6 ms·
https://sso.tax/ https://sso.tax/ a lot of companies put SSO behind a paywall. Not a fan of making users pay for basic security features.
by mffap 4y ago
https://sso.tax/ https://sso.tax/ a lot of companies put SSO behind a paywall. Not a fan of making users pay for basic security features.
- jrockway 4y agoIt cuts both ways. While SSO is a basic security feature (and improves usability and reduces support burden), it also makes account sharing more difficult. Users on the low end plan definitely like account sharing; create a google group as the email, put the password in the shared vault, now the thing is $5/month instead of $30k a year.
- r00fus 4y agoWhich is why a lot of services (ie, commercial APIs) rely on # of hits/uses as a measure.
- jrockway 4y agoYou have to be a really useful service to price things this way. "Per user per month" means that people that don't use your software are still paying for it, which I guess is the best kind of user -- not adding any database rows, not burning any CPU, and not opening any support tickets. Good work if you can get it! Use-based pricing is my favorite pricing method, but your product has to be useful if you want to charge based on use. Most people don't have the guts to do it, because the "per user per month" is such an easy way to get money. If you go for use-based pricing, you have to make sure people actually use your thing, which is hard work!
- r00fus 4y agoIt mainly happens with B2B (e.g. forex rate services like xignite or Bloomberg).
- lmkg 4y agoI think I read somewhere that many companies use "needs SSO" as a proxy for "is Enterprise customer and can pay Enterprise rates."
- speedgoose 4y agoWhich is wrong and a waste of time for both sides.
- Spivak 4y agoI mean the alternative is the fat wallet tax. Is your company more than 20 employees or do you have more than 1M revenue, here’s a 500% price increase. If you’re at the point where employees x services is too big to do manually and then congrats you graduated to the “actually paying for the service tier.” There’s no real way to skin, “the only real money is by charging many dollars to large enterprises and if we can’t easily price discriminate the thing we’re dropping is the subsidized free/startup tier.
- speedgoose 4y agoHaving more than 20 employees or 1M revenues isn’t going to make an expensive product more attractive. I have been quoted twice this year at prices where hiring competent people would be a lot cheaper than purchasing the SSO option. But I understand the need to milk the badly managed companies.
- Spivak 4y agoOn the buying side we always used to joke that we could hire someone who’s entire job would be updating peoples passwords for less than they were charging and still have 30hrs/wk of an engineer. Sadly no one volunteers to be the password bitch.
- speedgoose 4y agoYou could always pick one randomly and you will soon get a script to automate everything.
- f38zf5vdt 4y agoAs much as people wish that they can get SSO for free, I don't think it's realistic for many companies. There are a lot of different SSO standards out there, and even among the most common type (SAML2) there are many different SP and IDP implementations that you have to interface with to make SSO work properly. Then there are issues around attribute syncing, patching XML vulnerabilities on your implementation (which seem to occur regularly), dealing with customers updating or patching their own implementations, homebake obscurities in implementations for things like NameID and attribute, and myriad other complications. At minimum I think it's reasonable to charge for SSO onboarding and maintenance on as as-needed basis.
- atonse 4y agoNot really anymore. There are many places that do self service SSO after charging you for it. The best happy medium I’ve found is allowing “sign in with google” for free and true SAML paid.
- josephcsible 4y agoAh, I hadn't thought of this: open core reduces security.