Ever heard of the SSO Tax? In short, it's a tactic where software vendors bully security-conscious companies to upgrade to costly enterprise plans. They do this by gating SSO (Single Sign-On) features behind their priciest options, causing companies to pay up to 70 times their standard rates.<p>As a former CTO at a VC-backed and security-conscious company, I've faced the tough choice of skipping costly enterprise upgrades, even when SSO was crucial.<p>Take a look at Notion: to access SSO, they casually double their standard pricing.<p>Imagine buying a Tesla and being charged extra to unlock full braking power. That's what SSO Tax is - vendors exploiting a built-in feature, essential for security, to extract excessive fees.<p>So, why initiate a new project?<p>Rob Chahin's work on sso.tax initially highlighted this issue. However, the site's updates dwindled, and data became outdated. Despite offering assistance, I received no response, leading to the creation of <a href="https://ssotax.org" rel="nofollow noreferrer">https://ssotax.org</a>. While there has been short spike of activity post-fork, it already stopped again. That’s what we’ve seen often in the last few years. Instead, I want to give the topic the attention it deserves.<p>In addition of integrating all pending PRs and enriching the data, I’ve introduced a new feature: "Friends of SSO". We should not only call out unfair practices but also praise vendors who are committed to security!<p>Furthermore, I’d love to raise awareness about vendor practices by utilizing Twitter and Linkedin to publicly praise or critique them. The goal is to get attention for the topic, ideally sparking conversation with the vendors involved.<p>What are your thoughts on getting rid of the SSO Tax? Excited to hear your ideas!
Ha ha. I noticed the SSO tax and it has stopped us SSOing all the things which would be nice from a security point of view.<p>I think vendors use SSO as a feeler for “company has more money to spend on us” so if you want to eliminate SSO tax you need to give them a new thing to grade enterprises on. However a simpler thing would be like Docker etc. who look at ARR.