4 ms·
Because in both auth and email one can make a small screw-up that allows for a company threatening breach. As someone who has performed penetration tests for al
by photon12 5y ago
Because in both auth and email one can make a small screw-up that allows for a company threatening breach. As someone who has performed penetration tests for all of: companies that roll their own SSO, companies that use a third party SSO service, companies that provide third party SSO services, the failure modes for contracting out to a third party are a bit easier to manage if you are a small company, and chances are if your SSO provider is breached they are going to care about bigger fish than you.
For medium to large enterprises, the calculus is harder and there's going to be months of flame war trying to hash that out.