cloak VS sso-wall-of-shame

Compare cloak vs sso-wall-of-shame and see what are their differences.

cloak

Secrets automation for developers (by purton-tech)

sso-wall-of-shame

A list of vendors that treat single sign-on as a luxury feature, not a core security requirement. (by robchahin)
InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
cloak sso-wall-of-shame
11 201
220 583
2.7% -
5.5 8.3
about 1 year ago 10 days ago
Rust JavaScript
MIT License Apache License 2.0
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

cloak

Posts with mentions or reviews of cloak. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-02-27.
  • Ask HN: Co-Founder? Seeking Co-Founder?
    1 project | news.ycombinator.com | 2 Mar 2023
    SEEKING FOUNDER CEO | Dev Tools | CEO Co-founder | Worldwide | MVP

    Lookign for

    Someone with experience taking a product to market, someone willing to trade equity for MAUs.

    Idea

    https://cloak.software/

    Current Progress

    Ready to onboard users but still a few issues to iron out.

    Contact

    https://www.linkedin.com/in/ianpurton

  • Launch HN: Infisical (YC W23) – Open-source secrets manager for developers
    9 projects | news.ycombinator.com | 27 Feb 2023
    Hi. I'm also working on an E2E secrets manager. https://github.com/purton-tech/cloak

    A few tips.

    1. It looks like I'm able to do account enumeration on your login page. For a secure app you want to make sure this is not possible.

  • Ask HN: What are some good examples of Rust code bases to read and learn from?
    1 project | news.ycombinator.com | 26 Feb 2023
  • Ask HN: Which CI/CD do you use for a monorepo?
    3 projects | news.ycombinator.com | 14 Jan 2023
    You want to take a look at Earthly. https://earthly.dev/

    This gives you a mix of docker and a makefile.

    The best bit is you can test your pipeline locally and you are vendor agnostic.

    I'm using it here https://github.com/purton-tech/cloak

  • Ask HN: Where do you host images for your blog or landing pages?
    6 projects | news.ycombinator.com | 17 Oct 2022
    I commit to a github repo and that gets deployed to cloudflare pages. https://pages.cloudflare.com/

    I use Zola the static site generator. My repo is here https://github.com/purton-tech/cloak/tree/main/www

  • Seeking advice on my AuthZ Implementation for web app.
    1 project | /r/rust | 28 Aug 2022
    You can see my migrations to switch on RLS here https://github.com/purton-tech/cloak/blob/main/db/migrations/20220808094314_tenancy_isolation.sql
  • Launch HN: DeploySentinel (YC S22) – End-to-end tests that don't flake
    2 projects | news.ycombinator.com | 2 Aug 2022
    Hi we are running selenium tests in our CI/CD pipeline.

    We do actually generate a video of the tests running as an example see here https://github.com/purton-tech/cloak/actions/runs/2787628672

    We're not using cypress we use webdriver connected to a selenium docker instance.

    Is that something you can connect to?

  • Ask HN: How to find a problem a solo founder could and would want to solve?
    2 projects | news.ycombinator.com | 16 Apr 2022
    I can give you a concrete example if that helps.

    I looked at the "secrets automation" space and my background is cryptography and web development.

    I'm a solo developer so when I look at a problem I have to make the solution small enough that I can actually build it.

    I also have to have an idea about how I will get people to use my product i.e. marketing.

    In my case 1Password raised 620million in funding based on their acquisition of Secretshub which for me proves there is a market in secrets automation for developers.

    I looked at the secretshub product and I was confident I could build it better with easier to use encryption and make it open source.

    As the market is developers I feel writing blog articles about software development will give me a route to market.

    So I started about 4 months ago. The product is now here https://cloak.software and source code is here https://github.com/purton-tech/cloak

    My first article about web development with rust has already had 16K views so I'm confident with the marketing approach. Now the hard works starts of turning visitors into paying users.

    Hope this helps.

  • Ask HN: How does your team manage environment variables?
    1 project | news.ycombinator.com | 13 Apr 2022
    I've just launched an MVP for a solution to this problem. https://cloak.software/
  • Dagger: a new way to build CI/CD pipelines
    29 projects | news.ycombinator.com | 30 Mar 2022
    I've been using Earthly for about 6 months.

    Earthly uses Dockerfile style syntax so I don't have to learn a new language, I can leverage my existing knowledge.

    Another advantage is that in Earthly I can run up a docker compose within my pipeline so that I have selenium, envoy and postgres running for integration testing.

    You can see my integration tests here https://github.com/purton-tech/cloak/blob/main/Earthfile#L14...

    Is that possible in dagger?

sso-wall-of-shame

Posts with mentions or reviews of sso-wall-of-shame. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2024-03-16.
  • Tailscale SSH is now Generally Available
    1 project | news.ycombinator.com | 18 Apr 2024
    Hi! Tailscalar here. This is very topical for me! Over the past 3 weeks I've been working with internal stakeholders to remove our SSO tax - the sso tax is a pet hate of mine. A couple of weeks ago we removed it from our pricing plan after my proposal was approved, and today I released a blog on our website to announce it more widely: https://tailscale.com/blog/sso-tax-cut

    I knew of https://sso.tax (which we are not listed on but I did include in my blog), but didn't know there was another website too!

  • Software Company HashiCorp Is Weighing a Potential Sale
    4 projects | news.ycombinator.com | 16 Mar 2024
    I'm not the person you've asked, but I'm somebody who has been purchasing SaaS/software for businesses large and small for years. My take:

    1. If SSO and other basic modern security features are locked into "Enterprise" pricing tiers then the service is at the bottom of the list (see: https://sso.tax). I'd love to say instant disqualification but too many SaaS companies have it in their head that only wealthy enterprises use SSO, despite SSO platforms being widely available and some quite cheap to acquire and start using.

    2. If I need to request a quote to start any kind of service to see what the product is about then I'm not likely to pursue it. Don't make me jump through hoops when I'm just trying to see if a product can fit my needs.

    3. If license terms are too complex or easy to violate that's a hard pass. Infrastructure monitoring tools are a great example. The licensing is often per "device" or per monitored metric, and some vendors are very loose with their definition of "device". (Don't use LogicMonitor with k8s unless you like throwing money in the garbage can). Hard lessons learned.

    4. If the only details I can find regarding how you secure your product are claims of SOC2 and ISO27001 certification then that's a very likely pass. Those controls are great to have, necessary even, but anyone who has had to work to meet those compliance objectives knows that they're much more about organization controls than they are product security. Give me an idea about how you protect data and whatnot on a security page somewhere, not an attestation that dev and prod are separate and you have logs.

    On the side of the positives, outside of not hitting the negative marks, I value ease to work with, responsive and competent support, strong pre and post-sales solutions architecture and support/training (if the product is complex enough to warrant that), and supports SSO. I bring up SSO again because it's a hard requirement for SaaS purchases everywhere I go -- no SSO, no go. Social login is not a substitute and is highly undesired.

    Hope this helps.

  • Multi – Multiplayer Collaboration for macOS
    2 projects | news.ycombinator.com | 26 Feb 2024
    Don’t be shy, here’s the link: https://github.com/robchahin/sso-wall-of-shame/issues.
  • SSO Tax- SaaS companies basis of upgrading from standard to enterprise
    1 project | news.ycombinator.com | 18 Dec 2023
  • SSO everything, good Idea?
    1 project | /r/sysadmin | 9 Dec 2023
  • We built the fastest CI in the world. It failed
    11 projects | news.ycombinator.com | 12 Sep 2023
    It sounds like you're unaware of why SSO is considered a security feature at all them, but it's covered right on the site: https://sso.tax/

    It's to allow centralized access management. Stuff like firing someone and revoking their access from one platform instantly, instead running around and changing permissions in every tool manually. Or ensuring people in department A can't be invited to some platform for people in department B in order to limit information access.

    SSO tax is predicated on the idea that the moment you outgrow the informal arrangements and liberal access, you're really a business. Seems pretty fair?

  • eSignature for Google Docs and Google Drive (Beta)
    3 projects | news.ycombinator.com | 10 Aug 2023
    Last time I had to implement Okta integration for DocuSign at my employer it was absurdly expensive. If Google does this right then I’d be ever so happy.

    DocuSign on the SSO Tax site: https://sso.tax/

  • Show HN: Infisical – open-source secret management platform
    6 projects | news.ycombinator.com | 19 Jul 2023
    There’s a strong, widespread objection to hiding security features behind a paywall: https://sso.tax/

    If 2fa is the only way you can differentiate in order to force enterprises to pay, it’s better to have a fee for security than to die because you can’t make money… but broadly, as a security company, you should aim for maximum security for every user.

  • Keygen: a software licensing and distribution API
    5 projects | /r/selfhosted | 5 Jul 2023
    I totally understand. I'm aware of the SSO tax. It's just honestly a complex feature, with a significant maintenance and support burden, and I leaned making it EE so that it'd be worth all the effort to implement and maintain (i.e. I want it to be a new-positive feature for revenue). But if I could get help from other contributors, I'd be fine with SSO being a CE feature too.
  • Managed Services Client Onboarding: Simple Process (Free Template)
    1 project | /r/msp | 5 Jul 2023
    Need to put them up for the SSO Wall of shame. https://sso.tax/