpenID Connect, which doesn't help with the confusion... or they abbreviate OpenID Connect as "OpenID" which also means something else. I've never had to clarify what someone is actually trying to accomplish when they want "SAML 2.0"
- tptacek 6y agoYou said "OAuth only does authz and must be combined with other technologies to get authn"; obviously, that's not true, in the sense that you can simply use OIDC --- a dialect of OAuth --- to get both. Since OIDC is better than SAML, which is probably the scariest security standard on the Internet, I think it's worth being clear to people that OIDC/OAuth is viable. The SAML authz story, for what it's worth, is pretty shady.
- tptacek 6y agoSince they just said they were waiting for Enterprise revenue to reach a level where they could free the core product, and since SAML is an important driver of Enterprise upgrades (I've seen it happen), I wouldn't hold your breath. Now that the core Pro features are free, I wonder if Rob will update sso.tax to set Github to :inf:.
- thramp 6y agoI was _just_ thinking of https://latacora.micro.blog/2020/03/12/the-soc-starting.html https://latacora.micro.blog/2020/03/12/the-soc-starting.html and https://sso.tax/ https://sso.tax/ as I was writing my comment!