5 ms·
I don't get what's wrong with charging more for SSO? They're in the business of making money, and if you need SSO and you need their service you're more likely
by danmur 2y ago
I don't get what's wrong with charging more for SSO? They're in the business of making money, and if you need SSO and you need their service you're more likely to have money. It's nothing to do with the feature itself.
- earnesti 2y agoI don't think there is anything wrong about it, but I think it is a good thing to be informed about it, especially for those involved with smaller businesses.
- danmur 2y agoI don't disagree, but I doubt anyone's going to use this website called the 'wall of shame' to get pricing info rather than look at the pricing page.
- michaelt 2y agoThe problem is we in the software industry are so used to getting handed everything for free that a lot of software developers don't even know how to get their employer to buy something. Every engineer in every other field of engineering knows exactly how to order things, and has access to a properly organised budget for doing so. You need electronic components? Custom-machined parts? Raw material like metal sheets? Nuts and bolts? Aluminium extrusion? Of course you pay for it - and the organisation's purchasing procedure is something you learn in your first week. We in the software industry, on the other hand, get free operating systems, free compilers, free IDEs, free databases, free libraries, free documentation and training, free support - pretty much free everything. So you can get surprisingly far in the industry without ever learning the difference between a quote and a proforma invoice - or how to explain to the boss why we should give JetBrains $50k per year in terms she'll understand and approve of. As such, when the people gifting us and our employers free stuff add a paid tier with features we want, but they charge money for it, it's an almighty inconvenience.
- ikiris 2y agoNo, this is nowhere close to it.
- solatic 2y agoIf you're storing passwords for the non-SSO option then you're hurting yourself as well as your customers, because storing passwords is a massive security and operational headache. If your limited SSO options, before charging the SSO tax, are "social" (e.g. Google) logins, then you're letting BigTech in between you and your customers. I'm all for price discrimination, but SSO is the exception, because the alternative is too expensive.
- halJordan 2y agoIf you dont remember sso was sold as a panacea, and there was a lot of lip service to it. Whether you believe it is or is not matters less than what the industry promised. So selling this fundamental, foundational security service as a top tier premium value add is disingenuous, and either deceitful or greedy. And frankly if you're overly cynical about it; it's a lot like streaming in the sense of why am i forced to pay 10 vendors for the same library? There's a data ownership issue, why am i forced to let them own my user data on their cloud unless i pay for the privilege of owning my own data?
- Terretta 2y agoEVERYONE needs SSO. 1. SaaS providers need it so they don't store your creds. If they don't store them, they can't leak them. 2. You need it because 1. 3. Nobody needs SSO any more :-) Actually you only need OpenID Connect which shows up as "Sign in with" or "Continue with", which -- if coupled with a domain name validation on your canonical user ID -- amounts to most of the same value as the complicated SSO / SAML dance without per customer config. It is less work for a SaaS provider to support sign in with than to make an entire auth chain. My current recommendation to new SaaS offerings is OIDC plus magic links as a fallback. (Many SaaS go a very long way with just magic links, those plus a domain name in email address check can also tie employees to a company, regardless of the company's IdP.) All that said, SCIM and group-to-role sync, etc., should be EXTRA. You need extra moving parts, and enterprises with information barrier or other compliance or regulatory obligations are thrilled to pay for this.
- OkayPhysicist 2y agoThe argument for it is that SSO should be treated as a basic security feature. It'd be like if you had to cough up enterprise pricing for the company to keep your passwords hashed instead of in plain text.
- danmur 2y agoYou don't have to use the service though! Can't afford it, don't use it. The price to get x service with the features you want is y no matter how you slice it by feature.
- throwaway48476 2y agoThe problem is the cost of data breaches is shared. "You" might always pay for security but the number of data breaches that happen indicate that not very one does yet they affect you all the same.