stopthessotax / sso-wall-of-shame

A list of vendors that treat single sign-on as a luxury feature, not a core security requirement. This is a fork of robchahin/sso-wall-of-shame (sso.tax)
https://stopthesso.tax/
31 stars 19 forks source link

Add Bitwarden #64

Open sdepablos opened 1 year ago

mbainter commented 1 year ago

This is a tricky one. I feel like BitWarden's pricing is in a grey area here. While the percentage increase is greater than 10%, that's because the overall cost is so low that any increase is significant. If we do add this, we should probably also add lastpass ($4/$6, 50% increase)

doransmestad commented 1 year ago

@mbainter Hm, true, though based on how it's described on the Bitwarden pricing page it does sound to me like they're purposely gating SSO as an enterprise feature (vs it being a maintenance cost coverage), so my leaning is towards having it on the list.

Looks like this also is true for Lastpass, 1Password, and Keeper as well unfortunately, so I believe they should be on the list as well; makes me sad seeing the SSO tax from security focused companies.

Thoughts? Any objections to me merging in the change?

mbainter commented 1 year ago

Our main page indicates that the issue isn't companies having a small fee for it, or a reasonably small price increase between non-SSO and SSO tiers. We don't really have a hard number on this, except that there's a FAQ that indicates anything under 10% increase doesn't go in the list -- but I don't think that percentage had such a low per-user cost in view. Maybe we need a better metric there that acounts for these types of lower cost services?

I won't stand in the way if we're in general agreement that we want 10% to be the fixed limit full stop, I just wanted to make sure we considered this before merging.