sso-wall-of-shame

A list of vendors that treat single sign-on as a luxury feature, not a core security requirement. (by robchahin)

Sso-wall-of-shame Alternatives

Similar projects and alternatives to sso-wall-of-shame

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a better sso-wall-of-shame alternative or higher similarity.

sso-wall-of-shame discussion

Log in or Post with

sso-wall-of-shame reviews and mentions

Posts with mentions or reviews of sso-wall-of-shame. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2024-06-04.
  • Encryption at Rest: Whose Threat Model Is It Anyway?
    3 projects | news.ycombinator.com | 4 Jun 2024
    SaaS vendors charging a big premium for customers locked in that have compliance requirements is nothing new; itā€™s basically a standard play in the rentseeking startup model:

    https://sso.tax/

  • Show HN: I'm tired of S3 and all the nonsense around it
    1 project | news.ycombinator.com | 29 May 2024
    In short: SSO is a core security requirement for any company [customer] with more than five employees.

    SaaS vendors appear not to have received this message, however. SSO is often only available as part of ā€œEnterpriseā€ pricing, which assumes either a huge number of users (minimum seat count) or is force-bundled with other ā€œEnterpriseā€ features which may have no value to the company using the software.

    If companies claim to ā€œtake your security seriouslyā€, then SSO should be available as a feature that is either:

    - part of the core product, or

    - an optional paid extra for a reasonable delta, or

    - attached to a price tier, but with a reasonably small gap between the non-SSO tier and SSO tiers.

    https://sso.tax/

  • Tailscale SSH is now Generally Available
    1 project | news.ycombinator.com | 18 Apr 2024
    Hi! Tailscalar here. This is very topical for me! Over the past 3 weeks I've been working with internal stakeholders to remove our SSO tax - the sso tax is a pet hate of mine. A couple of weeks ago we removed it from our pricing plan after my proposal was approved, and today I released a blog on our website to announce it more widely: https://tailscale.com/blog/sso-tax-cut

    I knew of https://sso.tax (which we are not listed on but I did include in my blog), but didn't know there was another website too!

  • Software Company HashiCorp Is Weighing a Potential Sale
    4 projects | news.ycombinator.com | 16 Mar 2024
    I'm not the person you've asked, but I'm somebody who has been purchasing SaaS/software for businesses large and small for years. My take:

    1. If SSO and other basic modern security features are locked into "Enterprise" pricing tiers then the service is at the bottom of the list (see: https://sso.tax). I'd love to say instant disqualification but too many SaaS companies have it in their head that only wealthy enterprises use SSO, despite SSO platforms being widely available and some quite cheap to acquire and start using.

    2. If I need to request a quote to start any kind of service to see what the product is about then I'm not likely to pursue it. Don't make me jump through hoops when I'm just trying to see if a product can fit my needs.

    3. If license terms are too complex or easy to violate that's a hard pass. Infrastructure monitoring tools are a great example. The licensing is often per "device" or per monitored metric, and some vendors are very loose with their definition of "device". (Don't use LogicMonitor with k8s unless you like throwing money in the garbage can). Hard lessons learned.

    4. If the only details I can find regarding how you secure your product are claims of SOC2 and ISO27001 certification then that's a very likely pass. Those controls are great to have, necessary even, but anyone who has had to work to meet those compliance objectives knows that they're much more about organization controls than they are product security. Give me an idea about how you protect data and whatnot on a security page somewhere, not an attestation that dev and prod are separate and you have logs.

    On the side of the positives, outside of not hitting the negative marks, I value ease to work with, responsive and competent support, strong pre and post-sales solutions architecture and support/training (if the product is complex enough to warrant that), and supports SSO. I bring up SSO again because it's a hard requirement for SaaS purchases everywhere I go -- no SSO, no go. Social login is not a substitute and is highly undesired.

    Hope this helps.

  • Multi ā€“ Multiplayer Collaboration for macOS
    2 projects | news.ycombinator.com | 26 Feb 2024
    Donā€™t be shy, hereā€™s the link: https://github.com/robchahin/sso-wall-of-shame/issues.
  • SSO Tax- SaaS companies basis of upgrading from standard to enterprise
    1 project | news.ycombinator.com | 18 Dec 2023
  • SSO everything, good Idea?
    1 project | /r/sysadmin | 9 Dec 2023
  • We built the fastest CI in the world. It failed
    11 projects | news.ycombinator.com | 12 Sep 2023
    It sounds like you're unaware of why SSO is considered a security feature at all them, but it's covered right on the site: https://sso.tax/

    It's to allow centralized access management. Stuff like firing someone and revoking their access from one platform instantly, instead running around and changing permissions in every tool manually. Or ensuring people in department A can't be invited to some platform for people in department B in order to limit information access.

    SSO tax is predicated on the idea that the moment you outgrow the informal arrangements and liberal access, you're really a business. Seems pretty fair?

  • eSignature for Google Docs and Google Drive (Beta)
    3 projects | news.ycombinator.com | 10 Aug 2023
    Last time I had to implement Okta integration for DocuSign at my employer it was absurdly expensive. If Google does this right then Iā€™d be ever so happy.

    DocuSign on the SSO Tax site: https://sso.tax/

  • Show HN: Infisical ā€“ open-source secret management platform
    6 projects | news.ycombinator.com | 19 Jul 2023
    Thereā€™s a strong, widespread objection to hiding security features behind a paywall: https://sso.tax/

    If 2fa is the only way you can differentiate in order to force enterprises to pay, itā€™s better to have a fee for security than to die because you canā€™t make moneyā€¦ but broadly, as a security company, you should aim for maximum security for every user.

  • A note from our sponsor - SurveyJS
    surveyjs.io | 16 Jun 2024
    With SurveyJS form UI libraries, you can build and style forms in a fully-integrated drag & drop form builder, render them in your JS app, and store form submission data in any backend, inc. PHP, ASP.NET Core, and Node.js. Learn more ā†’

Stats

Basic sso-wall-of-shame repo stats
203
608
8.2
6 days ago

Sponsored
Open-Source JSON Form Builder to Create Dynamic Forms Right in Your App
With SurveyJS form UI libraries, you can build and style forms in a fully-integrated drag & drop form builder, render them in your JS app, and store form submission data in any backend, inc. PHP, ASP.NET Core, and Node.js.
surveyjs.io