robchahin / sso-wall-of-shame

A list of vendors that treat single sign-on as a luxury feature, not a core security requirement.
https://sso.tax
Apache License 2.0
619 stars 288 forks source link

⚠ Improving sso.tax for the benefit of security ⚠ #469

Open wparad opened 2 months ago

wparad commented 2 months ago

Problem

Research tells us that the more people are exposed to something then the more they will think it is a good thing, even if it is bad. People favor familiar. In other words, "I see it, it must be good!". This is known as preferential attachment.

The problem is that we are creating positive press for all the companies listed on sso.tax because when you go there you are actually seeing these companies. Even if what they are doing is wrong and bad and harmful. The reason is, it just isn't that bad. If it was a fundamental moral issue, then it might serve to be a problem and be actually negative press, but really when people come to this website, we are actually encouraging them to buy these companies exactly because they tax SSO. If they don't tax, then people don't learn about them. We are actually encouraging SSO Tax by exactly publicizing it. :vomiting_face:

The easiest way to see this is:

you go to the web 100 times and you see Terrible Company X 100 times. Then months later, you go on google and look far a product that solves product X challenge. When you see Terrible Company X You think WOW I know them, I like them because I know them, I will buy them. But when you see Better Alternative Y, that's the first time you see them, I'm going to be unsure if they are good, so you are actually inclined to buy Terrible Company X because you:

Whereas Better Alternative Y, you have never seen before.

Recommendation

Next to every sso.tax company, we list out 2+ alternatives to that company that don't have an SSO Tax, so that people see explicitly which alternatives are better from a security standpoint