(Arguments for this being a bad thing are listed there)
(Arguments for this being a bad thing are listed there)
Another problem I have with the "SSO should be free, because it's security-related" argument is that it's a misunderstanding of why it costs money. It's not because companies want to gate security features. It's because when you're trying to create a pricing model for an otherwise free product, going from "I'm ok with manually inviting/deactivating users" to "I now need SSO, because this product has enough adoption within the company to merit it" happens to be an almost a perfect way to delineate between casual freemium users and business users who should be paying. That, combined with my initial point, is why I dropped out of the SSO tax crowd.
The best solution would be to have G-Suite SSO in the lowest paid tier and SAML in Enterprise.
https://news.ycombinator.com/item?id=29892664
Long story short: it has almost nothing to do with the cost of providing SSO features (which is what upsets security nerds, because we know it's not that expensive to get these features right, though they are tricky).
Rather: the SSO tax is much more about making services cheap/free for small customers, and charging "what they're really worth" (the core service! the whole thing! not just the SSO feature!) to companies that demonstrate that they're large enough by demanding SSO.
You don't have to like it! I sure don't! We SSO everything and are relatively small and the tax takes a bite. But it's at least worth understanding the logic behind it.
Not a day goes by that I don't dedicate some thought to better business models for software and services, especially for FOSS and otherwise pro-freedom pro-user software. It's hard for many reasons. User-hostile software (surveillance, loot box games, cryptocurrency scams) is easy to make money from, but that's not my thing.
And I 100% agree with you. As good security practice SSO should be available for all but the reasoning makes sense
<rant>
... now if people would only pay for software without some lever like this we'd make SSO included.
I was just ranting on this topic earlier today:
https://news.ycombinator.com/item?id=31676011#31680304
SSO is a fairly decent "are you a business or an individual" lever, which is why the SSO tax exists. Otherwise businesses will not pay anything and then complain when you disappear.
As I always say: people will pay $10 every day for a latte and a donut at Starbucks but you have to twist their arms to get them to pay much less than that for software they get tons of value from.
</rant>
Arguably, a "are you a business rich enough to afford better security concepts" lever. So the smaller companies are left stranded :(
I understand your point, but at the same time I'd rather go for other levers. Maybe charging extra for SSO on support plans, while making SSO features themselves freely available (without support)?
[Ed.: I see you reworded your post a bit:]
> I agree. We do have plans to support free "social SSO" in the future with certain providers.
I guess that could cover most realistic small-business use cases. Or rather, if you can afford a "complicated" SSO solution, you can actually afford a SSO surcharge on services too. Sounds like a better lever?
One can view it as the SSO-enabled offering being a product, and the SSO-less option being a demo. Which, let’s be fair, it really is.
So, would you advocate the removal of the SSO-less trial discount ?
For the good of the Internet, the security of the global entirety of things, it is very very wise if everyone makes an attempt to make the defaults sane and secure, including things like this. It surely is a differentiator between "individual" and "business", but it shouldn't have to be. I agree wholehartedly with the sso.tax site that it's just one way for business to attempt to make revenue out of a basic need that any modern company would have.
Make the profit of real value added services for enterprises, automation, integrations, support, advanced features that gives insights or saves money or whatever; but don't be sneaky with the security aspect, is basically what I'm saying.
Compare it with streaming services. No one can argue against Netflix being particularly expensive. Anyone can afford it. It's just one latte per month. But when you not only want to consume what is on Netflix, you have to get another service, and another, and another, and another. Very very soon the aggregated cost starts to be very noticeable for a lot of people. And piracy makes a comeback.
And I very much doubt the typical ZeroTier user is earning minimum wage.
ZeroTier's SSO costs $5/user/month.
Why do so many people in tech expect to earn $$$$$$ themselves, yet expect their peers to work for nothing?
Or, to view it from a different angle - SSO is not a/the feature that should be removed to make it the "trial".
And from yet another angle: you could consider removing (or not offering) SSO similar to selling a car without seat belts (ignoring aspects of legality). It's not a problem until it is. But if you want the seat belts to be effective, you need to always have and use them from minute zero.
Why would we care about anyone not in the richest countries. It's not like they need security by default to not become another botnet and DDoS Europe or US businesses.
I would like to see you justify paying sso.tax to business owner in countries where sysadmin is payed less than those services ask in a month
I guess there's a lesson or two in market positioning and distribution in there somewhere.
See also: SimSWE 4: Wants, needs, and chasm-crossing, https://apenwarr.ca/log/20211024 (2021).
I know you are using this for effect, but I literally do not know anyone who goes to Starbucks anywhere close to daily.
$10 for lunch, even regularly, is still a one time expense.
It’s capx vs. opex
Sure, you can do it, but then it's $5/seat for thing A, $3/seat for thing B, $4/seat for thing C, and you can end up paying $50/seat for all the random software associated.
Yeah, for high value employees that's nothing. But for a warehouse worker to login and checkoff a compliance form once a month? It's not worth it, give them a shared login.
And then once shared logins happen, it'll just become habit for a bunch of small stuff that snowballs.
So that's why the first thing I look at for software is that if it has a per-seat cost, I'm going elsewhere because I want all my staff, not just the high-value staff, to be able to access and get what they need done.
And if you use Auth0/Okta to implement your SSO (on the SaaS side) shits expensive as fuuuck and cost is per integration.
They should have a hall of fame at the bottom though, showcasing SaaS-providers doing it right.